NAC Solutions
See every user and device joining your network with Fortinet FortiNAC, HPE Aruba ClearPass, Limatek LIMRAD and S3M ConnGuard; grant access by identity.
Know Who and Which Device Is Connecting to Your Network
Using a firewall alone is not enough in corporate network security.
Once a device connects to the corporate network, the questions;
Who owns this device? Is it a corporate device? Does it meet security policy? Which VLAN should it join? Which systems can it reach? Is it a guest user? Is it an IoT or OT device? Can it be removed from the network automatically once it becomes risky?
need to be answered.
NAC – Network Access Control is the security technology identifying the users and devices connecting to the corporate network, assessing their security posture and controlling their network access dynamically according to the policies built.
With the;
Discover → Identify → Authenticate → Authorize → Assess → Segment → Monitor → Respond
approach, modern NAC solutions have become one of the core components of network access security.
Within SecureSys NAC Solutions we build central access security architectures for organizations' wired, wireless, VPN, BYOD, IoT and other network access environments with the;
Fortinet FortiNAC HPE Aruba Networking ClearPass Limatek LIMRAD NAC
technologies.
What Is NAC – Network Access Control?
Network Access Control is the technology assessing a user's or device's compliance with security policy both before and after it connects to the corporate network.
NAC's core purpose is not merely to carry out user authentication.
The real purpose is;
Who + Which Device + From Where + How + With What Security Posture
to determine the appropriate access level automatically by assessing these questions about what is connecting to the network.
For example;
Corporate Laptop + Authorized Employee + Secure Endpoint → Corporate VLAN
Personal Phone + Employee → BYOD VLAN
Guest User → Guest Network / Internet Only
Endpoint Not Meeting Security Policy → Quarantine VLAN
dynamic access policies of this kind can be built.
What Is 802.1X?
802.1X is one of the core technologies providing port-based network authentication in corporate networks.
When a user or device connects to a switch port or to the wireless network, authentication is carried out.
The typical architecture:
Endpoint ↓ Switch / Access Point ↓ RADIUS ↓ NAC ↓ Active Directory / Identity Source
works in this way.
Once authentication succeeds, NAC can decide which network segment the user or device will reach.
RADIUS and NAC
RADIUS is one of the important components of NAC architecture.
In authentication and authorization processes the NAC platform can work together with different identity sources such as;
- Active Directory
- LDAP
- Certificate
- Entra ID
- User databases
- Identity Provider
and similar systems.
Network access policy can thereby be applied through user and device identity rather than IP addresses.
TACACS+ and Network Device Administration
Some NAC and policy management platforms can also offer TACACS+ capabilities for controlling administrator access to network devices centrally.
Network administration activity such as;
Who connected to the switch? Who made a change on the firewall? Which administrator ran which command?
can thereby be managed with central identity policy.
Device Profiling
Not every device connecting to the corporate network is a classic user computer.
Hundreds of different device types such as;
- Windows Laptop
- macOS
- Linux
- Mobile device
- IP Camera
- IP Phone
- Printer
- IoT device
- OT system
- Medical device
- Access Point
- Switch
can be present on the network.
NAC solutions can carry out automatic Device Profiling by analyzing the characteristics of devices.
For example, when the system determines that a newly connected device is an;
IP Camera
it can place the device automatically not into the user VLAN but into a Camera VLAN reaching only the necessary video systems.
Rogue Device Detection
Unauthorized devices connecting to the corporate network is a significant security risk.
An employee may connect a personal computer to an ethernet port, or an attacker gaining physical access may try to attach a device to the corporate network.
By identifying devices not defined previously, the NAC solution can carry out the;
Detect → Identify → Restrict / Block → Alert
operations.
Endpoint Posture Assessment
A device holding the correct username and password does not mean the device is secure.
NAC solutions can assess a device's security posture before or after connection.
The checks can include criteria such as;
- Is antivirus active?
- Is EDR running?
- Is the operating system up to date?
- Are the security patches present?
- Is the firewall on?
- Is the corporate agent installed?
- Does the device meet corporate standards?
and similar controls.
Dynamic VLAN Assignment
One of NAC's important characteristics is the dynamic assignment of the user and device to the appropriate VLAN.
