← Back to Home
// Full Feature List

Everything you need to
control network access

A complete NAC appliance for SMBs and MSPs — authenticates every device, enforces policy automatically, deploys in under 30 minutes.

// What each capability means for your business

Technical capability → business outcome

Capability What it means for you
802.1X port & wireless authentication Devices must prove who they are before they connect — not after an incident
Dynamic VLAN assignment Staff, guests and contractors land on the right segment automatically — no manual switch work
Microsoft Entra ID / LDAP sync Your existing user directory drives network access — no duplicate identity management
Captive portal for guest access Guests reach an isolated network through a branded page — never your internal systems
BYOD device policy enforcement Personal devices that don't meet your baseline are blocked or redirected automatically
EAP-TLS certificate authentication High-assurance device trust with no passwords to steal, rotate or share
CVE / CVSS vulnerability awareness Know which connected devices have known security weaknesses before attackers find them
MSP multi-tenant dashboard Manage all client environments from one platform — fully isolated per client
GPG-signed updates Every update verified before installation — supply-chain secure by design
Compliance evidence export Structured audit trail for ISO 27001 A.9, Cyber Essentials and SOC 2 — always ready
🔐
// EAP Layer

802.1X Authentication — Full EAP stack with FreeRADIUS

PEAP-MSCHAPv2

The most widely deployed EAP method. Users authenticate with their AD/Entra ID username and password. No certificates required on the client side.

EAP-TLS

Mutual certificate authentication — the strongest EAP method. Both client and server present certificates. Ideal for managed corporate devices.

TTLS-PAP

Tunneled TLS with PAP inner auth. Useful for Linux clients and legacy devices that don't support PEAP natively.

EAP Chaining

Multiple EAP methods can be chained. PortGuard tries each in order based on client capability, falling back gracefully.

🪪
// Identity

Entra ID & LDAP Federation — Connect your existing directory

SAML 2.0 SSO

Admin portal login via Microsoft Entra ID SAML. No separate PortGuard admin accounts needed — your IT team uses their corporate credentials.

OIDC Captive Portal

Guest and BYOD users authenticate via Microsoft on the captive portal. Full OIDC code flow with MFA enforcement from Conditional Access policies.

Real-time Group Sync

AD groups sync to PortGuard continuously. When a user is added to "Finance" in Entra ID, their VLAN assignment updates automatically on next auth.

LDAP Fallback

If Entra ID is unreachable, PortGuard can fall back to a local LDAP server or its internal user database — ensuring no single point of failure.

🔀
// Network Segmentation

Dynamic VLAN Assignment — Right network, every time

Identity-based VLAN

Map AD groups or LDAP OUs directly to VLANs. A user in "Finance" always lands on VLAN 20, regardless of which switch port they connect to.

Device-based VLAN

Assign VLANs based on device type (laptop, printer, IP phone, IoT). MAC OUI prefix matching with manual override capability.

Time-based Policies

Restrict VLAN access by time of day. After-hours connections can be automatically placed in a limited-access VLAN or rejected entirely.

Change of Authorization (CoA)

When a user's group changes mid-session, PortGuard sends a CoA to the switch — no disconnect required, VLAN changes live.

🌐
// Guest & BYOD Access

Captive Portal — Flexible portal profiles

Multi-profile Support

Separate portal profiles for Corporate, BYOD, and Guest — each with its own auth method, VLAN, bandwidth cap, and session duration.

Voucher System

Reception staff generate time-limited, single-use vouchers for visitors. Batch generation, CSV export, and email delivery supported.

Entra ID SSO Login

BYOD users hit the portal and click "Sign in with Microsoft". After OIDC auth, the correct VLAN is assigned automatically — no IT involvement needed.

Bandwidth Control

Per-profile bandwidth limits (up/down in kbps). Guests get limited bandwidth, employees get full speed — enforced via RADIUS attributes.

🔍
// Threat Detection

Security & Compliance — Proactive security posture

CVE / CVSS Scanning

Devices are continuously checked against the NVD CVE database. Configurable thresholds — a device with a CVSS 9.x vulnerability can be auto-quarantined.

Rogue MAC Detection

Every unknown MAC attempting authentication triggers an immediate security event. Auto-block with configurable whitelist and SNMP trap dispatch.

Auth Failure Tracking

Brute-force detection at the RADIUS level. Configurable failure thresholds per NAS and per user, with automatic lockout and alert.

Certificate Expiry Monitor

All certificates (server TLS, EAP CA, client certs) are monitored for expiry. Alerts fire at 60, 30, and 7 days before expiration.

📡
// Observability

Monitoring & Integration — Full visibility, standard tools

Real-time WebSocket Dashboard

All dashboard widgets update via WebSocket push — no polling. Auth events appear within 2 seconds of occurrence.

SNMP + PRTG Template

Native SNMPv2c/v3 with a ready-to-use PRTG device template exposing 28 custom OIDs — RADIUS sessions, rejects, VLAN usage, EAP failures.

Prometheus Metrics

10 operational metrics exported on localhost:9753/metrics. Compatible with Grafana, Alertmanager, and any Prometheus-compatible system.

Syslog (RFC 5424)

All security events and auth decisions can be forwarded to a remote syslog server — compatible with Splunk, Graylog, and any SIEM.

Ready to try all features?

30-day trial with full Enterprise access. No credit card required.

Start 30-Day Trial → View Architecture