SonarNext is the IT infrastructure business of Sonar Technologies International.

Wireless & wired security · Australia-wide

Network access control & 802.1X

Replace the shared Wi-Fi password with a network that knows every device on it. We design and roll out 802.1X, certificate onboarding and role-based segmentation on Aruba, Cisco, Fortinet or Meraki — staged so operations never stop on cut-over day.

Engineer checking a comms rack with a tablet beside a working warehouse floor

Why NAC

The Wi-Fi password is on a sticky note in the lunchroom

Most business networks still decide who gets on by asking one question: do you know the password? The same pre-shared key is typed into every handheld, printed on the dock office door and known by every contractor and former employee, and changing it means touching every device, so nobody does. Once a device is on, it is usually on everything: cameras, label printers, badge readers, forklift terminals, finance laptops and the guest charging a phone share one flat network, so a compromised camera can talk directly to the payroll server. Network access control fixes both halves. Every device proves who or what it is before it gets an address, what it proves decides where it lands and what it can reach, and when an auditor, insurer or customer asks who is on your network the answer comes from a log rather than a guess.

  • One shared Wi-Fi key that has never been changed
  • Ex-staff laptops and phones that still connect
  • Cameras, printers and scanners on the same network as finance
  • Any open wall port gives a stranger full access
  • Guests and contractors on the corporate SSID
  • No record of which device was where, and when
  • Audit, insurance or customer questionnaires you cannot answer

How devices prove who they are

802.1X, certificates and the devices that cannot do either

802.1X is the standard behind almost every NAC deployment. A device asks to join, the access point or switch port holds it at the door, and a RADIUS server checks its credentials against your directory before anything else is allowed through. The same policy covers wireless, wired switch ports and VPN users, so a cable in a meeting room is no shortcut past the wireless controls. What differs is how the device proves itself.

With EAP-TLS each device carries its own certificate, issued by your organisation and presented automatically: there is no password to phish, share or forget, and revoking one device does not affect any other. PEAP has the user sign in with directory credentials inside an encrypted tunnel; it is easier to start with, but it depends on passwords and on the device's check of the server certificate, so we treat it as a stepping stone, not a destination. Certificates used to be hard because of getting them onto devices; Microsoft Intune and SOTI MobiControl now push them at enrolment alongside the Wi-Fi profile, so a new laptop or Zebra handheld joins the secure network without anyone typing anything, and retiring it in MDM revokes its certificate. We design for EAP-TLS wherever the device supports it, which today is nearly every managed laptop, phone and enterprise handheld.

Printers, cameras, sensors and some older scanners cannot do 802.1X at all. Multiple or identity pre-shared keys (MPSK and iPSK) give each device, or each group of devices, its own key on the same SSID: leak one and you change one, and the key itself decides which segment the device lands in.

MAC authentication is the last resort. A hardware address is easy to copy, so on its own it proves very little. Where nothing better is available, on wireless or on switch ports without a supplicant, we pair it with profiling, which checks that a device claiming to be a printer behaves like one, and fence it into a segment that reaches only what it needs.

Platforms

We design to the network you have, not the one we would sell you

NAC sits between your identity system and your network hardware, so the right platform is usually the one that fits both. We work with the major enterprise policy engines and the identity sources behind them, and we will tell you when the capability you need is already sitting in a licence you own.

HPE Aruba Networking ClearPass & Central

ClearPass Policy Manager is a full on-premises policy engine with role-based policy, device profiling, guest and onboarding portals, and virtual appliance deployment. Aruba Central's cloud NAC (formerly Cloud Auth) suits sites that want 802.1X and MPSK without running a server. Both drive Dynamic Segmentation across Aruba wired, wireless and SD-WAN. HPE Aruba Networking is a SonarNext partner.

Cisco Identity Services Engine & Meraki

ISE gives deep context on every connection — who, what device, when, where and how — across wired, wireless and VPN, with TACACS+ device administration, posture, profiling, guest and BYOD services. Meraki builds RADIUS, group policy and adaptive policy into the dashboard for sites that do not need a separate policy server. Cisco is a SonarNext partner.

Fortinet FortiNAC & FortiGate

FortiNAC adds visibility, profiling and automated response across multi-vendor switching and wireless. On a Fortinet Security Fabric, FortiGate can apply NAC policy directly to FortiSwitch and FortiAP ports and quarantine a device the moment the firewall flags it. Fortinet is a SonarNext partner.

Each of these checks against an identity source: Microsoft Entra ID and Active Directory, Okta and other SAML single sign-on providers, LDAP and SQL stores, with device compliance from Intune or SOTI so an unmanaged or out-of-date device is treated differently from a healthy one. Underneath them all is RADIUS, and getting it right, with redundant policy servers and sensible timeouts, is most of what makes NAC reliable, cloud-hosted or on-premises, single-brand or multi-vendor. The same engines provide TACACS+ device administration, giving each engineer their own login to switches, firewalls and controllers, restricting which commands they can run and recording every change, which retires the shared admin password everyone in IT knows. Where SASE or firewall policy is in use, NAC roles feed into it.

Segmentation & zero trust

Being on the network should not mean reaching all of it

Authentication answers who you are; segmentation answers what you can reach, and it is where NAC pays for itself. Instead of one VLAN per SSID or switch port, the policy server assigns each connection a role from the user, the device type, its compliance state and where it connected, and the network enforces it on wireless and wired alike. Zero trust is simply that in practice: no device is trusted because it is inside the building, and each gets the least access it needs, so a label printer reaches the print server and a camera reaches the video recorder, and if either is compromised that is where the damage stops.

