Fail-closed at the port
A device either proves a trusted identity or it never gets a port or a VLAN. There is no partial or fail-open admission state to slip through.
Network access control · 802.1X EAP-TLS
Turn on network admission and every port becomes a checkpoint. A device holding a Skans-issued certificate is let onto its segment; anything else is rejected at the switch and never reaches the network. It runs on the appliance's native Windows NPS (RADIUS) — no extra NAC appliance to buy or run, stood up and hidden behind the console.

802.1X EAP-TLS
Admission is decided by cryptography, not a password or an allow-list you maintain by hand. A device presents the certificate Skans issued it; NPS runs EAP-TLS and checks the chain back to your enclave's own Root CA; a valid identity gets an Access-Accept and its port opens, while a missing or untrusted certificate gets an Access-Reject and the port stays shut. There is no partial state and no fail-open — a device either proves a trusted identity or it stays off the wire.

Meet the gear where it is
Mixed-vintage estates are the norm — a new camera next to a fifteen-year-old PLC. Skans sorts every device into a capability tier and applies the strongest control it can actually support, rather than pretending a weak device is admitted.

Safe by construction
Turning on admission means writing config to live switches and standing up a RADIUS service the whole site depends on. Skans is built so that path is safe by construction: staged rollout, a break-glass way back, and a service that stays honest about its own health.
A device either proves a trusted identity or it never gets a port or a VLAN. There is no partial or fail-open admission state to slip through.
Roll out monitor-first, segment cameras onto their own VLAN, and keep a break-glass path so admission never locks you out of your own gear. Already-admitted sessions survive a RADIUS outage — a RADIUS problem becomes a 'fix it Monday,' not a 3 a.m. lockout.
Skans functionally probes its own RADIUS every few minutes — not 'is the service running' but 'is it answering on the wire.' A silent failure raises a proactive alert, and a one-click repair brings it back safely.
When Skans logs into a switch or device to configure it, the connection is pinned to that device's exact certificate and SSH host key. An impostor presents a different key, the connection fails closed, and nothing sensitive is handed over.
How it turns on
You never hand-author an EAP-TLS policy or edit NPS. The Setup Wizard binds NPS to the appliance's own server certificate and its RADIUS shared secret — held in the credential vault, never in a config file — and turns admission on from golden-config defaults. From there, bringing a site's gear online is a short, plain-language job.

Compliance by design
Identity-gated admission is the technical enabler for the Access Control and Identification & Authentication families. Skans maps what it enforces to those controls and hands you the evidence — it supports your assessment; it doesn't certify you, and organizational controls stay yours.

Talk to us
Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.