Blog01 August 20262 min read491 words

What Is NAC (Network Access Control)? And Why You Need It

A practical guide to Network Access Control (NAC): what it does, the core capabilities of SignLogger's NAC module (802.1X, MAB, dynamic VLANs, device profiling, posture checks, BYOD and guest access), real-world industry scenarios, and how NAC supports Law No. 5651 and KVKK compliance.

#nac#network-security#802-1x#byod

The classic approach to network security assumed that "anyone with physical access to the network can be trusted." By 2026, that assumption has long since collapsed. Guest devices, employees' personal phones, IoT sensors, printers, cameras — everything is connecting to the network. Network Access Control (NAC) is the layer that governs, in this new reality, who connects to the network, when, with which device, and with what privileges.

NAC's Central Question: "Who Are You?"

When a device connects to the network, the NAC system asks:

  • Who: User identity (Active Directory, LDAP, certificate)
  • What: Device type (corporate laptop / personal phone / IoT)
  • Where: Which switch port, which access point, which location
  • Is it healthy: Is antivirus up to date, is the OS patched, is the disk encrypted
  • Is it authorized: Is this user permitted to use this device

The answers are evaluated, and the device is routed to the appropriate VLAN (production / guest / quarantine) or denied access altogether.

Capabilities Supported by the SignLogger NAC Module

802.1X Authentication

Industry-standard, port-based authentication. Supports the EAP-PEAP (username + password), EAP-TLS (certificate) and MS-CHAPv2 protocols.

MAB (MAC Authentication Bypass)

MAC address-based authentication for devices that cannot support 802.1X (printers, IP phones, IoT). Managed via whitelisting or device profiling.

Dynamic VLAN Assignment

Based on identity and device type, the user is automatically assigned to the correct VLAN. Different users plugging into the same switch port can land on different networks.

Device Profiling

Automatic device-type detection from DHCP fingerprints, OUI (MAC vendor), HTTP user-agent and LLDP/CDP data. Whether it's a printer, an Apple TV or a Windows laptop — it can tell the difference.

Posture Check

The device's security state is verified: is antivirus active, what is the OS update level, is the disk encrypted, is the firewall enabled. If it doesn't meet the requirements, it is moved to a quarantine VLAN.

BYOD Onboarding

A self-service portal for connecting an employee's personal device to the network. Certificate generation is handled automatically, and the device is registered.

Guest Flow

NAC and hotspot on a single infrastructure. Guests are directed to the captive portal and, once authenticated, are granted network access.

Industry Scenarios

  • Hospital: Devices are separated into HIS, PACS and administrative VLANs; visitors are kept apart.
  • University: Student / faculty / staff / researcher segments; exam VLANs are isolated.
  • Factory (OT/IT): Production-line devices are absolutely prevented from communicating with the office network; NAC isolates them dynamically.
  • Hotel: Guests + staff + back office + payment terminals — all separated, all auditable.

NAC + Law No. 5651 + KVKK

NAC records provide clear answers to who connected, when, and with which device. As a result:

  • The user-identification requirement under Law No. 5651 is fully met;
  • Access records (audit logs) are kept complete for KVKK (Law No. 6698) purposes;
  • In the event of a security incident, root-cause analysis takes minutes rather than hours.

Take a closer look at the SignLogger NAC module or request a deployment-focused demo.

Last updated: 01 August 2026

Questions about SignLogger?

Contact us