  • Role-based VLANs and dynamic segmentation
  • Staff, contractor and guest separated by policy
  • IoT and OT zones for cameras, printers, PLCs and sensors
  • Scanners and vehicle terminals reach only the WMS they need
  • Posture and MDM compliance checked before full access, with a remediation network for laptops that fail
  • Quarantine for non-compliant or unknown devices
  • Firewall rules between zones, not just VLAN tags

Guest & BYOD

Visitors online in a minute, and never near your systems

Guests and personal devices are the reason the shared password never changes. Give them their own properly controlled path, branded to your organisation with terms of use accepted on the portal, and the corporate network can finally be locked down. Guest traffic goes straight to the internet, isolated from every internal segment and from other guests, so a visitor's infected laptop cannot see the device next to it.

  • Sponsored guest access: a named staff member approves by email or text, access expires with the visit, and there is a record of who vouched for whom
  • Self-registration with time-limited credentials and bandwidth limits where visitor traffic is steady
  • Pre-issued contractor and event accounts, valid for the dates of the work and limited to the internet or the systems they need
  • BYOD onboarding that installs a certificate and Wi-Fi profile, lands the device in a BYOD role with email and approved apps, and removes access when staff leave
  • Staff portals signed in through Entra ID, Okta or another SAML provider, so everyday multi-factor sign-in applies here too

How we roll it out

The warehouse keeps scanning on cut-over day

NAC projects fail in one of two ways: switched on in enforcement mode on day one, locking out a forgotten device that turns out to run the conveyor, or left in monitor mode forever because nobody had the confidence to enforce. We stage it so neither happens.

  1. Discovery and profiling

    The policy server runs in monitor mode, authenticating and logging every connection but blocking nothing, while profiling builds an inventory of what is really on your network, including the devices nobody remembered.

  2. Policy design

    From that inventory we agree the roles, segments and access rules with your team, including how headless devices are handled, while certificates and Wi-Fi profiles are pushed through Intune or SOTI ahead of time.

  3. Staged enforcement

    Enforcement is switched on one group at a time, starting with the least critical and ending with the operational fleet, with each stage checked against the logs and shift supervisors told what is changing and when.

  4. Break-glass and fallback

    Before enforcement goes near the floor we agree and test what the network does if the policy servers are unreachable, a documented way to restore access to critical devices quickly, and named people who can use it.

  5. Handover

    You receive the policy design, device inventory, certificate details and runbooks for adding devices, onboarding sites and handling lockouts, written for the people who will be doing it at 6am.

Running it

Certificates expire. Plan for it or it will plan your outage.

The most common cause of a NAC outage is not an attack or a hardware failure but a certificate reaching its expiry date. When the policy server's own certificate lapses, every device checking it refuses to connect at the same moment; when a root or issuing certificate lapses, devices stop getting new ones; either way the site finds out when the handhelds stop. We track every certificate in the chain, from the RADIUS server to the issuing authority and the device certificates MDM is renewing, and act well before expiry. The same monitoring watches authentication failure trends, policy server health and RADIUS response times, so a problem shows up as an alert rather than a queue at the service desk.

Day to day, new device types are profiled and assigned a role, joiner and leaver access is kept in step with the directory, firmware and platform updates are planned rather than a surprise, and access logs are retained for audit and incident review. For organisations that want it handled end to end, NAC runs as part of managed IT services, with a dedicated IT manager, real-time monitoring and response commitments agreed in writing up front.

FAQs

Questions we get asked

What is network access control?

Network access control (NAC) checks every device before it joins your wired or wireless network, then decides where it lands and what it can reach. Instead of one shared password that lets anyone onto everything, each user and device proves its identity, and a policy server assigns it a role. You also get a log of who and what connected, when and where.

What is the difference between EAP-TLS and PEAP?

Both are ways of authenticating with 802.1X. PEAP uses a username and password inside an encrypted tunnel; EAP-TLS uses a certificate installed on the device, with no password at all. EAP-TLS is more secure and, once certificates are delivered by MDM, easier for users because nothing has to be typed. We use PEAP only as a transition step where devices are not yet managed.

How do scanners, printers and cameras that cannot do 802.1X get on?

Most enterprise Android handhelds support 802.1X and certificates through MDM. For headless devices that genuinely cannot, we use multiple or identity pre-shared keys, so each device or group has its own key and lands in its own segment. MAC authentication combined with profiling is kept as a last resort, and those devices are restricted to only the systems they need.

Will turning on NAC disrupt our operations?

It should not, if it is rolled out properly. We start in monitor mode, where nothing is blocked, to build an inventory of every device on the network. Enforcement is then switched on in stages, least critical first, with a tested fallback for the operational fleet if the policy servers are ever unreachable.

Which NAC platform should we use?

Usually the one that fits the network and identity systems you already have. HPE Aruba ClearPass or Aruba Central, Cisco ISE or Meraki, and Fortinet FortiNAC or FortiGate all do the job well on their own hardware, and some of the capability may already be in licences you own. We recommend based on your switching, wireless, directory and MDM, not on what we would prefer to sell.

Does NAC work with Microsoft Entra ID and Intune?

Yes. Entra ID and Active Directory are the most common identity sources we integrate with, alongside Okta and other SAML providers. Intune, like SOTI MobiControl, can deliver device certificates and Wi-Fi profiles during enrolment and report compliance to the policy server, so an unhealthy device gets restricted access automatically.

What happens when certificates expire?

If the policy server or issuing certificate expires, devices stop authenticating, often all at once. It is the most common cause of NAC outages we see. We track every certificate in the chain and renew well ahead of expiry, and ongoing monitoring can be included as part of a managed services agreement.

Related

Where this fits in the wider job

Ready to talk through your project?

Tell us what you are planning — a new site, a network that keeps dropping out, or IT that needs a safer pair of hands. We will come back with straight answers and a clear quote.