Wireless network design
Survey-led wireless design, so the network NAC protects actually covers the floor.
Wireless & wired security · Australia-wide
Replace the shared Wi-Fi password with a network that knows every device on it. We design and roll out 802.1X, certificate onboarding and role-based segmentation on Aruba, Cisco, Fortinet or Meraki — staged so operations never stop on cut-over day.
Why NAC
Most business networks still decide who gets on by asking one question: do you know the password? The same pre-shared key is typed into every handheld, printed on the dock office door and known by every contractor and former employee, and changing it means touching every device, so nobody does. Once a device is on, it is usually on everything: cameras, label printers, badge readers, forklift terminals, finance laptops and the guest charging a phone share one flat network, so a compromised camera can talk directly to the payroll server. Network access control fixes both halves. Every device proves who or what it is before it gets an address, what it proves decides where it lands and what it can reach, and when an auditor, insurer or customer asks who is on your network the answer comes from a log rather than a guess.
How devices prove who they are
802.1X is the standard behind almost every NAC deployment. A device asks to join, the access point or switch port holds it at the door, and a RADIUS server checks its credentials against your directory before anything else is allowed through. The same policy covers wireless, wired switch ports and VPN users, so a cable in a meeting room is no shortcut past the wireless controls. What differs is how the device proves itself.
With EAP-TLS each device carries its own certificate, issued by your organisation and presented automatically: there is no password to phish, share or forget, and revoking one device does not affect any other. PEAP has the user sign in with directory credentials inside an encrypted tunnel; it is easier to start with, but it depends on passwords and on the device's check of the server certificate, so we treat it as a stepping stone, not a destination. Certificates used to be hard because of getting them onto devices; Microsoft Intune and SOTI MobiControl now push them at enrolment alongside the Wi-Fi profile, so a new laptop or Zebra handheld joins the secure network without anyone typing anything, and retiring it in MDM revokes its certificate. We design for EAP-TLS wherever the device supports it, which today is nearly every managed laptop, phone and enterprise handheld.
Printers, cameras, sensors and some older scanners cannot do 802.1X at all. Multiple or identity pre-shared keys (MPSK and iPSK) give each device, or each group of devices, its own key on the same SSID: leak one and you change one, and the key itself decides which segment the device lands in.
MAC authentication is the last resort. A hardware address is easy to copy, so on its own it proves very little. Where nothing better is available, on wireless or on switch ports without a supplicant, we pair it with profiling, which checks that a device claiming to be a printer behaves like one, and fence it into a segment that reaches only what it needs.
Platforms
NAC sits between your identity system and your network hardware, so the right platform is usually the one that fits both. We work with the major enterprise policy engines and the identity sources behind them, and we will tell you when the capability you need is already sitting in a licence you own.
ClearPass Policy Manager is a full on-premises policy engine with role-based policy, device profiling, guest and onboarding portals, and virtual appliance deployment. Aruba Central's cloud NAC (formerly Cloud Auth) suits sites that want 802.1X and MPSK without running a server. Both drive Dynamic Segmentation across Aruba wired, wireless and SD-WAN. HPE Aruba Networking is a SonarNext partner.
ISE gives deep context on every connection — who, what device, when, where and how — across wired, wireless and VPN, with TACACS+ device administration, posture, profiling, guest and BYOD services. Meraki builds RADIUS, group policy and adaptive policy into the dashboard for sites that do not need a separate policy server. Cisco is a SonarNext partner.
FortiNAC adds visibility, profiling and automated response across multi-vendor switching and wireless. On a Fortinet Security Fabric, FortiGate can apply NAC policy directly to FortiSwitch and FortiAP ports and quarantine a device the moment the firewall flags it. Fortinet is a SonarNext partner.
Each of these checks against an identity source: Microsoft Entra ID and Active Directory, Okta and other SAML single sign-on providers, LDAP and SQL stores, with device compliance from Intune or SOTI so an unmanaged or out-of-date device is treated differently from a healthy one. Underneath them all is RADIUS, and getting it right, with redundant policy servers and sensible timeouts, is most of what makes NAC reliable, cloud-hosted or on-premises, single-brand or multi-vendor. The same engines provide TACACS+ device administration, giving each engineer their own login to switches, firewalls and controllers, restricting which commands they can run and recording every change, which retires the shared admin password everyone in IT knows. Where SASE or firewall policy is in use, NAC roles feed into it.
Segmentation & zero trust
Authentication answers who you are; segmentation answers what you can reach, and it is where NAC pays for itself. Instead of one VLAN per SSID or switch port, the policy server assigns each connection a role from the user, the device type, its compliance state and where it connected, and the network enforces it on wireless and wired alike. Zero trust is simply that in practice: no device is trusted because it is inside the building, and each gets the least access it needs, so a label printer reaches the print server and a camera reaches the video recorder, and if either is compromised that is where the damage stops.
