🚪 NAC

Network Access Control for Identity-First, Posture-Aware Connectivity

Network Access Control (NAC) decides who/what may connect to your wired, wireless, and VPN networks—only if identity is proven and the device is healthy.
SolveForce designs NAC so every port and SSID becomes Zero-Trust-aware: 802.1X EAP-TLS by default, posture checks (EDR/UEM), dynamic VLAN/ACL/SGT assignment, quarantine on failure, and auditable logs to SIEM/SOAR.

Where NAC fits in the SolveForce model:
🔒 Security (Semantics)Cybersecurity • 🔑 IdentityIAM / SSO / MFA
🖥️ Device trustMDM / UEM • 🛡️ EndpointEDR / MDR / XDR
🔐 AccessZTNA / SASE • 🧭 Routing/SD-WANSD-WAN
🪪 Certificates/KeysPKIKey Management / HSM • 🔐 Encryption
🖧 FabricNetworks & Data Centers • 🌐 Connectivity • 📊 SIEM / SOAR


🎯 Outcomes (What strong NAC delivers)

  • Least-privilege by default — every port/SSID enforces identity and device posture before access.
  • Automated segmentation — dynamic VLANs/ACLs/SGTs (Scalable Group Tags / TrustSec-style) based on who/what/where.
  • Quarantine & coaching — non-compliant devices land in remediation; users get clear steps to fix.
  • IoT/OT safety — headless devices profiled and isolated; per-function micro-segmentation.
  • Audit-grade evidence — who/what/when/where + policy decision + posture status shipped to SIEM/SOAR.

🧭 Scope (Wired, Wireless, VPN, Guest, IoT/OT)

  • Wired access (802.1X on edge switches) — EAP-TLS for corp devices; MAC Authentication Bypass (MAB) only for vetted exceptions.
  • Wireless (WPA2/WPA3-Enterprise) — EAP-TLS + posture; dynamic roles for staff/guest/contractor/IoT SSIDs.
  • VPN — identity + device posture at tunnel start; dynamic group policies; short re-auth timers.
  • Guest/Contractor — sponsor portal / captive portal with time-boxed credentials; bandwidth and app restrictions.
  • IoT/OT — cameras, printers, scanners, POS, sensors: profile → tag → isolate; DHCP/LLDP/OUI fingerprinting + device posture where possible.

🧱 Building Blocks (Spelled out)

  • 802.1X / EAP-TLS — certificate-based port/SSID authentication; strongest, phishing-resistant. → PKI
  • RADIUS / Change of Authorization (CoA) — real-time authorization and re-auth; change device policy on the fly.
  • Posture assessment — check EDR health, disk encryption, OS level, jailbreak/root, UEM enrollment. → MDM / UEMEDR / MDR / XDR
  • Dynamic policiesVLAN/ACL/SGT assignment per role, device type, and risk.
  • Profiling — LLDP/CDP, DHCP fingerprints, OUI, traffic heuristics for headless IoT/OT.
  • Guest services — sponsor approval, SMS/e-mail vouchers, captive portal, legal banner.
  • Logging & evidence — decision logs (authN/authZ), posture, CoA events → SIEM/SOAR. → SIEM / SOAR

🔐 Policy Model (Identity → Device → App → Data → Context)

A NAC decision evaluates five lenses before granting network access:

  1. Identity — user/service group via IAM/SSO/MFA; separate admin identities. → IAM / SSO / MFA
  2. Device postureUEM/EDR health, OS min, encryption on, certificate present. → MDM / UEMEDR / MDR / XDR
  3. Application needs — map to SGT/VLAN/ACL sets; minimal east-west access.
  4. Data sensitivityDLP labels narrow access to restricted zones; read-only where needed. → DLP
  5. Context — site/geo/ASN, time window, change ticket, session risk.

Outcome: allow (role VLAN/SGT)step-up (MFA or posture remediation)isolate (quarantine VLAN/guest)deny.


🧰 Controls (Concrete & enforceable)

  • Certificates everywhere — 802.1X EAP-TLS for corp devices; device/user certs auto-enrolled via MDM/PKI. → PKI
  • Dynamic segmentation — assign VLAN/ACL/SGT per role; push CoA on posture change.
  • Quarantine VLAN — walled garden + remediation portal; redirect until compliant.
  • Command & visibilityRADIUS accounting, netflow/IPFIX, DHCP/DNS logs to SIEM.
  • Headless/legacy (MAB) — static MAC lists only as last resort; tag as Restricted; watch for spoof; rotate to certs asap.
  • Guest access — time-boxed creds, bandwidth caps, DNS filtering, L7 threat block via SASE. → SASE
  • OT/IoT — profile, tag minimal policies, deny east-west; separate mgmt plane; monitor with NDR. → NDR

☁️ & WAN Integrations (Real-world interlock)

