<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.de/css/xml-course.xsl"?><course productid="30924" language="en" source="https://portal.flane.de/ibb/en/xml-course/aruba-cpac" lastchanged="2026-02-10T12:51:14+01:00" parent="https://portal.flane.de/ibb/en/xml-courses"><title>HPE Aruba Networking ClearPass Advanced Configuration</title><productcode>CPAC</productcode><vendorcode>AA</vendorcode><vendorname>Aruba</vendorname><fullproductcode>AA-CPAC</fullproductcode><version>25.23</version><objective>&lt;p&gt;After you successfully complete this course, expect to be able to:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deploy a complete and resilient Network Access Control (NAC) security solution based on HPE Aruba Networking ClearPass.&lt;/li&gt;&lt;li&gt;Understand the HPE Aruba Networking ClearPass logic to handle different authentication events.&lt;/li&gt;&lt;li&gt;Implement a secure network that follows the principles of the Zero Trust Security (ZTS) architecture.&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/ibb/en/course/aruba-cpc&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;HPE Aruba Networking ClearPass Configuration &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CPC)&lt;/span&gt; 25.23&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Ideal candidates include network professionals who are looking to build their advanced knowledge of ClearPass.&lt;/p&gt;</audience><contents>&lt;h5&gt;Public Key Infrastructure&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe PKI infrastructure&lt;/li&gt;&lt;li&gt;Evaluate the advantages and disadvantages of public and private PKIs&lt;/li&gt;&lt;li&gt;Understand best practices for public and private certificates on ClearPass&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;ClearPass cluster&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;The licensing module for ClearPass&lt;/li&gt;&lt;li&gt;Request certificates for RADIUS and HTTPS&lt;/li&gt;&lt;li&gt;Upgrade the ClearPass system&lt;/li&gt;&lt;li&gt;Run and secure backups&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Upgrade ClearPass cluster&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe ClearPass cluster upgrade procedures&lt;/li&gt;&lt;li&gt;Analyze best practices on cluster updates&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Cluster troubleshooting&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Revise common upgrade failures&lt;/li&gt;&lt;li&gt;Assess and troubleshoot failed cluster upgrades&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Enrollment over Secure Transport&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Define EST&lt;/li&gt;&lt;li&gt;EST&amp;rsquo;s main components&lt;/li&gt;&lt;li&gt;Configure and monitor ETS&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;RadSec&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe RadSec, its main components and characteristics&lt;/li&gt;&lt;li&gt;Configure RadSec&lt;/li&gt;&lt;li&gt;Troubleshoot RadSec&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;ClearPass access request process&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe the service classification and match process&lt;/li&gt;&lt;li&gt;The process of an access request&lt;/li&gt;&lt;li&gt;Perform services troubleshooting&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Creating services and rules manually&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe the process of manually creating a service and its dependencies&lt;/li&gt;&lt;li&gt;Manually configure new services, enforcement policies and profiles&lt;/li&gt;&lt;li&gt;Explore the different parts of a service and best practices of naming convention and maintenance&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Dual SSID OnBoard&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Compare single and dual SSID device onboarding&lt;/li&gt;&lt;li&gt;The benefits of dual SSID onboarding&lt;/li&gt;&lt;li&gt;Configure dual SSID onboarding&lt;/li&gt;&lt;li&gt;Managing usercertificates&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Implementing MPSK&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;MPSK concept&lt;/li&gt;&lt;li&gt;Configure MPSK with user self-registration&lt;/li&gt;&lt;li&gt;Configure MPSK for a device group&lt;/li&gt;&lt;li&gt;Troubleshooting