Network Access Control (NAC) goes beyond 802.1X authentication by evaluating whether a device meets defined security requirements—such as patch status, antivirus currency, and endpoint protection—before and after granting network access.
Network Access Control (NAC)
802.1X is great, but all it really does is authenticate a device. It doesn't check the device to see if it's set up properly to access the network. For that, we have something like network access control. So let's talk about network access control and what it does.
802.1X will not allow a computer to access a network until it authenticates. This is a great starting point, but let's say this machine is full of infections. Maybe it has some viruses on it, maybe it has some worms on it, some malware that is causing it to malfunction. Maybe it's not updated or patched, or maybe it has some issues on it. 802.1X is still going to allow it onto the network as long as it authenticates.
But there is a mechanism that we can do to not allow this device to gain access to the network if it does have malware on it, or if things are not patched and updated.
Network access control is both a methodology and technologies that help us validate a machine and make sure that the machine is valid, that the user is valid, that the operating system is patched, antivirus is patched, antivirus has scanned the machine recently, that vulnerability assessment has been done on the machine, that there's some sort of maybe intrusion detection systems or intrusion prevention system on the machine, maybe some sort of endpoint detection and response.
Really, it could be any one of a number of things, so it doesn't have to be all of these things. It could just be a subset of these things. It's whatever we set up, whatever stipulations we want to put into place to make sure that this machine is going to be safe for the rest of the network when it gets added to the rest of the network.
Now, when we set up NAC, network access control, what can happen is we could either set it up pre-admission or post-admission or both. So pre-admission just means that this machine, before it can connect to the rest of the network, is going to be checked. Does it meet certain criteria? If so, then it can join the network. Post-admission means, is it going to continually be checked after that? So we go back and we check this to say, hey, are you still in compliance?
So an example of this is that a machine might be patched and updated when it first joins the network. But if a zero day patch comes available, and it's never been disconnected from the network and it has not been updated, then a post-admission would then not allow it to continue to connect to the network until that update is made.
When it comes to NAC, we can set it up with an agent or being agentless. If we are agentless, that means nothing's installed on this machine. We're just using the native tools on the machine to do checks on it before it accesses the rest of the network. Versus agent means that we install some sort of NAC agent on the machine, and that NAC agent helps us to monitor things.
This is obviously a little more to set up, with this agent-based, and they have to have the agent installed ahead of time. Versus agentless, you don't have to have it installed ahead of time. The problem with agentless is it's limited in the scope of what it can check, versus we have better checks involved if we have the agent installed.
Now, what happens if a machine doesn't meet the criteria necessary to join the network? Well, one is it could just deny that it can't connect to the network. Another thing that could happen is it could be placed on another network that is a remediation network. So in that case right there, maybe it's on this separate network where it can go out and get its updates and get patched, so that once it's patched and okay, now it can join the network that it's trying to join.
So there is a difference between quarantining this machine and making sure that it doesn't have access to anywhere, or giving it access to some sort of other network that it can perform some remediation steps to get up to speed so it can connect to the actual network.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →