← Back to Home
// Use Cases

Where organizations
deploy PortGuard

Any environment with managed switches or wireless infrastructure benefits from zero-trust NAC.

🏢
Corporate Office

Employee Network Segmentation

Every device authenticates via 802.1X with Entra ID credentials before reaching the LAN. Finance, HR, and IT land on separate VLANs automatically — no manual switch port configuration required.

802.1XEntra IDDynamic VLANRBAC
Challenge

Challenge: Flat networks where any connected device can reach any server. PortGuard enforces identity-based microsegmentation without replacing existing switching infrastructure.

How PortGuard Solves It
  • Zero trust from day one — no device on the network without authentication
  • AD group → VLAN mapping managed centrally, not per-switch
  • Full audit log of every connection: who, what device, which port, which VLAN
🏨
Hospitality & Events

Guest Wi-Fi with Voucher Portal

Reception generates time-limited vouchers in seconds. Guests connect, enter the code on the captive portal, and land on an isolated VLAN with bandwidth controls — completely separated from the corporate network.

Captive PortalVoucherGuest VLANBandwidth
Challenge

Challenge: Providing guest internet access without exposing the corporate network, without an IT technician on site for every event.

How PortGuard Solves It
  • Reception staff generate vouchers independently — no IT ticket
  • Bandwidth limits per guest profile (e.g. 10 Mbps down)
  • Automatic session expiry — no cleanup needed after events
🏭
Manufacturing & OT

IT/OT Segmentation & MAC Control

Register approved MAC addresses for PLCs, cameras, and IoT devices. Any unknown device hitting the network triggers an immediate rogue MAC alert and auto-block. CVE scanning flags unpatched firmware.

MAC AuthRogue DetectionCVE ScanOT VLAN
Challenge

Challenge: IoT and OT devices cannot run 802.1X supplicants. They need MAC-based auth with strict monitoring.

How PortGuard Solves It
  • MAC whitelist enforced at RADIUS level — not just port security
  • CVE monitoring flags devices with known firmware vulnerabilities
  • Rogue MAC alert fires within seconds of unauthorized connection attempt
⚖️
Legal & Professional Services

Confidential Data Protection

Law firms and financial advisors handle sensitive client data. PortGuard ensures only authenticated, compliant devices reach document management and CRM systems — with full audit trail for regulatory requirements.

802.1XComplianceAudit LogGDPR
Challenge

Challenge: Regulatory requirements (GDPR, ISO 27001) demand proof of who accessed which network segment and when.

How PortGuard Solves It
  • SHA-256 audit chain — tamper-evident log of every auth decision
  • ISO 27001 evidence-ready reporting out of the box
  • Entra ID integration means leavers are immediately denied access
🔧
MSP / Multi-Tenant

Managed NAC for Multiple Clients

Managed Service Providers run PortGuard Enterprise as a shared platform. Each client gets an isolated tenant with its own policies, VLANs, and portal. Single pane of glass for monitoring all sites.

Multi-TenantMSP PortalResellerCredits
Challenge

Challenge: MSPs need to offer NAC as a service to multiple clients without deploying separate infrastructure for each.

How PortGuard Solves It
  • One PortGuard Enterprise instance — unlimited client tenants
  • Partner Portal for autonomous license generation per client
  • Up to 35% reseller margin on Standard, Professional and Enterprise licenses
🎓
Education & Campus

Student & Staff Segmentation

Universities and schools enforce role-based network access: students on one VLAN, staff on another, IoT devices (projectors, printers) on a third — all driven by directory group membership.

802.1XLDAPMulti-VLANBYOD
Challenge

Challenge: Thousands of personal devices (BYOD) mixed with managed devices, all needing appropriate network access.

How PortGuard Solves It
  • BYOD portal with Entra ID or LDAP login — no IT involvement for students
  • Per-device type VLAN (managed laptop vs personal phone vs projector)
  • Bandwidth limits for student VLAN during exam periods

Your use case not listed? Let's talk.

PortGuard works on any RFC 3580-compliant infrastructure. If you have managed switches or a wireless controller, it works.

📧 Contact Sales → View Pricing