Skip to content

Network Access Control

Decide what a device is before deciding what it may reach.

What this is

Network access control authenticates and profiles a device as it connects, then places it where policy says it belongs — production, guest, quarantine or remediation. It is what turns a network port from an open door into a decision.

It is also the capability most often abandoned mid-deployment, for one reason: enforcement is switched on before anybody knows what is on the network. Monitor mode first is not caution, it is the only way to build a policy that will not lock out a production system nobody documented.

When you need it

If more than one of these is true, this is usually the right place to start.

  • Any network port in the building granting full access to whatever is plugged into it.
  • No reliable inventory of what is actually connected, particularly printers, cameras and building systems.
  • Contractors and personal devices on the same network as production systems.
  • An audit or insurance requirement to demonstrate control over network admission.

What the scope covers

  • Discovery and profiling in monitor mode: what is connected, what it claims to be, and what it actually behaves like.
  • Policy design per device class, including the unmanaged devices that cannot run a supplicant.
  • 802.1X for managed endpoints, with MAC authentication bypass and profiling for everything else.
  • Posture checking so access depends on device state, not just identity.
  • Phased enforcement with a remediation path, so a failed check is recoverable without a help-desk call.

What you receive

DeliverableWhat it contains
Device inventoryEverything seen on the network, profiled and classified, with the unidentifiable set flagged for a decision.
Access policyPer class: what it must prove, where it lands, and what happens when it fails the check.
Enforcement planPhased by area and device class, with exit criteria per phase and a documented rollback.
Operations runbookOnboarding a new device type, handling a failure, and the exception process with its approver.

Reference architecture

A reference, not a template. Your estate decides which parts apply and in what order they arrive.

Network access control reference architecture: access, control and visibility layersAccess: 802.1X, MAB, Guest Portal. Control: Policy Engine, Posture Check, Dynamic VLAN. Visibility: Device Profiling, Session Audit, SIEM FeedAccess802.1XMABGuest PortalControlPolicy EnginePosture CheckDynamic VLANVisibilityDevice ProfilingSession AuditSIEM Feed
Network access control reference architecture: access, control and visibility layers

How success is measured

Targets are agreed with you before the work starts, and reported against for its duration.

  • Share of connected devices identified and classified, and the trend of the unknown set.
  • Ports under enforcement as a proportion of the estate, by phase.
  • Access failures caused by policy rather than by genuine posture problems — the number that shows whether the policy is right.

Questions we are asked

  • Will this lock people out?

    It will if enforcement precedes discovery. Run in monitor mode long enough to see everything, including the devices that only appear at month-end, then enforce by area with a remediation path. Done that way, disruption is small and recoverable.

  • What about devices that cannot do 802.1X?

    Printers, cameras, badge readers and industrial equipment usually cannot. They are handled by MAC authentication bypass with profiling, so a device claiming to be a printer is checked against whether it behaves like one — which is also how MAC spoofing is caught.

  • Is NAC still relevant with remote work?

    Yes, and the two are complementary. Zero-trust network access covers the remote user; NAC covers the physical port, which is still where the printer, the camera and the visitor's laptop connect.

  • How long does a deployment take?

    Discovery and policy design are typically weeks. Enforcement is deliberately longer and phased, because the pace is set by how quickly you can resolve the unidentified devices rather than by the technology.

  • Does it work across wired and wireless?

    It should, and a policy that covers only one is a gap by design. The same class and posture rules apply at both, so a device does not gain by choosing a different medium.

  • What does posture checking actually check?

    Whatever you decide is worth blocking on — patch level, disk encryption, whether the endpoint agent is running. Keep the list short: every check is a way to fail, and a long list produces lockouts nobody can diagnose.

Continue reading

  • Networking

    The full domain, and the other capabilities within it.

  • Network Monitoring

    Discovery, telemetry and alerting tuned so that an alert means something — with thresholds set from observed baselines rather than defaults.

  • Network Infrastructure

    Switching, routing and structured cabling designed for the traffic you will have in five years, not the traffic you had when the building opened.

Start with an assessment

The fastest way to a useful answer is a short, scoped look at what you already have.