For example;
Finance User → Finance VLAN
IT Administrator → IT Management VLAN
Guest → Guest VLAN
IoT → IoT VLAN
Non-Compliant Endpoint → Quarantine VLAN
automatic segmentation of this kind can be applied.
Network Segmentation
NAC technologies help network segmentation be applied dynamically.
In traditional estates, VLAN membership can be defined manually on switch ports.
In NAC architecture, by contrast, access policy can be applied dynamically according to;
Identity + Device + Role + Security Posture + Location
this information.
Microsegmentation
In modern Zero Trust architectures, large VLAN segments alone may not be enough.
With microsegmentation the aim is to permit devices to reach only the systems they need.
An IP camera, for example, may hold the;
NVR Server → Permit
but;
Database Server → Block
policy.
This approach makes it harder for compromised IoT or user devices to carry out lateral movement inside the organization.
BYOD Security
Bring Your Own Device policies allow employees to connect their personal devices to the corporate network.
Granting personal devices the same access as corporate endpoints, however, can create a serious security risk.
With NAC;
Corporate Device BYOD Guest Contractor
devices can be separated from one another and different security policies applied.
Guest Access
The internet access of guest users can be managed centrally through NAC.
For guest users;
- Captive Portal
- SMS / E-Mail verification
- Sponsor Approval
- Time-limited access
- Terms of use
- Guest VLAN
- Internet Only
policies can be built.
IoT Security
IoT devices are one of the biggest visibility problems of modern corporate networks.
IP cameras, printers, sensors, IP phones and other IoT systems mostly cannot run traditional endpoint agents.
NAC's agentless device profiling capabilities therefore carry critical importance for IoT security.
NAC in OT / ICS Environments
In manufacturing and critical infrastructure, the network access of;
- PLC
- HMI
- SCADA
- Engineering Workstation
- Industrial IoT
systems carries critical importance.
NAC technologies can be used to identify OT devices and apply controlled network segmentation.
When applying access policy in OT environments, however, production continuity and device compatibility must be taken into account.
Zero Trust and NAC
NAC is one of the important components of modern Zero Trust architecture.
Zero Trust's core approach is expressed as:
Never Trust, Always Verify
this principle.
A device being physically inside the organization does not mean it is trustworthy.
Every connection should be assessed in the context of;
User Identity + Device Identity + Security Posture + Location + Risk
these factors.
NAC and Active Directory
NAC platforms can be integrated with Active Directory so user and group information is used in network access policy.
For example, the;
AD Group: Finance → Finance Network
or;
AD Group: Contractor → Limited Network
policies can be built.
NAC + EDR
EDR and NAC integration can create rather powerful automated response scenarios.
For example:
EDR ↓ Ransomware Detected ↓ NAC ↓ Endpoint Quarantine ↓ Network Isolation
The compromised endpoint's access to other systems inside the organization can thereby be restricted automatically.
NAC + SIEM + SOC
The;
- Authentication
- Device Discovery
- Rogue Device
- Policy Violation
- Quarantine
- Failed Authentication
events produced by NAC can be carried into the SIEM.
SOC teams can analyze this data together with firewall, EDR, Active Directory and other security events.
Fortinet FortiNAC
Network Access Control and Zero Trust Access
FortiNAC is Fortinet's corporate Network Access Control solution.
In Fortinet's current approach, FortiNAC focuses on providing visibility, control and automated response for the digital assets connecting to the network, from IT devices to IoT, OT/ICS and IoMT systems.
FortiNAC can also work integrated with the Fortinet Security Fabric.
Advanced Device Profiling
FortiNAC tries to determine the identity of the assets on the network by profiling devices through different methods.
Fortinet's current product documentation states that 21 different profiling methods can be used.
This structure is important for the visibility of systems such as;
- IoT
- OT
- Camera
- Printer
- Medical devices
on which an agent cannot be installed.
Multi-Vendor NAC
FortiNAC is not a NAC designed only for Fortinet switch and access point infrastructure.
It can be positioned alongside existing switches, APs, firewalls and other network devices in multi-vendor network environments.
This characteristic is important particularly for large organizations that have come to use the network equipment of different vendors over the years.
