Core vs Subscriptions Capabilities

A detailed comparison between the NAC Core and subscription capabilities of the Central NAC platform.

This technote provides a detailed comparison between the Central NAC Core and Subscription capabilites of the Central NAC platform. As organizations adopt Central NAC to support their network, security, or identity infrastructure, it becomes essential to understand the capabilities offered between core and subscription to ensure optimal planning and alignment with business needs.

The default Central NAC Core capabilities include a robust set of core features designed to support standard deployments and day-to-day operational requirements. The subscription builds upon this by offering enhanced capabilities aimed at securing complex environments with greater flexibility.

This document outlines the key functional differences between the two tiers, highlights feature availability, and provides guidance on when and why an organization may benefit from upgrading to the subscription tier.

Central NAC Core vs Subscription Capabilities Comparison

Feature Core Capabilities Subscription Capabilities
In parity with the legacy CloudAuth features ✔️ ✔️
Visitor authentication methods (Anonymous, Created user, Self-registration) ✔️ ✔️
Basic portal customizations (multiple custom portals) ✔️ ✔️
Visitor portal language overrides ✔️ (override single language) ✔️ (override multiple languages)
EAP-TLS Client Certificates (per-tenant level) ✔️ ✔️
MAC address authentication ✔️ ✔️
Captive portal authentication ✔️ ✔️
EAP-TLS based 802.1X authentication ✔️ ✔️
Support for Cloud-based Identity Provider (IdP) ✔️ (Single External IdP) ✔️ (Multiple External IdPs)
“User” policy ✔️ ✔️
“Client” policy ✔️ ✔️
“Custom Type” policy ✔️
Additional NAC policy and rule configuration elements ✔️
MPSK support ✔️ (Limited to 5000) ✔️ (Unlimited)
MPSK expiration policy ✔️
Support for Wi-Fi Easy Connect (DPP) ✔️ ✔️
API access (all configuration capabilities) ✔️ ✔️
Bring Your Own Certificates (BYOC) or external PKI ✔️
Support for 3rd Party NAD (via RADIUS proxy) ✔️
Client Onboarding using the Onboard App ✔️ ✔️
UEM Onboarding using Intune / Jamf ✔️ ✔️
Static Tags ✔️ (Limited to 10 per Tenant and MAC Address) ✔️ (Limited to 400 per Tenant and 10 per MAC Address)
Air Pass SIM ✔️ ✔️
Air Pass OpenRoaming ✔️ ✔️

Core Feature Set Overview

The Central NAC Core vs Subscription Capabilities Comparison table showed earlier covers the capabilities that are availble in the Central NAC Core feature set and are included by default with the Aruba Central foundation or advanced licenses requiring no additional licensing to enable these features.The core capabilities in Central NAC offers a comprehensive set of baseline capabilities designed to support core network access use cases, identity integration, and guest access scenarios. It is ideal for organizations looking for a solid starting point without the need for advanced policies, multi-vendor NAD support, or Bring your own Certificates.

HPE Aruba Networking’s User Role forms the foundation for many of the existing security capabilities available across the portfolio. Every customer should have access to a NAC that makes it simple to unlock and apply these capabilities. In fact, many customers are eager to leverage these features to strengthen their network security posture.

This is precisely why we include the above feature set in the Core capabilities. By making these capabilities universally available, we ensure that every organization—regardless of size or maturity—can implement consistent role-based access control, simplify onboarding, and establish a secure baseline for their network. The Core capabilities serve as the entry point to modern NAC, giving customers immediate value while providing a pathway to adopt more advanced capabilities as their needs evolve.

The following section outlines the key differences in feature between the Core capabilities and Central NAC subscription capabilities. It highlights which capabilities are present in Core and which are exclusive to the subscription tier. This will help users quickly identify what is accessible in their current setup and what additional functionality becomes available with the subscription.

As part of the core capabilities, only a single corporate IdP can be configured.



Bring Your Own Certificate (BYOC) capabilities are not available in the Core tier.



Custom policy type is not available. You can define only one User or Client policy, and its pre-conditions are automatically set based on the selection and cannot be modified..



Only User Groups from the IdP, Client Category, and Client Tags are allowed as conditions in AuthZ rules. A default session timeout of 8 hours is enforced (not editable), and VLAN assignment is not supported.



Only Client Category, and Client Tags are allowed as conditions in Client access AuthZ rules. A default session timeout of 8 hours is enforced (not editable), and VLAN assignment is not supported.



Central NAC Subscription Overview

The Subscription capabilities builds on the core capabilities by offering enhanced security and policy capabilities for organizations with more complex requirements. It provides support for multiple identity providers, granular policy control, Bring your own certificate capabilities and much more. With these features, customers can extend their network access control beyond the baseline, enabling stronger compliance and more flexibility in aligning access policies with business needs. The advanced options covered under subscription capabilities would only be visible in the UI once the NAC subscription is applied.

