PortGuard NAC gives IT teams, MSPs and system integrators a simpler way to control network access, segment devices and detect unauthorized endpoints — without complex appliances or long deployment projects.
Staff, contractors and visitors connect from personal devices you've never seen. You have no way to know if they meet your security standards — or where they go once connected.
A single misconfigured access point is all it takes for a guest device to reach systems it should never see. Shared infrastructure is a compliance risk most teams underestimate.
Bring Your Own Device policies without technical enforcement are wishful thinking. Personal devices with no security baseline are on your network right now.
Cisco ISE and ForeScout are powerful platforms built for organisations with dedicated network security teams. If your IT team is fewer than ten people, those tools aren't the right fit.
PortGuard is a network access control appliance designed for companies that need real security outcomes without the complexity of enterprise platforms. It authenticates every device before it reaches the network, assigns it to the right segment automatically and gives your IT team a clear, real-time picture of everything connected.
It integrates with Microsoft Entra ID, Active Directory and LDAP. It works with the switches and Wi-Fi infrastructure you already have. And it can be running in your environment today.
All data stays on your premises. No cloud. No per-device fees. Deploy in under 30 minutes.
Blocks every unauthenticated device at the switch port or Wi-Fi access point. Staff, guests and contractors all have to prove who they are before they get network access.
Access ControlUsers and devices land on the right VLAN automatically — staff, BYOD, guests and contractors, each on their own segment. No manual switch configuration needed.
Dynamic VLANNative integration with Microsoft Entra ID, Active Directory and LDAP. Your existing user directory drives network access — no duplicate identity management.
Entra ID / LDAPBranded captive portal with time-limited vouchers for visitors. Guest and personal devices land on isolated VLANs — never your internal systems.
Guest Portal · VoucherAutomatic inventory identifies every endpoint by vendor (IEEE OUI, offline) and classifies it — computer, phone, printer, CCTV, VoIP, IoT — with unmanaged / randomized MACs flagged on sight.
Device ProfilingSee every connected device, its identity, its network location and its policy status in real time. Compliance evidence generated automatically. No blind spots.
Live DashboardHigh-assurance device authentication with no passwords to steal or rotate. Managed devices get certificate-based identity — the strongest form of network access control.
EAP-TLS · PKINative SNMP support for your existing managed switches and Wi-Fi hardware. No new infrastructure required — PortGuard sits alongside what you already have.
SNMP · PRTGManage multiple client networks from one platform. Each client environment is fully isolated. Centrally operated, per-client billing, purpose-built for MSPs.
Multi-TenantYou need to pass a security audit, control what personal devices can reach, and stop guests from seeing internal systems. PortGuard gives you the tools to do it — no consultancy engagement required.
See what's included →Managing 20, 50 or 200 client networks means you need a platform that isolates each customer while giving you one operational view. PortGuard's multi-tenant architecture was built for that.
Become a partner →Your clients need network access control as part of a Zero Trust or compliance programme. PortGuard deploys quickly, integrates with their existing identity stack, and produces the evidence their auditor needs.
Why PortGuard? →Cisco ISE and PacketFence are powerful tools — designed for organisations with dedicated security teams. If you need access control working by the end of the month, PortGuard is the right tool.
| PortGuardNAC | Cisco ISE | PacketFence | |
|---|---|---|---|
| Deployment timeline | < 1 day | 3–12 months | Weeks to months |
| Expertise required | Network admin | Cisco engineers | Linux admin |
| MSP multi-tenancy | Built-in | Complex add-on | Manual |
| Entra ID / AD | Native | Via SAML/LDAP | Manual scripting |
| Ready-to-run appliance | ✓ | ✗ | ✗ |
| On-premises, no cloud | ✓ | ✓ | ✓ |
| GPG-signed updates | ✓ | ✗ | ✗ |
| Compliance evidence | ✓ | Enterprise add-on | Partial |
| Support model | Dedicated | Enterprise SLA | Community |
Your existing network infrastructure stays in place. No forklift upgrade, no months of configuration, no professional services contract.
Install PortGuard from ISO onto any 40 GB server, VM or bare-metal hardware. Physical or virtual — your choice.
Link Microsoft Entra ID, Active Directory or LDAP through the first-boot wizard. Typically 30 minutes.
Set who gets access to what, which devices qualify, and how guests connect — through a web interface built for network administrators.
PortGuard begins enforcing policy immediately. Full visibility from day one. Compliance evidence generated automatically.
All plans include a 30-day trial with every feature unlocked. No credit card.