Network Access Control Appliance

Enterprise-Grade
Network Access Control.
Without the Enterprise Project.

PortGuard NAC gives IT teams, MSPs and system integrators a simpler way to control network access, segment devices and detect unauthorized endpoints — without complex appliances or long deployment projects.

< 30 min
Deploy time
Zero
Cloud dependency
Entra ID
Native integration
MSP
Multi-tenant ready
🛡
Live Dashboard
Access Control Active
Every device authenticated · Every segment enforced
Devices blocked (unauthenticated)100%
Policy enforcement rate99.8%
Entra ID identity verified at connection
Dynamic VLAN assigned — no manual config
Every device profiled by vendor and type
All policies enforced
Live Active
Works with your existing switches and Wi-Fi
Microsoft Entra ID & LDAP native integration
Deploys in under 30 minutes
100% on-premises — no per-device fees
ISO 27001 compliance evidence built-in
// Sound familiar?

You know you need network access control.
You just don't want a six-month project to get it.

🔓

Unverified devices on your network

Staff, contractors and visitors connect from personal devices you've never seen. You have no way to know if they meet your security standards — or where they go once connected.

📶

Guest Wi-Fi too close to business data

A single misconfigured access point is all it takes for a guest device to reach systems it should never see. Shared infrastructure is a compliance risk most teams underestimate.

📱

BYOD with no enforcement and no visibility

Bring Your Own Device policies without technical enforcement are wishful thinking. Personal devices with no security baseline are on your network right now.

🏗️

Enterprise tools that weren't built for your team

Cisco ISE and ForeScout are powerful platforms built for organisations with dedicated network security teams. If your IT team is fewer than ten people, those tools aren't the right fit.

// The fix

PortGuard closes the gap between needing NAC and having it.

PortGuard is a network access control appliance designed for companies that need real security outcomes without the complexity of enterprise platforms. It authenticates every device before it reaches the network, assigns it to the right segment automatically and gives your IT team a clear, real-time picture of everything connected.

It integrates with Microsoft Entra ID, Active Directory and LDAP. It works with the switches and Wi-Fi infrastructure you already have. And it can be running in your environment today.

No cloud dependency — your data stays on your network
No rip-and-replace — works with your existing infrastructure
No dedicated NAC engineer required to operate it
Deploys from ISO on any 40 GB server, VM or bare-metal
Full compliance evidence generated automatically
// What's included

Every capability — and what it means for your business

All data stays on your premises. No cloud. No per-device fees. Deploy in under 30 minutes.

🔒

Control Who Connects

Blocks every unauthenticated device at the switch port or Wi-Fi access point. Staff, guests and contractors all have to prove who they are before they get network access.

Access Control
🏷️

Automatic Network Segmentation

Users and devices land on the right VLAN automatically — staff, BYOD, guests and contractors, each on their own segment. No manual switch configuration needed.

Dynamic VLAN
🪪

Connect Microsoft Entra ID

Native integration with Microsoft Entra ID, Active Directory and LDAP. Your existing user directory drives network access — no duplicate identity management.

Entra ID / LDAP
🌐

Secure Guest & BYOD Access

Branded captive portal with time-limited vouchers for visitors. Guest and personal devices land on isolated VLANs — never your internal systems.

Guest Portal · Voucher
🖥️

See Every Device on the Network

Automatic inventory identifies every endpoint by vendor (IEEE OUI, offline) and classifies it — computer, phone, printer, CCTV, VoIP, IoT — with unmanaged / randomized MACs flagged on sight.

Device Profiling
📊

Full Real-Time Visibility

See every connected device, its identity, its network location and its policy status in real time. Compliance evidence generated automatically. No blind spots.

Live Dashboard
🔐

Certificate-Based Device Trust

High-assurance device authentication with no passwords to steal or rotate. Managed devices get certificate-based identity — the strongest form of network access control.

EAP-TLS · PKI
📡

Works With Your Infrastructure

Native SNMP support for your existing managed switches and Wi-Fi hardware. No new infrastructure required — PortGuard sits alongside what you already have.

SNMP · PRTG
🏢

MSP Multi-Tenant Platform

Manage multiple client networks from one platform. Each client environment is fully isolated. Centrally operated, per-client billing, purpose-built for MSPs.

Multi-Tenant
// Who uses PortGuard

Built for teams like yours

SMB IT Manager

Control BYOD and guest access without a security team

You need to pass a security audit, control what personal devices can reach, and stop guests from seeing internal systems. PortGuard gives you the tools to do it — no consultancy engagement required.

See what's included →
MSP / Reseller

One platform for every client — fully isolated

Managing 20, 50 or 200 client networks means you need a platform that isolates each customer while giving you one operational view. PortGuard's multi-tenant architecture was built for that.

Become a partner →
Security Consultant

Deploy a defensible NAC posture for your clients, fast

Your clients need network access control as part of a Zero Trust or compliance programme. PortGuard deploys quickly, integrates with their existing identity stack, and produces the evidence their auditor needs.

Why PortGuard? →
// Honest comparison

Not another enterprise NAC project

Cisco ISE and PacketFence are powerful tools — designed for organisations with dedicated security teams. If you need access control working by the end of the month, PortGuard is the right tool.

PortGuardNAC Cisco ISE PacketFence
Deployment timeline < 1 day 3–12 months Weeks to months
Expertise required Network admin Cisco engineers Linux admin
MSP multi-tenancy Built-in Complex add-on Manual
Entra ID / AD Native Via SAML/LDAP Manual scripting
Ready-to-run appliance
On-premises, no cloud
GPG-signed updates
Compliance evidence Enterprise add-on Partial
Support model Dedicated Enterprise SLA Community
// Getting started

From unboxing to enforcing policy in a single day

Your existing network infrastructure stays in place. No forklift upgrade, no months of configuration, no professional services contract.

Step 01

Deploy the appliance

Install PortGuard from ISO onto any 40 GB server, VM or bare-metal hardware. Physical or virtual — your choice.

Step 02

Connect your identity provider

Link Microsoft Entra ID, Active Directory or LDAP through the first-boot wizard. Typically 30 minutes.

Step 03

Define your access policies

Set who gets access to what, which devices qualify, and how guests connect — through a web interface built for network administrators.

Step 04

Go live

PortGuard begins enforcing policy immediately. Full visibility from day one. Compliance evidence generated automatically.

// Pricing

Simple, transparent licensing

All plans include a 30-day trial with every feature unlocked. No credit card.

🎁
30-day trial — all features included
Full Enterprise access for 30 days, then choose your plan.
Standard
€490/yr
Billed annually · trial included
Up to 25 endpoints
  • 802.1X PEAP-MSCHAPv2
  • Local user database
  • Dynamic VLAN basic
  • Device profiling & inventory
  • Web dashboard
  • SNMP monitoring
  • Email alerts
  • Entra ID / LDAP
  • Captive Portal
Start 30-Day Trial →
Enterprise
€5.990/yr
Billed annually · trial included
Unlimited endpoints
  • Everything in Professional
  • Unlimited endpoints
  • MSP multi-tenant
  • HA / cluster deployment
  • Air-gapped / offline
  • Custom MIB & integrations
  • Dedicated onboarding
  • Support & SLA — on request
Contact Sales →
// Get Started

Ready to take control of your network access?

Book a 30-minute demo — we'll show you a live deployment on infrastructure similar to yours and give you a clear picture of fit. No enterprise sales cycle.

Book a Free Demo → Start 30-Day Trial

No credit card required · Full-feature trial · No enterprise sales cycle