Cloud Managed Networks

 View Only
  • 1.  Aruba Central NAC with customer provided certificates

    Posted 8 days ago

    Dear Experts, 

    One of the customer is planning for AOS 10 setup. They want to integrate with Azure AD and do authentication based on certificates that are issued internally by their firewall/server. Do we need Central NAC, and is it possible to use customer's own certificates for authentication of users and devices? so far what i have read, i think it may not be possible since cloud auth provisions its own certs?



    ------------------------------
    Owais101
    ------------------------------


  • 2.  RE: Aruba Central NAC with customer provided certificates

    Posted 8 days ago

    Azure AD is now called Entra ID. And what you describe is called Bring Your Own Certificates in Central NAC.

    Cloud Authentication and Poilcy (Classic Central) indeed supports Central provisioned certificates; Central NAC (New Central) supports in addition custom certificates as part of the Premium NAC License. Note that for Central NAC, configuration needs to be in New Central.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Aruba Central NAC with customer provided certificates

    Posted 8 days ago
    So it is possible through new central with premium NAC license?

    Will it support machine authentication also?

    Lastly, where can i read more about new Central NAC?







  • 4.  RE: Aruba Central NAC with customer provided certificates

    Posted 8 days ago

    I'm not sure about machine authentication, and for now would say it's not possible as the user needs to be in EntraID. Possibly you can assign a certificate with a user account for the machine certificate and authenticate through that path.

    Documentation for Central NAC is here. In my previous response, I added a direct link to the BYOC (Bring your own certificate) section.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Aruba Central NAC with customer provided certificates

    Posted 8 days ago

    For BYOC feature you need Pro subscription and here you can find the details HPE Aruba Networking Central NAC



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 6.  RE: Aruba Central NAC with customer provided certificates

    Posted 7 days ago

    Also register for Airheads Event for Central NAC feature held at 21.January 2026. Registration link is on Airheads home page.

    Best, Gorazd 



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------