Dynamic Network Access
FortiNAC can change network access dynamically according to the user and device profile.
For example;
Corporate BYOD Guest Printer Camera IoT Quarantine
logical network structures of this kind can be built so devices are assigned automatically to the appropriate network segment.
Automated Response
One of FortiNAC's important use cases is applying automated network response to security events.
A risky or unauthorized device can be restricted within the network with the;
Detect → Identify → Policy Violation → Restrict / Isolate
approach.
Fortinet Security Fabric Integration
FortiNAC;
FortiGate + FortiSwitch + FortiAP + FortiClient + FortiAnalyzer + FortiSIEM
can be made part of a wider network security architecture together with Fortinet Security Fabric components of this kind.
Who Is FortiNAC Suitable For?
It can be assessed particularly for;
- Organizations holding Fortinet infrastructure
- Multi-vendor network environments
- Organizations wanting IoT visibility
- OT/ICS infrastructure
- Multi-branch organizations
- Zero Trust projects
- Organizations needing dynamic segmentation
these estates.
HPE Aruba Networking ClearPass
Identity-Based Network Access Control
HPE Aruba Networking ClearPass Policy Manager is an advanced Network Access Control and policy management platform placing user and device identity at its centre.
ClearPass offers the;
Authentication + Authorization + Device Profiling + Posture Assessment + Guest + BYOD + Policy Enforcement
capabilities within the same NAC architecture.
Role-Based Access Control
One of ClearPass's strengths is that it can build detailed role-based network policy.
Policies can be applied through contextual information such as;
- The user's role
- Device type
- Authentication method
- Device Health
- UEM information
- Location
- Time
and similar signals.
ClearPass Policy Manager
ClearPass Policy Manager is the central NAC policy engine.
Authentication and authorization are carried out so the network access a user or device will hold can be determined.
The platform supports common network authentication protocols such as RADIUS and TACACS+.
ClearPass OnGuard
ClearPass OnGuard can be used for endpoint posture assessment.
The endpoint's compliance with corporate security policy is assessed so non-compliant devices can have their access restricted or be directed to a quarantine network.
ClearPass Onboard
ClearPass Onboard makes the processes for bringing BYOD devices onto the corporate network securely easier in particular.
Users' personal devices can be registered in a controlled way and the necessary identity/certificate operations carried out.
ClearPass Guest
For managing guest network access;
- Guest Portal
- Self Registration
- Sponsor Approval
- Time-limited user accounts
- Guest policies
can be built.
Multi-Vendor Network
ClearPass is not limited to Aruba network devices alone.
Thanks to HPE Aruba Networking's open and multi-vendor approach, integration with different network and security technologies can be carried out.
Who Is ClearPass Suitable For?
It forms a strong NAC alternative particularly for;
- Large campus networks
- Universities
- Hospitals
- Financial institutions
- Large Enterprise estates
- Dense Wi-Fi infrastructure
- Organizations with heavy BYOD use
- Guest network requirements
- Multi-vendor network infrastructure
these organizations.
S3M Security NAC
Hybrid NAC and Zero Trust Network Access Control
S3M Security NAC is a Turkish-made Network Access Control platform for managing user and device access centrally across organizations' wired, wireless, remote access and mobile connection layers.
In its current approach, S3M Security does not limit NAC technology to controlling LAN and Wi-Fi access alone.
The platform aims to position the;
NAC + Endpoint Management + Guest Access + Private APN + Remote Access
capabilities under a shared access security architecture.
The Vendor-Agnostic NAC Approach
One of S3M Security's important positioning characteristics is its vendor-agnostic architecture.
This approach aims for the NAC solution to work together with the existing network infrastructure without depending on a particular switch, firewall or wireless vendor.
This characteristic can offer a significant advantage particularly in Enterprise estates holding more than one network vendor.
Identity-Driven Zero Trust
In the S3M NAC approach, access policy can be assessed not through IP or MAC address alone but in the context of;
User Identity + Device Identity + Connection Type + Authorization + Security Policy
these factors.
This structure helps Zero Trust principles be applied at the network access layer.
S3M ConnGuard
S3M Security's solution on the NAC side is positioned as ConnGuard.