How licenses usage is calculated

A NAC subscription is required if any of the subscription capabilities listed above are to be enabled. Once the NAC subscription is applied, subscription usage is based on number of connected devices or concurrent sessions. Each connected device consume a license at the start of session and once the session ends, the license is released. RADIUS accounting START and STOP messages are used to determine if the device is still connected. In cases where RADIUS Accounting is not enabled, the license would be consumed for 24 hours.

If the license usage threshold is reached, Central NAC will present an alert notifying of the license exhaustion but the authentication would continue to work.

INFO

Once Central NAC subscription is applied, all connected devices will consume a license regardless of whether they are using core capabilities or subscription capabilities

Central NAC Subscription Capabilities

Let us now walk through the additional enhanced capabilities that the Central NAC subscription offers.

Multiple corporate IdPs are supported, whether of the same type or different providers. For example, you can configure multiple Entra ID identity stores alongside additional identity stores for Google Workspace or Okta..



When using the default certificate option for EAP-TLS, client certificates can be issued with validity periods of 90, 180, or 365 days. In the core capabilities tier, customization of client certificate validity is not available, and the default validity period is set to 365 days



Custom policies and pre-conditions can be defined as needed.



Policy rules support a broader set of matching conditions, including the User Group from the identity store defined in the corresponding authorization policy. With support for multiple IdPs, it is easier to identify which identity store is being referenced when creating authorization rules.



Session timeout is configurable, and the VLAN ID can be sent as an attribute to the NAD. This is especially important for third-party NAD devices, Returning a VLAN ID overrides the value defined in the role configuration



Support for third-party NADs is provided through RADIUS proxy to Central NAC. This requires an AOS 10.7.2 or later Gateway, where the third-party NADs communicate with the AOS Gateway, which in turn proxies the RADIUS requests to Central NAC using the RADIUS proxy profile feature available with the Central NAC subscription.







The Central NAC subscription enables Bring Your Own Certificate (BYOC) capabilities in authentication profiles, allowing customers to leverage their own PKI infrastructure for issuing EAP-TLS client certificates. The custom certificate option in the authentication profile supports adding trusted CAs, enabling Central NAC to accept certificates issued by external certificate authorities.



Static tags can be applied to entries in MAC Address store. With core capabilities, up to 10 tags can be assigned per MAC Address while with subscription capabilities, up to 400 can be applied.



The Core and Subscription capabilities of HPE Aruba Networking Central NAC provide organizations with a clear path to strengthen network security and simplify access control. The Core capabilities ensures every customer can establish a secure baseline with essential features such as certificate-based authentication, identity provider integration, and policy enforcement. Central NAC subscription expands these capabilities with greater flexibility, granular policy controls, support for multiple IdPs, and advanced integration options for complex environments.

Together, these tiers empower organizations to adopt NAC at their own pace starting with foundational security and seamlessly scaling to advanced capabilities as their needs evolve.

Licensing FAQs

Q: What happens if the subscription expires? Will services be impacted?

A: If subscription expires, HPE Networking Central would generate alerts notifying the administrators. Warning messages would also be displayed on Central NAC web interface. At present, there is no enforcement which means NAC functionality would not be restricted and there should be no impact to services.

Q: What license do I need for the visibility and profiling provided by HPE Networking Central Client Insights?

A: Client classification, custom tags and extension integrations provided by HPE Networking Central Client Insights is included with the NAC Subscription. If not using NAC Subscription:

  • Client classification is included with the device foundation license
  • Ability to use custom tags and attributes fetched through extension integrations would require device advanced license

Q: How are licenses applied for MSP tenants

A: Subscriptions owned by the tenant in a MSP workspace are applied and managed at the specific tenant level just like a non MSP tenant. Ability to add MSP owned subscriptions to specific tenants is not yet supported today.

Q: I have a scenario where I need to add multiple external IDPs (Microsoft Entra and Okta) for corporate 802.1X authentication for 1000 devices. I also want to setup visitor self registration workflow for up to 1000 guest devices. Multiple IDPs are a subscription capability while visitor self registration is part of core capabilities. How many NAC subscriptions would I need? Can I use NAC subscription only for the 1000 devices doing 802.1X authentication?

A: NAC subscription is required to enable multiple external IDPs. The subscription is to enable the advanced capabilities within Central NAC and once it is applied, all devices authenticating through Central NAC whether they are using core or subscription capabilities would count against the subscription. Hence in this example, 2000 NAC subscriptions would be required.


Last modified: June 4, 2026 (5be1427f)