Aruba Networks Secure Mobility Access Aruba ClearPass CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved @arubanetworks Are you ready for CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved Aruba’s FY’2013 ClearPass Business Gartner 2013 NAC CLEARPASS MAGIC QUADRANT OPENING DOORS INDUSTRY LEADER at NON-ARUBA CUSTOMERS MORE THAN 2200 TOTAL CUSTOMERS CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 3 @arubanetworks Why We’re Winning GUEST Beating Cisco with ACS REPLACEMENT: integrated RADIUS & TACACS+, built-in profiling and ease of management! GUEST ACCESS: ClearPass works in multivendor networks, scales and makes the customer brand look good! MOBILITY SERVICES: ClearPass Onboard with built-in CA, AirGroup, and IT Off-load features are making BYOD roll-outs easy! CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 4 @arubanetworks Inside the ClearPass Solution Industry leading Security and Access Control for Mobility VISIBILITY WORKFLOW POLICY Device Profiling Onboarding, Registration Role-based Enforcement Troubleshooting Guest Management Health/Posture Checks Per Session Tracking MDM Integration Device Context CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 5 @arubanetworks Pitching The ClearPass Platform DEVICE SECURITY Guest DEVICE OnGuard Onboard DIFFERENTIATED UNIFIED Visitor VISIBILITY Posture & ACCESS DevicePOLICIES Health Checks Provisioning Management VPN GUEST EMPLOYEE ClearPass Policy Manager Policy SERVICES Services POLICY AAA Services Policy Engine ENTERPRISE-CLASS AAA Profiling RADIUS, TACACS+ Identity Stores CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 3rd Party MDM App Servers 6 Multivendor Networks @arubanetworks ClearPass 6.3 – January 2014 INTEROPERABILITY CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved INTEGRATION 7 @arubanetworks Auto Sign On to Work Apps 1. 2. 3. Successful network authentication validates the user for automatic access to SAML enabled web/work apps CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 8 @arubanetworks Auto Sign-On with Partners Only Aruba lets you sign-in once & you’re good to go • One login for all web/mobile apps – Uses valid network login • NO App logins • IBM, Okta, Ping • ClearPass as Provider (IdP) – Uses SAML, not RADIUS CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 9 @arubanetworks More in ClearPass 6.3 INTEROPERABILITY CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved INTEGRATION 10 @arubanetworks ClearPass Exchange Two-way Third-Party Integration 1. Jail-broken device detected ClearPass denies access to device Syslog Messages / RESTful APIs 3. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 11 Message to device auto generated Helpdesk ticket auto generated 2. @arubanetworks Recent Win!: Cisco ACS Replacement Bechtel Corporation WHO / WHY? • Industry: Engineering, Construction • Objective: Role out of BYOD initiative AAA PROBLEM? • Address lack of Cisco scalability for AAA and onboarding of personal devices RESOLUTION? • Solution: ClearPass, plus Onboard • Why Aruba: Cisco could not meet ease of policy management, scalability and onboarding capabilities GUEST CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 12 @arubanetworks Selling ClearPass Core Mobility Services How Bechtel was Won! 1. Installed product was being phased out. – EOL of Cisco ACS. Policy in ClearPass versus just AAA 2. Organization has > 1000 users – IT NOT onboarding ~ 1500 devices 3. Customer also expressed interest in Guest Access – ClearPass Guest more customizable and scalable than Cisco ISE CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 13 @arubanetworks Recent Win!: Guest San Francisco Intl Airport GUEST WHO / WHY? • Industry: Transportation/Public Facing Ent. • Objective: Free & reliable Wi-Fi for guests PROBLEM? • Replacement of Cisco guest to support high density of daily visitors RESOLUTION? • Solution: ClearPass Guest, Aruba Wi-Fi • Why Aruba: Cisco could not meet the key requirement to provide visibility and workflow control in a multivendor network GUEST CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 14 @arubanetworks Selling ClearPass Guest Access How SFO was Won! 1. Large volume of daily visitors. – Old Cisco Wi-Fi and guest solution not scalable 2. Multivendor requirement. – Cisco ISE guest fails in mixed Aruba and Cisco environment 3. Branding and guest experience. – Aruba Guest portal fully customizable and sized for laptops / tablets / smart phones CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 15 @arubanetworks Recent Win!: Onboarding Mobile Devices L.A. Unified School District ONBOARD WHO? • Industry: Education • Objective: Every student has a tablet PROBLEM? • Simple way to configure iPads and protect content END RESULT! • Solution: ClearPass, plus Onboard • Why Aruba: Ability to scale, off-load IT and support network policies based on MDM data for largest Onboard deployment CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 16 @arubanetworks Selling Device Onboarding How LAUSD was Won! 1. District concerned with device security. – ClearPass MDM Connector leverages data from 3rd party MDM solution 2. Ease of device configuration. – ClearPass Onboard easier to manage than competing solutions 3. Multivendor interoperability. – ClearPass policy enforcement works across multivendor wireless equipment deployed at individual schools CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 17 @arubanetworks Handling a Proof of Concept ClearPass Canned PoC Scope creep leads to endless PoC 2014 2015 Customer learning on Aruba’s time SE’s stuck for long periods No end dates CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved Available to all partners Only requires access to SEEL Limits scope and time 18 @arubanetworks Industry Wide Deployments CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 19 @arubanetworks What Makes ClearPass Different? Multi-vendor Independence Built-in Services for RADIUS, TACACS+, CA, MDM, SSO, Guest Self-service and Automated Workflows CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 20 @arubanetworks Competitive Differentiation CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 21 @arubanetworks Competitive: Built-in Services ClearPass 1 Integrated System ISE CA TACACS ClearPass does not require multiple systems for full featured service. Bonjour Cisco claims ISE is an extensible Enterprise Class platform. Silos CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved NAC Silos 22 @arubanetworks Competitive: Multivendor Support 100 Built-in RADIUS Dictionaries Deployed in 2K multivendor accounts Cisco claims to have a few Aruba Wi-Fi reference customers. Interoperability CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 23 @arubanetworks Competitive: Guest Access Full Customization and Branding Cisco guest meets quick & easy access needs. ClearPass Guest is enterprise ready. 1 Template – 3 Colors Branding Advertising Multivendor Custom Skins Branding Advertising Multivendor CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 24 @arubanetworks Partner News CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 25 @arubanetworks ClearPass Program Benefits • 15% rebate on ClearPass product sales extended to July 31,2014 - Offer may continue beyond July 31, however terms and conditions will change • Collaboration on joint marketing activities • Free 3-year NFR (demo) license upon completion of technical training • Go-to partner for Aruba-identified ClearPass sales opportunities Eligibility: – Open to all Platinum, Gold and Silver PartnerEdge Program members – Authorized-level members must have pre-approval from Aruba Channel Account Manager CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 26 @arubanetworks Get Started with #GenMobile Assessment COMING! Please complete the following survey and we will calculate your opportunity to Rightsize for #GenMobile and generate a set of recommendations. Please contact Aruba Sales or an Authorized Reseller for additional information. Your Summary About Your Organization $ 1.3M Potential money you can save from network rightsizing learn more 238 hours Potential time saved from automating routine IT tasks learn more Company Size Number of users Industry Education 2.1x better Potential improvement in speed and reliability of Wi-Fi learn more Healthcare Number of offices % of employees that work from home CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved • Survey-based assessment • Rightsizing calculation for potential savings • Evaluates all key #GenMobile imperatives Retail Finance Other 27 @arubanetworks Thank You CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 28 @arubanetworks