← Back to Home
// Full Feature List

Everything you need to
control network access

A complete NAC appliance for SMBs and MSPs — authenticates every device, enforces policy automatically, deploys in under 30 minutes.

// What each capability means for your business

Technical capability → business outcome

Capability What it means for you
802.1X port & wireless authentication Devices must prove who they are before they connect — not after an incident
Dynamic VLAN assignment Staff, guests and contractors land on the right segment automatically — no manual switch work
Microsoft Entra ID / LDAP sync Your existing user directory drives network access — no duplicate identity management
Captive portal for guest access Guests reach an isolated network through a branded voucher page — never your internal systems
EAP-TLS certificate authentication High-assurance device trust with no passwords to steal, rotate or share
IEEE OUI device profiling & inventory See exactly what is on your network — every device identified by vendor and type, with unmanaged / randomized MACs flagged automatically
Appliance CVE / CVSS monitoring Know the moment a published vulnerability affects the appliance's own software components — with severity, remediation and PDF/JSON export
MSP multi-tenant dashboard Manage all client environments from one platform — fully isolated per client
GPG-signed updates Every update verified before installation — supply-chain secure by design
Compliance evidence export Structured audit trail for ISO 27001 A.9, Cyber Essentials and SOC 2 — always ready
🔐
// EAP Layer

802.1X Authentication — Full EAP stack with FreeRADIUS

PEAP-MSCHAPv2

The most widely deployed EAP method. Users authenticate with their AD/Entra ID username and password. No certificates required on the client side.

EAP-TLS

Mutual certificate authentication — the strongest EAP method. Both client and server present certificates. Ideal for managed corporate devices.

TTLS-PAP

Tunneled TLS with PAP inner auth. Useful for Linux clients and legacy devices that don't support PEAP natively.

EAP Chaining

Multiple EAP methods can be chained. PortGuard tries each in order based on client capability, falling back gracefully.

🪪
// Identity

Entra ID & LDAP Federation — Connect your existing directory

Directory Identity Sources

Authenticate 802.1X users against Microsoft Entra ID, LDAP / Active Directory or SAML 2.0 — no duplicate identity management, your existing directory drives access.

Group → VLAN Sync

Directory groups sync to PortGuard continuously. Map a group to a VLAN and its members land on the right segment automatically on their next authentication.

Directory-Driven Device Names

Machine authentications (host/PCNAME) are matched to the synced Entra ID device — the Devices page shows domain/PCNAME instead of a raw MAC or hostname.

Provider Priority / Fallback

Choose which source wins when a user exists in several (local, LDAP, SAML, Entra). If one directory is unreachable, the next takes over — no single point of failure.

🔀
// Network Segmentation

Dynamic VLAN Assignment — Right network, every time

Identity-based VLAN

Map AD groups or LDAP OUs directly to VLANs. A user in "Finance" always lands on VLAN 20, regardless of which switch port they connect to.

Device-based VLAN

Assign VLANs by profiled device group (printer, CCTV, IP phone, IoT) resolved from IEEE OUI vendor data — one rule per group, no per-MAC work, manual override supported.

Realm / Domain Routing

A policy condition can match the authentication realm (e.g. company.it) — route multiple domains or tenants through one appliance, each to the correct VLAN.

Change of Authorization (CoA)

When a user's group changes mid-session, PortGuard sends a CoA to the switch — no disconnect required, VLAN changes live.

🖥️
// Device Visibility

Device Profiling & Inventory — Know every device on your network

IEEE OUI Vendor Recognition

Every MAC is matched against the official IEEE registry (~53,000 vendor prefixes, bundled offline) to identify the manufacturer of each connected device — no cloud lookup, works fully air-gapped.

Multi-Signal Classification

Devices are classified into Computer, Phone/Tablet, Printer, CCTV, VoIP, IoT and Switch using a confidence engine that combines vendor rules, auth/EAP method, hostname & user patterns, MAC randomization and VLAN — real signals only, no fabricated fingerprints. Manual override always wins.

Live Device Inventory & Network State

A dedicated Devices page lists every endpoint seen (vendor, group, VLAN, last identity, last-seen), and the SOC/NOC "Live Network State" view shows live endpoints in real time beside a device-profiling summary. Randomized / private MACs are flagged on sight.

Group-based VLAN Enforcement

Turn profiling into control: one policy sends every CCTV camera to an isolated VLAN and every printer to the print segment — no per-device configuration.

🌐
// Guest & BYOD Access

Captive Portal — Flexible portal profiles

Multi-profile Support

Separate portal profiles per SSID / NAS — each with its own VLAN, session duration, bandwidth cap, idle timeout and concurrent-session limit.

Voucher System

Reception staff generate time-limited, usage-capped vouchers for visitors. Batch generation and print/export for the front desk.

Open / Splash Mode

A terms-acceptance splash page for open guest networks — no code required, while VLAN, session and bandwidth limits are still enforced.

Bandwidth Control

Per-profile bandwidth limits (up/down). Guests get limited bandwidth, employees get full speed — enforced via RADIUS attributes.

🔍
// Threat Detection

Security & Compliance — Proactive security posture

Appliance CVE / CVSS Monitoring

The appliance's own software components are checked against CVE feeds on a schedule. Findings carry CVSS severity and a remediation plan, exportable as PDF or CVE JSON for your security team.

Unknown Device Detection

Every endpoint that reaches the RADIUS auth layer without a known identity is surfaced as a security event and counted on the dashboard — unauthenticated access attempts stay visible, not buried in switch logs.

Authentication Failure Tracking

Every RADIUS reject is logged with identity, MAC, NAS and reason. Failure trends and EAP errors surface on the dashboard so credential problems and misconfigured supplicants are caught early.

Certificate Expiry Monitoring

All issued certificates (server TLS, EAP CA, client certs) are tracked in a certificate inventory, and the dashboard flags those approaching expiry or already expired.

📡
// Observability

Monitoring & Integration — Full visibility, standard tools

Real-time WebSocket Dashboard

All dashboard widgets update via WebSocket push — no polling. Auth events appear within 2 seconds of occurrence.

SNMP + PRTG Template

Native SNMPv2c/v3 with a ready-to-use PRTG device template exposing 28 custom OIDs — RADIUS sessions, rejects, VLAN usage, EAP failures.

Prometheus Metrics

10 operational metrics exported on localhost:9753/metrics. Compatible with Grafana, Alertmanager, and any Prometheus-compatible system.

Syslog (RFC 5424)

All security events and auth decisions can be forwarded to a remote syslog server — compatible with Splunk, Graylog, and any SIEM.

Ready to try all features?

30-day trial with full Enterprise access. No credit card required.

Start 30-Day Trial → View Architecture