MPSK&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Wired onboarding/profiling&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Onboarding process for wired devices&lt;/li&gt;&lt;li&gt;Configure services for wired devices onboard&lt;/li&gt;&lt;li&gt;Troubleshoot wired authentication and profiling&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Dynamic Segmentation - BYOD, employee, and guest&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Concepts of dynamic segmentation&lt;/li&gt;&lt;li&gt;ClearPass functions related to dynamic segmentation&lt;/li&gt;&lt;li&gt;Configure downloadable user roles to support dynamic segmentation&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h5&gt;Public Key Infrastructure&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe PKI infrastructure&lt;/li&gt;&lt;li&gt;Evaluate the advantages and disadvantages of public and private PKIs&lt;/li&gt;&lt;li&gt;Understand best practices for public and private certificates on ClearPass&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;ClearPass cluster&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;The licensing module for ClearPass&lt;/li&gt;&lt;li&gt;Request certificates for RADIUS and HTTPS&lt;/li&gt;&lt;li&gt;Upgrade the ClearPass system&lt;/li&gt;&lt;li&gt;Run and secure backups&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Upgrade ClearPass cluster&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe ClearPass cluster upgrade procedures&lt;/li&gt;&lt;li&gt;Analyze best practices on cluster updates&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Cluster troubleshooting&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Revise common upgrade failures&lt;/li&gt;&lt;li&gt;Assess and troubleshoot failed cluster upgrades&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Enrollment over Secure Transport&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Define EST&lt;/li&gt;&lt;li&gt;EST&amp;rsquo;s main components&lt;/li&gt;&lt;li&gt;Configure and monitor ETS&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;RadSec&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe RadSec, its main components and characteristics&lt;/li&gt;&lt;li&gt;Configure RadSec&lt;/li&gt;&lt;li&gt;Troubleshoot RadSec&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;ClearPass access request process&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe the service classification and match process&lt;/li&gt;&lt;li&gt;The process of an access request&lt;/li&gt;&lt;li&gt;Perform services troubleshooting&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Creating services and rules manually&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe the process of manually creating a service and its dependencies&lt;/li&gt;&lt;li&gt;Manually configure new services, enforcement policies and profiles&lt;/li&gt;&lt;li&gt;Explore the different parts of a service and best practices of naming convention and maintenance&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Dual SSID OnBoard&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Compare single and dual SSID device onboarding&lt;/li&gt;&lt;li&gt;The benefits of dual SSID onboarding&lt;/li&gt;&lt;li&gt;Configure dual SSID onboarding&lt;/li&gt;&lt;li&gt;Managing usercertificates&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Implementing MPSK&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;MPSK concept&lt;/li&gt;&lt;li&gt;Configure MPSK with user self-registration&lt;/li&gt;&lt;li&gt;Configure MPSK for a device group&lt;/li&gt;&lt;li&gt;Troubleshooting MPSK&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Wired onboarding/profiling&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Onboarding process for wired devices&lt;/li&gt;&lt;li&gt;Configure services for wired devices onboard&lt;/li&gt;&lt;li&gt;Troubleshoot wired authentication and profiling&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Dynamic Segmentation - BYOD, employee, and guest&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Concepts of dynamic segmentation&lt;/li&gt;&lt;li&gt;ClearPass functions related to dynamic segmentation&lt;/li&gt;&lt;li&gt;Configure downloadable user roles to support dynamic segmentation&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>After you successfully complete this course, expect to be able to:



- Deploy a complete and resilient Network Access Control (NAC) security solution based on HPE Aruba Networking ClearPass.
- Understand the HPE Aruba Networking ClearPass logic to handle different authentication events.
- Implement a secure network that follows the principles of the Zero Trust Security (ZTS) architecture.</objective_plain><essentials_plain>- HPE Aruba Networking ClearPass Configuration (CPC) 25.23</essentials_plain><audience_plain>Ideal candidates include network professionals who are looking to build their advanced knowledge of ClearPass.</audience_plain><contents_plain>Public Key Infrastructure


- Describe PKI infrastructure
- Evaluate the advantages and disadvantages of public and private PKIs
- Understand best practices for public and private certificates on ClearPass
ClearPass cluster


- The licensing module for ClearPass
- Request certificates for RADIUS and HTTPS
- Upgrade the ClearPass system
- Run and secure backups
Upgrade ClearPass cluster


- Describe ClearPass cluster upgrade procedures
- Analyze best practices on cluster updates
Cluster troubleshooting


- Revise common upgrade failures
- Assess and troubleshoot failed cluster upgrades
Enrollment over Secure Transport


- Define EST
- EST’s main components
- Configure and monitor ETS
RadSec


- Describe RadSec, its main components and characteristics
- Configure RadSec
- Troubleshoot RadSec
ClearPass access request process


- Describe the service classification and match process
- The process of an access request
- Perform services troubleshooting
Creating services and rules manually


- Describe the process of manually creating a service and its dependencies
- Manually configure new services, enforcement policies and profiles
- Explore the different parts of a service and best practices of naming convention and maintenance
Dual SSID OnBoard


- Compare single and dual SSID device onboarding
- The benefits of dual SSID onboarding
- Configure dual SSID onboarding
- Managing usercertificates
Implementing MPSK


- MPSK concept
- Configure MPSK with user self-registration
- Configure MPSK for a device group
- Troubleshooting MPSK
Wired onboarding/profiling


- Onboarding process for wired devices
- Configure services for wired devices onboard
- Troubleshoot wired authentication and profiling
Dynamic Segmentation - BYOD, employee, and guest


- Concepts of dynamic segmentation
- ClearPass functions related to dynamic segmentation
- Configure downloadable user roles to support dynamic segmentation</contents_plain><outline_plain>Public Key Infrastructure


- Describe PKI infrastructure
- Evaluate the advantages and disadvantages of public and private PKIs
- Understand best practices for public and private certificates on ClearPass
ClearPass cluster


- The licensing module for ClearPass
- Request certificates for RADIUS and HTTPS
- Upgrade the ClearPass system
- Run and secure backups
Upgrade ClearPass cluster


- Describe ClearPass cluster upgrade procedures
- Analyze best practices on cluster updates
Cluster troubleshooting


- Revise common upgrade failures
- Assess and troubleshoot failed cluster upgrades
Enrollment over Secure Transport


- Define EST
- EST’s main components
- Configure and monitor ETS
RadSec


- Describe RadSec, its main components and characteristics
- Configure RadSec
- Troubleshoot RadSec
ClearPass access request process


- Describe the service classification and match process
- The process of an access request
- Perform services troubleshooting
Creating services and rules manually


- Describe the process of manually creating a service and its dependencies
- Manually configure new services, enforcement policies and profiles
- Explore the different parts of a service and best practices of naming convention and maintenance
Dual SSID OnBoard


- Compare single and dual SSID device onboarding
- The benefits of dual SSID onboarding
- Configure dual SSID onboarding
- Managing usercertificates
Implementing MPSK


- MPSK concept
- Configure MPSK with user self-registration
- Configure MPSK for a device group
- Troubleshooting MPSK
Wired onboarding/profiling


- Onboarding process for wired devices
- Configure services for wired devices onboard
- Troubleshoot wired authentication and profiling
Dynamic Segmentation - BYOD, employee, and guest


- Concepts of dynamic segmentation
- ClearPass functions related to dynamic segmentation
- Configure downloadable user roles to support dynamic segmentation</outline_plain><duration unit="d" days="5">5 days</duration><pricelist><price country="GB" currency="GBP">2830.00</price><price country="IL" currency="ILS">13650.00</price><price country="PL" currency="EUR">3000.00</price><price country="SI" currency="EUR">3300.00</price><price country="AU" currency="USD">3200.00</price><price country="SG" currency="USD">2560.00</price><price country="IN" currency="USD">1920.00</price><price country="DE" currency="EUR">4950.00</price><price country="AT" currency="EUR">4950.00</price><price country="SE" currency="EUR">4950.00</price><price country="CH" currency="EUR">4950.00</price><price country="FR" currency="EUR">4000.00</price><price country="IT" currency="EUR">3300.00</price></pricelist><miles/></course>