With ConnGuard the aim is to control the access carried out to the corporate network, identify unauthorized connection attempts and manage user/device access with central policy.
Connections that are unauthorized or that do not meet the necessary authentication and authorization controls can be logged and their access restricted.
Network SSO and User Visibility
S3M Security NAC also supports the Network SSO approach for making user identity on the network visible.
Security teams can thereby see not only the device's IP address but also which user the connection concerned relates to.
This information helps security events be analyzed in user context in;
Firewall + NAC + SIEM + SOC
these integrations.
Wired and Wireless Network Access
S3M NAC aims for corporate users to be controlled across different access layers.
Among these can be;
- Ethernet
- Wi-Fi
- VPN
- Gateway access
- Remote user connections
- Mobile and cellular connections
these layers.
S3M's current platform approach extends traditional NAC scope in particular, bringing to the fore the management of wired, wireless and cellular access layers under shared Zero Trust policy.
Private APN and Mobile Access Security
One of the areas in which S3M Security differs from classic NAC solutions is the inclusion of mobile and private APN access in the security architecture.
Particularly in scenarios such as;
- Field teams
- IoT devices
- Mobile terminals
- Critical infrastructure systems
- Defence projects
- Remotely connected devices
including not only Ethernet and Wi-Fi but the mobile communication infrastructure in access policy can be important.
Guest Access
Guest users can be given controlled access to the corporate network.
With the guest access approach;
Guest User → Authentication → Time-Limited Access → Guest Network → Internet Only
policies of this kind can be built.
Visitor and corporate user traffic can thereby be separated from one another.
Endpoint Management
S3M Security positions its NAC approach together with endpoint management.
The device connecting to the network can thereby be assessed not only at the moment of connection but together with its device state and access context.
This approach aims to provide a wider;
User + Device + Network + Endpoint
visibility than classic NAC.
Who Is S3M Security NAC Suitable For?
It can be assessed particularly for;
- Organizations wanting a Turkish-made NAC solution
- Public institutions
- Defence industry
- Critical infrastructure
- Estates using telecom and mobile connectivity
- Multi-vendor network environments
- IoT and remote device infrastructure
- Zero Trust projects
- Organizations using a Private APN
these estates.
The Updated NAC Product Portfolio
We can position the SecureSys NAC product portfolio in this way:
Fortinet FortiNAC Security Fabric, IoT/OT visibility, dynamic segmentation and automated response.
HPE Aruba Networking ClearPass Identity-Based NAC, 802.1X, RADIUS/TACACS+, BYOD, Guest and Posture Management.
Limatek LIMRAD NAC Turkish-made NAC; network access security focused on user/device control and local support.
S3M Security NAC / ConnGuard Turkish-made, vendor-agnostic Hybrid NAC; an access security platform managing wired, wireless, remote and cellular access under a shared Zero Trust approach.
Which NAC Product Stands Out in Which Estate?
FortiNAC In Fortinet-heavy estates or where IoT/OT visibility is critical.
ClearPass For large campus, dense Wi-Fi, 802.1X, BYOD and identity policy requirements.
LIMRAD NAC In projects where a domestically developed product and classic corporate NAC requirements are to the fore.
S3M Security NAC Can be assessed in projects where, alongside a domestically developed product, the scope of Hybrid NAC, vendor independence, Private APN, remote and mobile access matters.
Limatek LIMRAD NAC
Turkish-Made Network Access Control Solution
Limatek LIMRAD NAC can be positioned as a Turkish-made NAC solution for controlling organizations' network access centrally.
The core aim with LIMRAD NAC is to make the users and devices connecting to the corporate network visible and to control their network access according to the security policies built.
A domestically developed NAC alternative can be an important part of the product selection criteria particularly in public sector, defence industry and critical infrastructure projects.
Central Network Access Control
In the LIMRAD NAC architecture the aim is to centralize access decisions by assessing;
User + Device + Network + Authorization + Security Policy
this information together.
Control of Unauthorized Devices
Detecting unknown or unauthorized devices connecting to the corporate network is one of NAC's core use cases.
Devices not defined can be granted limited access or have their access blocked according to the organization's security policy.