  • SD-WAN — honor NAC tags (SGT/role) across the fabric; app-aware steering per role/SLO. → SD-WAN
  • ZTNA/SASE — NAC decides who gets a port; ZTNA/SASE decides which app per session. → ZTNASASE
  • PKI/KMS/HSM — issue/rotate device certs; keep private keys non-exportable. → Key Management / HSM
  • SIEM/SOAR — contain via NAC: CoA, quarantine VLAN, or port-shut on incident; all actions auditable. → SIEM / SOAR

📐 SLO Guardrails (Experience you can measure)

Metric (p95)Target (Recommended)Notes
802.1X auth time (wired/wifi)≤ 1–3 s / ≤ 2–5 sCached EAP-TLS + fast RADIUS
Posture eval to CoA≤ 30–90 sHealth change → policy change
Guest onboarding≤ 60–120 sSponsor approval + captive
False reject rate≤ 1–2%Tune cert chains & supplicants
Availability (RADIUS/NAC core)≥ 99.99%Dual NAC nodes + site HA
Evidence completeness100%AuthN/Z + posture + CoA logs

🛠️ Implementation Blueprint (No-surprise rollout)

  1. Inventory — switches/APs/VPN concentrators, sites/ports, SSIDs, device types (corp/BYOD/IoT/OT).
  2. Identity & PKI — pick identity sources, define groups/roles, plan EAP-TLS cert issuance/rotation. → IAM / SSO / MFAPKI
  3. Policy design — role matrix → VLAN/ACL/SGT; quarantine & guest policies; MAB exceptions register.
  4. Posture baselines — UEM/EDR min versions, encryption on, firewall on, jailbreak/root blocked. → MDM / UEMEDR / MDR / XDR
  5. Pilot rings — a floor/SSID first; enable 802.1X with fail-open (brief), then fail-closed; measure SLOs.
  6. Automations — remediation portal, self-service cert fix, CoA triggers; change windows documented.
  7. Logging — RADIUS accounting, DHCP/DNS, netflow to SIEM; SOAR playbooks for quarantine. → SIEM / SOAR
  8. Go broad — campus → branches → datacenter mgmt VLANs; retire MAB; quarterly posture raises.

🧩 Policy Matrix (example sketch)

Role/TypeAuthPostureNetwork Result
Corp-LaptopEAP-TLS (cert)EDR+UEM healthyCorp VLAN + SGT=Staff; full intranet
Admin-WorkstationEAP-TLSEDR healthyAdmin VLAN; mgmt ACL; session recording
BYODPortal + SSOWork profile okInternet-only; ZTNA to private apps
ContractorEAP-TLS/PortalEDR/UEM (vendor)Restricted VLAN; allow only needed apps
Printer/CameraMAB (temp)N/A (profiled)IoT VLAN; block east-west; mgmt only
Non-compliantAnyFails postureQuarantine VLAN + remediation portal

🧾 Compliance Mapping (Examples)

  • PCI DSS — segment cardholder data environment; strong auth at ports; logging.
  • HIPAA — device accountability; isolation of PHI networks; audit trails.
  • ISO 27001 — A.9 access control; A.12 operations; A.13 network security.
  • NIST 800-53/171 — AC-17/18, IA-2, CM-7 (least privilege, device auth, configuration).
  • CMMC — controlled access & auditing for CUI zones.

All NAC decisions stream to SIEM with immutable evidence and case linkage. → SIEM / SOAR


✅ Pre-Engagement Checklist

  • 🔐 Identity sources (IdP/AD), group/role taxonomy, MFA rules.
  • 🪪 PKI readiness (device/user certs), auto-enrollment via UEM. → PKIMDM / UEM
  • 🧩 Switch/AP/VPN capabilities (802.1X, CoA, SGT/TrustSec-like tags).
  • 🧠 Posture baseline (EDR/UEM, OS minimums, encryption).
  • 🗺️ Policy matrix (roles → VLAN/ACL/SGT); quarantine design.
  • 🧪 Pilot plan (sites/SSIDs), rollback strategy, SLO targets.
  • 📊 Logging destinations & retention (SIEM), SOAR playbooks for quarantine.

🔄 Where NAC Fits (Recursive View)

1) Grammar — access rides Connectivity & the Networks & Data Centers fabric.
2) Syntax — auth flows and segmentation patterns in Cloud & WAN.
3) SemanticsCybersecurity preserves truth; NAC proves device/identity before entry.
4) PragmaticsSolveForce AI spots anomalies, predicts drift, and suggests auto-quarantine.
5) Foundation — consistent terms via Primacy of Language.
6) Map — indexed in the SolveForce Codex & Knowledge Hub.


📞 Deploy NAC That’s Identity-First & Audit-Ready

Related pages:
CybersecurityIAM / SSO / MFAMDM / UEMEDR / MDR / XDRZTNASASESD-WANSIEM / SOARNetworks & Data CentersKnowledge Hub