Networking · Segmentation
Network Access Control
Authenticating and authorising devices before granting network access, typically with 802.1X and dynamic VLAN or ACL assignment.
AdvancedUpdated 2026-09-01
Overview
NAC answers 'what is allowed on this port or SSID?'. A supplicant presents a certificate or credential, the switch or AP acts as authenticator, and a RADIUS policy server decides the outcome and the segment.
Devices that cannot run a supplicant, printers, cameras, medical and industrial equipment, are handled with MAC authentication bypass and profiling, which must be treated as identification rather than strong authentication.
Security considerations
- Deploy in monitor mode first, then enforce, to avoid locking out unprofiled devices.
- Keep a documented break glass path for critical ports.
