At this point, if you don't have to attempt to integrate with the Aruba Clear Pass system, you should probably avoid it. We attempted to use the API early on and had all kinds of issues that Aruba couldn't explain. They went back to the drawing board, and we settled Radius Accounting, after building out a bunch of backend, Active Directory group stuff, with the promise that the API would be fixed and updated.
Radius Accounting was great, up until you need Clear Pass to send updates to the firewall in a timely manner. We see 5 to 20 minute delays between user log in and the messages being sent by the Aruba side.
Months waiting, new code provided, still seeing same weirdness with the API, and an inability to explain why Clear Pass is doing what it is doing.
In my opinion, Clear Pass integration via API or Radius Accounting on a large network is half-baked at best. Because the integration piece is just so broken right now, we are going to have to crack open our firewall rules and do enforcement on the Aruba side...So goodbye to my easy to understand, troubleshoot and log Check Point rules I think.