PortGuardNAC
  • Why PortGuard
  • Features
  • Use Cases
  • Pricing
  • Partners
  • Docs
  • Contact
🔐 Partner Login Book a Demo
Why PortGuard Features Use Cases Pricing Partners Docs Contact
Book a Demo →
// Docs

Changelog

PortGuard release notes · ← back to documentation

v1.1.12 — August 2026 latest

  • Package Operations Guard — system updates can no longer fail halfway. Every package operation runs in a pristine environment, a preflight check refuses an update that cannot complete (free space on /, /boot and /var, package-manager lock, dpkg state) with an explicit cause and remedy, and dpkg state is repaired and re-verified around each install
  • Kernel updates no longer fail with “Read-only file system” — an Ubuntu kernel update could abort mid-install and leave the package manager blocked until manual recovery over SSH
  • Repair Package State — recover a half-finished package manager from Updates → System Updates without SSH, or from the console with portguardnac-cli packages. An automatic check every 6 hours repairs it on its own when safe, and notifies when it cannot
  • Fixes that live in /etc (systemd drop-ins, sudo delegations) are now delivered by over-the-air updates instead of requiring an ISO reinstall; they become active at the next reboot

v1.1.11 — July 2026

  • HTTPS — the certificate uploaded in the dashboard is now really served by nginx. The apply checks that certificate and key match, reloads nginx and rolls back automatically if the new pair is rejected, so a wrong key can never leave the web UI unreachable
  • RADIUS — a newly added switch is active immediately, with no manual restart: the apply now performs a real service restart (FreeRADIUS does not reload its client list on reload), validated before and health-checked with auto-rollback after
  • RADIUS — the automatic rollback of a configuration apply now has a real snapshot to restore (snapshots were silently empty)
  • Updates — a leftover Python cache no longer aborts an installation, and an outdated cached package is no longer installed silently (SHA-256 re-checked against the live manifest before installing)

v1.1.10 — July 2026

  • Complete license lifecycle — expiry email alerts at 30/14/7/1 days, a two-stage grace period after expiry (read-only, then blocked) and support-window enforcement on version updates. Security updates always remain available
  • Two-factor authentication is now optional — enable or disable MFA per administrator, with a “Require MFA at login” policy toggle. The forced password-change screen no longer requires MFA enrollment (fixes a password-change loop)
  • In-place Factory Reset — return the appliance to a fresh state from Settings → Maintenance without reinstalling the ISO; optionally keep network settings and license
  • Reliability — RADIUS sessions now auto-close when a device goes silent (no more endpoints stuck online); fixed a rare post-update login lockout; cleaner Recent Auth Events on a fresh install

v1.1.9 — July 2026

  • Advanced Device Profiling — a multi-signal confidence engine (IEEE OUI vendor, auth/EAP method, hostname & user patterns, MAC randomization, VLAN) classifies and ranks device types. Real signals only — no fabricated fingerprints
  • Live Network State in SOC/NOC — real-time Live Endpoints (one row per MAC: device type, OS, IP, VLAN, auth method, status) shown beside a device-profiling summary
  • Accurate authentication-method reporting — EAP-TLS is now distinguished from PEAP and EAP-TTLS
  • Endpoint IP detection from RADIUS accounting (Framed-IP-Address), shown per endpoint where the switch supplies it
  • "Policies" renamed to "Access Policies"; RADIUS client terminology aligned to Switch / Devices
  • More accurate "Unknown Devices" metric on flat L2 networks — counts only unidentified endpoints that actually reached the RADIUS auth layer

v1.1.7 – v1.1.8 — July 2026

  • Device profiling with IEEE OUI — every device identified by vendor from the official IEEE registry (~53,000 prefixes, bundled offline)
  • Automatic device grouping — Computer, Phone/Tablet, Printer, CCTV, VoIP, IoT and Switch, with a manual override that always wins
  • Devices inventory page — vendor, group, VLAN and last identity per endpoint, with randomized / private MAC detection
  • Group-based VLAN enforcement — send every CCTV camera or printer to its own segment with a single policy, no per-MAC rules
  • Device-group and SSID policy conditions enforced live, with dedicated cctv / printer / voip roles and access profiles

v1.1.6 — July 2026

  • Emergency fix: update guard with automatic rollback — a failed update can no longer block appliance login
  • Clear login error reporting instead of opaque internal errors
  • Full pre-restart syntax check of the whole application during updates
  • Fixed post-update automatic service restart
  • Super admin account is protected and can never be deleted
  • High-quality PDF reports — multi-page exports with proper fonts, pagination and aligned tables (logs, vulnerability, compliance, update reports)
  • RADIUS config rollback — snapshots selectable by clear local date/time
  • Inactivity logout verified: disabling it keeps the session active as configured

v1.1.5 — July 2026

  • Client Certificates for 802.1X EAP-TLS — issue and manage user and machine certificates directly from the dashboard
  • SNMP extensions for PRTG / LibreNMS infrastructure monitoring
  • SOC/NOC telemetry accuracy improvements (connected devices, identities, top VLANs)
  • Consistent dd/mm/yyyy HH:MM:SS date format across the dashboard

v1.1.1 – v1.1.4 — June 2026

  • New secure update channel — SHA-256 verified packages, optional release signature, no token required
  • Component inventory refreshes automatically after system and application updates
  • portguardnac-cli — status and diagnostics tool from the appliance console
  • Idle session timeout now enforced as configured (0 = disabled)
  • Trial licenses unlock all features, including Entra ID integration
  • "Select all" for system updates and update-installer reliability fixes

v1.1.0 — June 2026

  • Native Microsoft Entra ID integration (SAML 2.0 / OIDC)
  • Group-Based VLAN mapping from Entra ID groups
  • Multi-profile Captive Portal with custom branding
  • Real-time dashboard via WebSocket
  • Prometheus metrics endpoint
  • Audit log with SHA-256 chain
  • MFA for admin dashboard access
  • Complete REST API

v1.0.0 — March 2025

  • First public release
  • 802.1X EAP-TLS / PEAP / TTLS
  • MAC Authentication Bypass
  • Dynamic VLAN
  • Integrated FreeRADIUS
PortGuardNAC
© 2026 Valerio Lollini / CrazyNet.
Why PortGuard Features Use Cases Pricing Partners Docs Status Support
Made with ♥ in Proudly built in Italy 🇮🇹
Privacy Policy· Cookie Policy· Terms of Service· EULA
CrazyNet · St Julian's, Malta · [email protected]
🍪 Cookies on this site

We only use essential technical cookies for authenticated areas — no tracking, no profiling, no third-party cookies. See our Cookie Policy.

PortGuardNAC AssistantAsk about features, setup, pricing
AI assistant — may be imperfect. For quotes or account issues, email [email protected].