Deployment Guide

Figure 13 ClearPass Onboard Network Architecture when Using ClearPass Guest
The user experience for device provisioning is the same in Figure 13 and Figure 11, however there are implementation
differences between these approaches:
l When using the ClearPass Guest RADIUS server for provisioning and authentication, EAP-TLS and PEAP
authentication must be configured.
Navigate to RADIUS> Authentication> EAP & 802.1X to configure a server certificate and the appropriate EAP
types for the ClearPass Guest RADIUS server.
l ClearPass Policy Manager supports a rich policy definition framework. If you have complex policies to enforce,
multiple authentication or authorization sources that define user accounts, or you need features beyond those
available in the ClearPass Guest RADIUS server, you should deploy Policy Manager for authentication.
The ClearPass Onboard Process
Devices Supporting Over-the-Air Provisioning
Dell Networking W-ClearPass Onboard supports secure device provisioning for iOS 4, iOS 5, and recent versions of
Mac OS X (10.7 “Lion and later). These are collectively referred to as “iOS devices”. The Onboard process for iOS
devices is shown in Figure 14.
Figure 14 ClearPass Onboard Process for iOS Devices
The Onboard process is divided into three stages:
Dell Networking W-ClearPass Guest 6.3 | User Guide Onboard + WorkSpace | 85