Çözüm13 Ağustos 20265 dk okuma1047 kelime

What Is NAC (Network Access Control)? Network Access Control Solution

What is NAC (network access control) and how does it work? SignLogger's brand-independent NAC solution with 802.1x, captive portal, RADIUS, LDAP/Active Directory and 2FA.

#NAC#network access control#802.1x#RADIUS#captive portal#LDAP#Active Directory#2FA

What Is NAC (Network Access Control)? Network Access Control Solution

NAC (Network Access Control) is a central access-control system that decides who connects to your network, with which device and with which permissions. It answers two core questions: authentication (“is this person or device really who they claim to be?”) and authorization (“now that they are verified, which network, which VLAN and which rules may they access?”). SignLogger’s NAC solution runs on the industry-standard RADIUS protocol and a policy engine behind it; from a single user pool it manages two major scenarios at the same time: 802.1x for the corporate wired/wireless network and the captive portal (hotspot) for guest access. Because it is brand-independent, it integrates over RADIUS with your existing firewalls, switches and access points, letting you control network access centrally without replacing your hardware. It records who connected and when, applies rules through groups and monitors suspicious access.

What does NAC do?

An uncontrolled network carries both security and compliance risk. NAC manages that risk with central rules:

  • Authentication: Every user or device that wants to join the network is verified before access is opened (local password, LDAP/Active Directory, MAC or a second factor).
  • Authorization: A verified user is authorized according to the policy defined for their group; for example, assigned to a specific VLAN or limited by session duration and concurrent-session count.
  • Visibility and record: Who connected, with which device and when is logged; administrative changes are written to the audit log.
  • Segmentation: The guest network is separated from the corporate network; unauthorized devices cannot join.

How does NAC work?

When a user or device wants to join the network, the request first reaches the network device (firewall, switch or access point). The network device forwards this request to SignLogger over RADIUS. SignLogger first verifies the identity (local password or LDAP/AD), asks for a second factor if required (TOTP, SMS, email), checks that the account is active and not expired, resolves the user’s group membership and evaluates the policies bound to that group. The result is either an “accept” decision (with optional extra rules such as a VLAN or a time limit) or a “reject” decision, returned to the network device. Five core concepts make up this flow: the client (NAS) is your network device that sends the request, the user (identity) is the account to be verified, the group is the set that policies are bound to, the policy (rule) is the condition-action logic, and the policy engine is the core that produces the decision on every request.

802.1x and captive portal: one solution, two scenarios

SignLogger NAC covers two different needs from the same user pool:

  • 802.1x (corporate network): Staff and managed devices are verified with EAP over the switch or access point and connect securely to the corporate wired/wireless network; the rule engine manages access with actions such as VLAN assignment.
  • Captive portal (guest Wi-Fi): Guests sign in from a welcome page with SMS verification, sponsor approval or username-password. For details, see the Hotspot & Captive Portal solution page.

Which authentication methods does NAC support?

The goal is to tie every access to a verifiable identity. SignLogger NAC combines several methods on a single platform:

  • Local account: A username and password held in the product.
  • LDAP / Active Directory: Users in your existing directory server are verified and groups are synchronized automatically; the password is not stored in the product.
  • Two-factor authentication (2FA): A second factor via TOTP, SMS or email; it works in interactive logins where a code can be requested (administrator, VPN, portal).
  • MAC-based recognition: For printers, cameras and IoT devices that cannot enter a username — being low-security, 802.1x is preferred for managed devices.

What does the SignLogger NAC solution offer?

  • Brand-independent integration: Works over RADIUS with common brands including FortiGate, Palo Alto, Sophos, SonicWall, WatchGuard, Zyxel, Aruba, Ruckus and Cisco/Meraki.
  • Rule wizard and policy engine: Build condition-action rules (VLAN, duration, concurrent sessions, login-type context) easily with a wizard.
  • Directory integration: User and group synchronization with LDAP/Active Directory; domain join for AD password verification in 802.1x.
  • Security: Brute-force protection, two-factor authentication and an audit log of all administrative events.
  • Monitoring: Sign-in logs and MAC anomaly (spoofing) detection for visibility into suspicious access.
  • Multi-tenant structure: Each administrator sees only the tenant they are authorized for; role-based authorization.

For a detailed walkthrough of setup and every screen, see the SignLogger NAC Management User Guide.

Which organizations need NAC?

Almost any organization that manages guest and staff networks at the same time benefits from NAC: hotels and holiday resorts, hospitals, malls, plazas and business centers, schools and dormitories, manufacturing sites and public institutions. As the number of users and devices grows, manual access management falls short; a central NAC provides both security and operational ease.

Frequently Asked Questions

What is NAC (network access control) in short?

NAC is an access-control system that decides centrally who and which device connects to the network, and with which permissions. It performs authentication and authorization together; SignLogger NAC delivers this with RADIUS and a policy engine.

Why is NAC needed?

Uncontrolled network access is a security and compliance risk. NAC keeps unauthorized devices out, verifies users, authorizes access by group and records who connected when.

What is the difference between 802.1x and captive portal?

802.1x works with EAP for staff and managed-device access to the corporate wired/wireless network; the captive portal verifies guest Wi-Fi entry with a welcome page. SignLogger NAC manages both on a single platform, from a single user pool.

Why is 2FA not requested in 802.1x?

This is designed behavior. In the 802.1x/EAP flow the user cannot be asked for a code mid-conversation, so the second factor is skipped. 2FA works in interactive flows such as administrator login, VPN and the captive portal.

Does SignLogger NAC work with my existing network devices?

Yes. The solution is brand-independent and integrates over RADIUS with devices such as FortiGate, Palo Alto, SonicWall, WatchGuard, Zyxel, Aruba, Ruckus and Cisco/Meraki; you do not need to replace your hardware.

Does NAC integrate with Active Directory / LDAP?

Yes. Users and groups are synchronized automatically from the directory and the password is not stored in the product. For AD password verification in 802.1x, the server must be joined to the domain.

Son güncelleme: 21 Ağustos 2026

SignLogger bu çözümü kurumunuz için nasıl uyguluyor, görün

Ücretsiz demo isteyin