Aruba Networks this week unveils software designed to protect corporate data and networks when accessed by employee-owned mobile clients, whether laptops, tablets, or smartphones.
The software, ClearPass Policy Manager, offers a set of modules that let enterprise IT groups streamline provisioning, inventory, security and management for personal devices used for work purposes, a trend often dubbed "bring your own device" or BYOD. Aruba's software is intended to make it simpler to securely manage a much more varied client environment, especially in mobile deployments, and to provision secure network access, a feature missing from at least some other mobile device management (MDM) applications.
[ Stay ahead of advances in mobile technology with InfoWorld's Mobile Edge blog and Mobilize newsletter. ]
SECURITY MINEFIELD: 'Bring your own device' will bedevil IT security in 2012
ClearPass Policy Manager can be bought preloaded on a server appliance or as a VMware virtual machine instance. The application can work with the major mobile and PC operating systems in the enterprise: iOS, Android, BlackBerry OS, OS X and Windows 7. The new product combines code from two Aruba acquisitions, Amigopod, for guest access and management, and from last December, Avenda Systems, whose mobile management software is the heart of Policy Manager.
The new offering includes the FreeRadius open source software, for authentication, authorization and accounting, but the Policy Manager also can work with an existing AAA/Radius infrastructure.
Policy Manager consists of the core application, and four separately licensed modules: Onboard, a self-service mobile provisioning portal for employees; Profiler, which creates a detailed inventory of each device; OnGuard, which is a Network Access Control application, including the quarantine and cleanup of compromised devices; and Guest, for registering and managing guest access to the network.
One additional cloud service, ClearPass QuickConnect, can automatically configure wired and wireless network settings for personal devices.
The actual provisioning is set up in advance by IT administrators working with ClearPass Policy Manager, which lets them set a range of policies for devices by device type, OS, user groups and other variables.
Users then can register their devices for access on their own, via a Web portal, and have them automatically configured for such enterprise-standard protections and services as 802.1x authentication, a VPN client, Exchange ActiveSync, and machine IDs or certificates. When users attempt to log into the corporate network for the first time, they're redirected to the portal, where an application wizard walks them through the configuration process. Once that happens, these personal devices become uniquely visible to IT.