A complete NAC appliance for SMBs and MSPs — authenticates every device, enforces policy automatically, deploys in under 30 minutes.
| Capability | What it means for you |
|---|---|
| 802.1X port & wireless authentication | Devices must prove who they are before they connect — not after an incident |
| Dynamic VLAN assignment | Staff, guests and contractors land on the right segment automatically — no manual switch work |
| Microsoft Entra ID / LDAP sync | Your existing user directory drives network access — no duplicate identity management |
| Captive portal for guest access | Guests reach an isolated network through a branded voucher page — never your internal systems |
| EAP-TLS certificate authentication | High-assurance device trust with no passwords to steal, rotate or share |
| IEEE OUI device profiling & inventory | See exactly what is on your network — every device identified by vendor and type, with unmanaged / randomized MACs flagged automatically |
| Appliance CVE / CVSS monitoring | Know the moment a published vulnerability affects the appliance's own software components — with severity, remediation and PDF/JSON export |
| MSP multi-tenant dashboard | Manage all client environments from one platform — fully isolated per client |
| GPG-signed updates | Every update verified before installation — supply-chain secure by design |
| Compliance evidence export | Structured audit trail for ISO 27001 A.9, Cyber Essentials and SOC 2 — always ready |
The most widely deployed EAP method. Users authenticate with their AD/Entra ID username and password. No certificates required on the client side.
Mutual certificate authentication — the strongest EAP method. Both client and server present certificates. Ideal for managed corporate devices.
Tunneled TLS with PAP inner auth. Useful for Linux clients and legacy devices that don't support PEAP natively.
Multiple EAP methods can be chained. PortGuard tries each in order based on client capability, falling back gracefully.
Authenticate 802.1X users against Microsoft Entra ID, LDAP / Active Directory or SAML 2.0 — no duplicate identity management, your existing directory drives access.
Directory groups sync to PortGuard continuously. Map a group to a VLAN and its members land on the right segment automatically on their next authentication.
Machine authentications (host/PCNAME) are matched to the synced Entra ID device — the Devices page shows domain/PCNAME instead of a raw MAC or hostname.
Choose which source wins when a user exists in several (local, LDAP, SAML, Entra). If one directory is unreachable, the next takes over — no single point of failure.
Map AD groups or LDAP OUs directly to VLANs. A user in "Finance" always lands on VLAN 20, regardless of which switch port they connect to.
Assign VLANs by profiled device group (printer, CCTV, IP phone, IoT) resolved from IEEE OUI vendor data — one rule per group, no per-MAC work, manual override supported.
A policy condition can match the authentication realm (e.g. company.it) — route multiple domains or tenants through one appliance, each to the correct VLAN.
When a user's group changes mid-session, PortGuard sends a CoA to the switch — no disconnect required, VLAN changes live.
Every MAC is matched against the official IEEE registry (~53,000 vendor prefixes, bundled offline) to identify the manufacturer of each connected device — no cloud lookup, works fully air-gapped.
Devices are classified into Computer, Phone/Tablet, Printer, CCTV, VoIP, IoT and Switch using a confidence engine that combines vendor rules, auth/EAP method, hostname & user patterns, MAC randomization and VLAN — real signals only, no fabricated fingerprints. Manual override always wins.
A dedicated Devices page lists every endpoint seen (vendor, group, VLAN, last identity, last-seen), and the SOC/NOC "Live Network State" view shows live endpoints in real time beside a device-profiling summary. Randomized / private MACs are flagged on sight.
Turn profiling into control: one policy sends every CCTV camera to an isolated VLAN and every printer to the print segment — no per-device configuration.
Separate portal profiles per SSID / NAS — each with its own VLAN, session duration, bandwidth cap, idle timeout and concurrent-session limit.
Reception staff generate time-limited, usage-capped vouchers for visitors. Batch generation and print/export for the front desk.
A terms-acceptance splash page for open guest networks — no code required, while VLAN, session and bandwidth limits are still enforced.
Per-profile bandwidth limits (up/down). Guests get limited bandwidth, employees get full speed — enforced via RADIUS attributes.
The appliance's own software components are checked against CVE feeds on a schedule. Findings carry CVSS severity and a remediation plan, exportable as PDF or CVE JSON for your security team.
Every endpoint that reaches the RADIUS auth layer without a known identity is surfaced as a security event and counted on the dashboard — unauthenticated access attempts stay visible, not buried in switch logs.
Every RADIUS reject is logged with identity, MAC, NAS and reason. Failure trends and EAP errors surface on the dashboard so credential problems and misconfigured supplicants are caught early.
All issued certificates (server TLS, EAP CA, client certs) are tracked in a certificate inventory, and the dashboard flags those approaching expiry or already expired.
All dashboard widgets update via WebSocket push — no polling. Auth events appear within 2 seconds of occurrence.
Native SNMPv2c/v3 with a ready-to-use PRTG device template exposing 28 custom OIDs — RADIUS sessions, rejects, VLAN usage, EAP failures.
10 operational metrics exported on localhost:9753/metrics. Compatible with Grafana, Alertmanager, and any Prometheus-compatible system.
All security events and auth decisions can be forwarded to a remote syslog server — compatible with Splunk, Graylog, and any SIEM.
30-day trial with full Enterprise access. No credit card required.