Guest & BYOD
Guests and personal devices are the reason the shared password never changes. Give them their own properly controlled path, branded to your organisation with terms of use accepted on the portal, and the corporate network can finally be locked down. Guest traffic goes straight to the internet, isolated from every internal segment and from other guests, so a visitor's infected laptop cannot see the device next to it.
How we roll it out
NAC projects fail in one of two ways: switched on in enforcement mode on day one, locking out a forgotten device that turns out to run the conveyor, or left in monitor mode forever because nobody had the confidence to enforce. We stage it so neither happens.
The policy server runs in monitor mode, authenticating and logging every connection but blocking nothing, while profiling builds an inventory of what is really on your network, including the devices nobody remembered.
From that inventory we agree the roles, segments and access rules with your team, including how headless devices are handled, while certificates and Wi-Fi profiles are pushed through Intune or SOTI ahead of time.
Enforcement is switched on one group at a time, starting with the least critical and ending with the operational fleet, with each stage checked against the logs and shift supervisors told what is changing and when.
Before enforcement goes near the floor we agree and test what the network does if the policy servers are unreachable, a documented way to restore access to critical devices quickly, and named people who can use it.
You receive the policy design, device inventory, certificate details and runbooks for adding devices, onboarding sites and handling lockouts, written for the people who will be doing it at 6am.
Running it
The most common cause of a NAC outage is not an attack or a hardware failure but a certificate reaching its expiry date. When the policy server's own certificate lapses, every device checking it refuses to connect at the same moment; when a root or issuing certificate lapses, devices stop getting new ones; either way the site finds out when the handhelds stop. We track every certificate in the chain, from the RADIUS server to the issuing authority and the device certificates MDM is renewing, and act well before expiry. The same monitoring watches authentication failure trends, policy server health and RADIUS response times, so a problem shows up as an alert rather than a queue at the service desk.
Day to day, new device types are profiled and assigned a role, joiner and leaver access is kept in step with the directory, firmware and platform updates are planned rather than a surprise, and access logs are retained for audit and incident review. For organisations that want it handled end to end, NAC runs as part of managed IT services, with a dedicated IT manager, real-time monitoring and response commitments agreed in writing up front.
FAQs
Network access control (NAC) checks every device before it joins your wired or wireless network, then decides where it lands and what it can reach. Instead of one shared password that lets anyone onto everything, each user and device proves its identity, and a policy server assigns it a role. You also get a log of who and what connected, when and where.
Both are ways of authenticating with 802.1X. PEAP uses a username and password inside an encrypted tunnel; EAP-TLS uses a certificate installed on the device, with no password at all. EAP-TLS is more secure and, once certificates are delivered by MDM, easier for users because nothing has to be typed. We use PEAP only as a transition step where devices are not yet managed.
Most enterprise Android handhelds support 802.1X and certificates through MDM. For headless devices that genuinely cannot, we use multiple or identity pre-shared keys, so each device or group has its own key and lands in its own segment. MAC authentication combined with profiling is kept as a last resort, and those devices are restricted to only the systems they need.
It should not, if it is rolled out properly. We start in monitor mode, where nothing is blocked, to build an inventory of every device on the network. Enforcement is then switched on in stages, least critical first, with a tested fallback for the operational fleet if the policy servers are ever unreachable.
Usually the one that fits the network and identity systems you already have. HPE Aruba ClearPass or Aruba Central, Cisco ISE or Meraki, and Fortinet FortiNAC or FortiGate all do the job well on their own hardware, and some of the capability may already be in licences you own. We recommend based on your switching, wireless, directory and MDM, not on what we would prefer to sell.
Yes. Entra ID and Active Directory are the most common identity sources we integrate with, alongside Okta and other SAML providers. Intune, like SOTI MobiControl, can deliver device certificates and Wi-Fi profiles during enrolment and report compliance to the policy server, so an unhealthy device gets restricted access automatically.
If the policy server or issuing certificate expires, devices stop authenticating, often all at once. It is the most common cause of NAC outages we see. We track every certificate in the chain and renew well ahead of expiry, and ongoing monitoring can be included as part of a managed services agreement.
Related
Survey-led wireless design, so the network NAC protects actually covers the floor.
Intune and SOTI enrolment that delivers certificates and Wi-Fi profiles to every handheld.
Certified cabling and managed switching ready for 802.1X on every wired port.
Tell us what you are planning — a new site, a network that keeps dropping out, or IT that needs a safer pair of hands. We will come back with straight answers and a clear quote.