PortGuardNAC
  • Why PortGuard
  • Features
  • Use Cases
  • Pricing
  • Partners
  • Docs
  • Contact
🔐 Partner Login Book a Demo
Why PortGuard Features Use Cases Pricing Partners Docs Contact
Book a Demo →
// Admin Guide

4. Network Access Control

PortGuard v1.1.10 · ← Administrator’s Guide · Documentation

VLANs

The registry of VLANs the appliance can assign dynamically. Define each VLAN with ID (1–4094), name and description; they then appear in the dropdowns of users, groups, policies and captive-portal profiles. Assignment uses standard RADIUS attributes (Tunnel-Private-Group-Id), compatible with any switch/AP that supports dynamic VLAN assignment (RFC 3580).

Clients / NAS

The switches and access points authorized to talk to the RADIUS service.

Adding a NAS

  1. NAS / Access Clients → name, IP address, shared secret, vendor, description.
  2. Save — the RADIUS configuration is regenerated and reloaded automatically.
  3. Configure the same secret on the switch/AP, pointing at the appliance (ports 1812 auth / 1813 accounting).

RADIUS 802.1X Service

On the same page: default authentication method (PEAP-MSCHAPv2 / EAP-TLS / TTLS-PAP), server certificate for EAP, default VLAN, accounting on/off, and CoA (Change of Authorization) on/off.

RADIUS Config Rollback

Every RADIUS configuration change creates a snapshot; if a change breaks something you can roll back to any previous snapshot from here.

Devices — endpoint inventory & profiling

An automatic inventory of every MAC address seen on the network, with vendor recognition and group classification.

What happens automatically

  • Each device is recorded at its first RADIUS authentication (or captive-portal access): vendor resolved from the built-in IEEE OUI database (~53,000 MA-L/MA-M/MA-S prefixes, fully offline, refreshed monthly), first/last seen, last identity, VLAN, NAS and IP.
  • Group classification — computer, phone/tablet, printer, CCTV, VoIP, IoT, network, unknown — from vendor rules plus heuristics (EAP vs MAB, machine identity).
  • Randomized MACs (iOS/Android/Windows privacy) are detected from the U/L bit and labeled “Randomized / Private MAC”.
  • Domain-qualified identity — when the identity is host/PCNAME and the PC is synced from Entra ID, the Last identity column shows yourdomain.com/PCNAME; the raw RADIUS identity stays in the tooltip.

Using the page

  • Summary tiles: known devices, online (seen in the last 2 hours), randomized MACs, OUI database status.
  • Group filter chips and free search (MAC, vendor, user, notes).
  • Manual group override: pick a group from the row’s selector — a manual choice always wins and is never overwritten by the automation; choosing “Auto” returns to automatic classification.
  • Delete removes the device (it reappears at its next authentication).

The device group is available as a policy condition — e.g. every CCTV camera goes to VLAN 40 regardless of which port it is plugged into.

Policies — the network policy engine

The heart of the NAC: rules evaluated in real time at every authentication that decide access and VLAN.

Creating a policy

  1. Open the Create Policy Wizard: name, description, priority (policies are evaluated in order; the first match wins).
  2. Conditions (all must be true): user, group (local or Entra), authentication source, domain/realm (e.g. company.com — lets a single appliance route several tenants), NAS client, SSID (wireless), device group (from profiling), device MAC, certificate status, compliance status.
  3. Actions: allow/deny, assigned VLAN, role (computer / phone / printer / cctv / voip / … — a metadata tag for audit and future ACL mapping).
  4. Save and enable.

Test / Preview

A simulation panel: compose the parameters of a hypothetical authentication (user, group, NAS, SSID, MAC…) and see which policy would match and which VLAN would be assigned — without touching the network.

Policy Audit

The history of real matches: which policy decided what, and when.

Authentication policies

Rules about how subjects authenticate: allowed methods and requirements per user/device category. Same wizard interface (conditions + actions) with its own audit trail.

Dynamic VLAN — session policies

Session rules per user group: idle timeout, maximum session duration, maximum concurrent sessions, RADIUS re-authentication interval, CoA/Disconnect support. Same wizard interface as the other policy types.

← 3. Identity
5. Certificates & EAP-TLS →
PortGuardNAC
© 2026 Valerio Lollini / CrazyNet.
Why PortGuard Features Use Cases Pricing Partners Docs Status Support
Made with ♥ in Proudly built in Italy 🇮🇹
Privacy Policy· Cookie Policy· Terms of Service· EULA
CrazyNet · St Julian's, Malta · [email protected]
🍪 Cookies on this site

We only use essential technical cookies for authenticated areas — no tracking, no profiling, no third-party cookies. See our Cookie Policy.

PortGuardNAC AssistantAsk about features, setup, pricing
AI assistant — may be imperfect. For quotes or account issues, email [email protected].