Network Access Control (NAC)
Control which devices and users may connect to your wired, wireless and remote networks, and place each one in the right network segment automatically.
- NIST CSF 2.0 functions
- Protect
- Relevant for
-
- Banking and financial services
- Telecommunications
- Government and public sector
- Oil and gas
Overview
Anyone who can plug a cable into a wall socket or join the wireless network starts inside your perimeter. Printers, cameras and visitors’ laptops often share a network with servers.
We help you decide who and what may connect, check devices before they join and place each one where it belongs, without stopping people from working.
What you get
- Only known and approved devices connect to the network
- Guest, contractor and IoT devices kept apart from critical systems
- Non-compliant devices restricted or sent to a remediation network
- A live list of what is connected, by location and type
What we cover
- 802.1X authentication for wired and wireless networks
- Device profiling for printers, cameras, IoT and OT devices
- Guest and contractor access portals
- Posture checks and automatic segment assignment
- Integration with your directory, MDM and firewalls
- Monitoring and reporting
How we work
-
Discover
We map who and what connects today, including devices that cannot use 802.1X.
-
Design
We design authentication, network segments and policies by device and user type.
-
Monitor first
We run in monitor mode to see the effect before anything is blocked.
-
Enforce and hand over
We enforce in stages, document the policies and train your network team.
Deliverables
- Network access design and policy matrix
- Configured NAC platform
- Staged enforcement plan
- Documentation and administrator training
Questions buyers ask
Will NAC block devices that cannot authenticate?
Not by surprise. We profile them first and give each kind of device a defined path, such as MAC-based rules with restricted access.
Does NAC work with our existing switches?
Usually, if they support the required standards. We check this during discovery.
Related offerings
-
Next-Generation Firewall (NGFW)
Next-generation firewalls that control traffic by application, user and content, with a clean, documented rule base.
NIST CSF function: Protect -
Micro-Segmentation
Fine-grained rules between servers and applications that stop an intruder moving from one compromised system to the next.
NIST CSF function: Protect -
Endpoint Compliance
Continuous checks that every laptop, desktop and server meets your security baseline, with non-compliant devices flagged, fixed or kept away from sensitive systems.
NIST CSF function: Identify NIST CSF function: Protect