Network Segmentation
Different network segments can be applied per user and device group so access to critical resources is restricted.
For example, the;
Corporate User → Corporate Network
Guest → Guest Network
IoT → IoT Network
Non-Compliant Device → Quarantine Network
approach can be applied.
The Domestic NAC Advantage
One of LIMRAD NAC's important positioning points is that it is a domestically developed technology alternative.
This characteristic can be one of the assessment criteria particularly for;
- Public sector
- Defence industry
- Critical infrastructure
- Projects requiring a domestically developed product
- Organizations with a high need for local technical support
these estates.
The product's specific integration, authentication, posture and device support should be verified before the project through current vendor technical documentation and a POC.
FortiNAC, ClearPass or LIMRAD NAC?
A single NAC solution is not the best option for every organization.
FortiNAC
Fortinet Security Fabric + IoT/OT Visibility + Multi-Vendor + Dynamic Segmentation + Automated Response
is a strong alternative in projects where these needs are to the fore.
HPE Aruba Networking ClearPass
Identity-Based Access + RADIUS/TACACS+ + BYOD + Guest + Posture + Multi-Vendor Network
stands out in large Enterprise and campus environments where these requirements are heavy.
Limatek LIMRAD NAC
Turkish-made NAC + Network Access Control + Local Support + Public Sector/Defence/Critical Infrastructure
can be assessed in projects focused on these factors.
What Should You Consider When Choosing NAC?
The NAC decision should not be made on the existing switch brand alone.
The main criteria that need to be assessed;
- Switch vendors
- Access Point vendors
- 802.1X support
- RADIUS
- TACACS+
- Active Directory integration
- Entra ID / Cloud Identity
- Device Profiling
- Agent / Agentless operation
- Endpoint Posture
- Dynamic VLAN
- Network Segmentation
- BYOD
- Guest Management
- IoT Visibility
- OT Visibility
- Certificate Management
- EDR integration
- Firewall integration
- SIEM integration
- SOAR integration
- High Availability
- Multi-Site management
- API support
- Licensing
should be these.
The SecureSys NAC POC Process
POC carries critical importance in NAC projects.
- 1. Network Discovery — the existing switch, wireless, VLAN and user architecture is analyzed.
- 2. Identity Integration — integration with Active Directory and other identity systems is carried out.
- 3. Device Discovery — the visibility of the devices connected to the network is assessed.
- 4. Device Profiling — whether laptops, phones, cameras, printers, IoT and other devices are classified correctly is tested.
- 5. 802.1X — 802.1X authentication tests are carried out on a controlled user group.
- 6. Dynamic VLAN — the assignment of different user and device types to the correct VLAN is tested.
- 7. Posture — non-compliant endpoint scenarios are applied.
- 8. Quarantine — the automatic restriction of a risky device's network access is tested.
- 9. SIEM / EDR Integration — the sharing of security events with other security platforms is verified.
- 10. Production Rollout — a controlled migration plan is prepared after a successful POC.
SecureSys NAC Solutions
In NAC projects SecureSys addresses not merely the deployment of the NAC software but the whole network access architecture.
The process;
Network Analysis → Switch / Wireless Inventory → Identity Analysis → Product Selection → POC → 802.1X Design → Policy Design → VLAN / Segmentation → Pilot Migration → Endpoint Onboarding → IoT / BYOD / Guest Policies → SIEM / SOC Integration → Production Rollout → Operations & Support
can be carried out in this way.
In our product portfolio, the;
Fortinet FortiNAC HPE Aruba Networking ClearPass Limatek LIMRAD NAC
solutions can be positioned according to the organization's existing network infrastructure and security requirements.
Connecting to the Network Should Not Mean Authorization
In modern network security, a user plugging in an ethernet cable or knowing the Wi-Fi password should not be enough to reach corporate resources.
Real network security requires the questions;
Who are you? Which device are you using? Is your device secure? Which resources should you reach? Can your access be cut automatically when risk arises?
to be answered continuously.
With SecureSys NAC Solutions, make the users and devices connecting to your network visible, manage access according to identity and security posture and strengthen your Zero Trust Network Access architecture.
Request a demo, POC and quote for NAC Solutions
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.