757-216-3656 | Monday–Friday 8:30 AM – 4:30 PM | info@itdojo.com

Course Duration

5 Days

Audience

Employees of federal, state and local governments; and businesses working with the government.

Prerequisites

Completion of AA-CPC (HPE Aruba Networking ClearPass Configuration) or equivalent hands-on experience with ClearPass NAC, 802.1X, and enforcement policies.

Course Description

In the 5-day HPE Aruba Networking ClearPass Advanced Configuration course, you will learn how to design, deploy, and troubleshoot several aspects of the ClearPass security product. This course includes both instructional modules and hands-on labs to teach you about advanced features of the ClearPass portfolio.

Learning Objectives

  • Deploy a complete and resilient Network Access Control (NAC) security solution based on HPE Aruba Networking ClearPass.
  • Understand the HPE Aruba Networking ClearPass logic to handle different authentication events.
  • Implement a secure network that follows the principles of the Zero Trust Security (ZTS) architecture.

Course Outline

Course Modules
  • Public Key Infrastructure
  • Describe PKI infrastructure
  • Evaluate the advantages and disadvantages of public and private PKIs
  • Understand best practices for public and private certificates on ClearPass
  • ClearPass cluster
  • The licensing module for ClearPass
  • Request certificates for RADIUS and HTTPS
  • Upgrade the ClearPass system
  • Run and secure backups
  • Upgrade ClearPass cluster
  • Describe ClearPass cluster upgrade procedures
  • Analyze best practices on cluster updates
  • Cluster troubleshooting
  • Revise common upgrade failures
  • Assess and troubleshoot failed cluster upgrades
  • Enrollment over Secure Transport
  • Define EST
  • EST’s main components
  • Configure and monitor ETS
  • RadSec
  • Describe RadSec, its main components and characteristics
  • Configure RadSec
  • Troubleshoot RadSec
  • ClearPass access request process
  • Describe the service classification and match process
  • The process of an access request
  • Perform services troubleshooting
  • Creating services and rules manually
  • Describe the process of manually creating a service and its dependencies
  • Manually configure new services, enforcement policies and profiles
  • Explore the different parts of a service and best practices of naming convention and maintenance
  • Dual SSID OnBoard
  • Compare single and dual SSID device onboarding
  • The benefits of dual SSID onboarding
  • Configure dual SSID onboarding
  • Managing usercertificates
  • Implementing MPSK
  • MPSK concept
  • Configure MPSK with user self-registration
  • Configure MPSK for a device group
  • Troubleshooting MPSK
  • Wired onboarding/profiling
  • Onboarding process for wired devices
  • Configure services for wired devices onboard
  • Troubleshoot wired authentication and profiling
  • Dynamic Segmentation - BYOD, employee, and guest
  • Concepts of dynamic segmentation
  • ClearPass functions related to dynamic segmentation
  • Configure downloadable user roles to support dynamic segmentation

Frequently Asked Questions

What does ClearPass Advanced Configuration cover?

This 5-day course covers advanced ClearPass topics including PKI, certificate-based 802.1X, RADIUS proxy, guest workflows, OnBoard device provisioning, OnGuard posture checks, high availability, and integration with external identity sources.

What certification does this course prepare me for?

This course prepares you for the HPE Aruba Networking Certified Professional - ClearPass (ACP-ClearPass) certification.

Is there a prerequisite for this course?

Yes. Completion of AA-CPC (ClearPass Configuration) or equivalent practical ClearPass experience is required before attending.

Is this course available as live remote online training?

Yes. IT Dojo offers this course as live remote online instruction. On-site delivery is also available.

How do I register?

IT Dojo training is employer-sponsored. Contact IT Dojo via the Request Training form or call 757-216-3656.

Get More Information

We work with Government Agencies, Military, government contractors, and corporate clients. As much as we would love to, our business model does not include working with the general public.