Network access control · 802.1X EAP-TLS

Nothing reaches the wire without a trusted identity.

Turn on network admission and every port becomes a checkpoint. A device holding a Skans-issued certificate is let onto its segment; anything else is rejected at the switch and never reaches the network. It runs on the appliance's native Windows NPS (RADIUS) — no extra NAC appliance to buy or run, stood up and hidden behind the console.

Skans console · Devices
The Skans device inventory — cameras, switches and firewalls with certificate status, capability tier and admission lane

802.1X EAP-TLS

Only a trusted certificate opens the port.

Admission is decided by cryptography, not a password or an allow-list you maintain by hand. A device presents the certificate Skans issued it; NPS runs EAP-TLS and checks the chain back to your enclave's own Root CA; a valid identity gets an Access-Accept and its port opens, while a missing or untrusted certificate gets an Access-Reject and the port stays shut. There is no partial state and no fail-open — a device either proves a trusted identity or it stays off the wire.

  • Runs on native Windows NPS — the installer stands up NPS, AD CS and AD DS / GPO together and hides all three behind the console. There is no separate NAC appliance to license or operate.
  • Chain-trust is the always-on gate — a certificate that doesn't chain to your Skans Root CA is rejected. The trusted store and EAP-TLS policy are set up for you at install.
  • Every decision is visible — the console surfaces live admissions with accept / reject counts, the EAP type, the account, and which switch sent them (NPS security events 6272 and 6273).
  • No hand-authored policy — the Setup Wizard turns admission on from golden-config defaults, bound to the appliance's own server certificate. There is no operator CLI for it and none is needed.
Skans console · NOC
The Skans NOC wall — fleet health, certificates, devices-by-tier and a RADIUS / NPS Serving status tile

Meet the gear where it is

Not every device can hold a certificate. We plan for that.

Mixed-vintage estates are the norm — a new camera next to a fifteen-year-old PLC. Skans sorts every device into a capability tier and applies the strongest control it can actually support, rather than pretending a weak device is admitted.

  • Tier A — cert-capable — full 802.1X EAP-TLS admission by the device's own Skans-issued certificate.
  • Tier B — limited — no supplicant, but identifiable: admitted by MAC (MAB) and placed on a restricted, RADIUS-assigned dynamic VLAN using the standard Tunnel-Type / Tunnel-Medium-Type / Tunnel-Private-Group-ID attributes.
  • Tier C — legacy — old PLCs, raw Modbus and BACnet MS/TP that can't hold a certificate are never faked onto the wire; they're segmented behind a protective gateway, allow-listed to only the flows they need, and monitored — NIST 800-82 compensating controls, not fake admission.
  • Standards-based, lab-proven on UniFi — the validated authenticator is a UniFi Cloud Key controller; any switch or AP that speaks standard 802.1X, MAB and RADIUS dynamic VLAN works the same way.
Skans console · Devices
Device inventory rows tagged by capability tier A, B and C with certificate status and admission lane

Safe by construction

A write path that can't lock you out — and a lane that can't wedge.

Turning on admission means writing config to live switches and standing up a RADIUS service the whole site depends on. Skans is built so that path is safe by construction: staged rollout, a break-glass way back, and a service that stays honest about its own health.

Fail-closed at the port

A device either proves a trusted identity or it never gets a port or a VLAN. There is no partial or fail-open admission state to slip through.

Break-glass and rollback

Roll out monitor-first, segment cameras onto their own VLAN, and keep a break-glass path so admission never locks you out of your own gear. Already-admitted sessions survive a RADIUS outage — a RADIUS problem becomes a 'fix it Monday,' not a 3 a.m. lockout.

A RADIUS lane that can't fail silently

Skans functionally probes its own RADIUS every few minutes — not 'is the service running' but 'is it answering on the wire.' A silent failure raises a proactive alert, and a one-click repair brings it back safely.

Connections pinned against MITM

When Skans logs into a switch or device to configure it, the connection is pinned to that device's exact certificate and SSH host key. An impostor presents a different key, the connection fails closed, and nothing sensitive is handed over.

How it turns on

The PKI runs behind it. You press one button.

You never hand-author an EAP-TLS policy or edit NPS. The Setup Wizard binds NPS to the appliance's own server certificate and its RADIUS shared secret — held in the credential vault, never in a config file — and turns admission on from golden-config defaults. From there, bringing a site's gear online is a short, plain-language job.

  • Register each switch once — on the Network page, add each switch or AP as a RADIUS client with its name, IP and shared secret. NPS won't answer for an authenticator it doesn't know.
  • Secrets in the vault — RADIUS shared secrets and device logins live in the TPM-hardened credential vault, encrypted, with reveal and copy audited — never in plaintext JSON.
  • Watch devices come on — the console shows recent admissions in plain terms: accepted, rejected, and by which switch — enough to confirm a segment is authenticating or spot a device being turned away.
  • Outcomes, not certificate chains — the operator sees results; AD, Kerberos, the CA and the RADIUS policy stay behind the wizard.
Skans console · Passwords
The Skans credential vault — device logins and RADIUS secrets encrypted, TPM-protected, with reveal and copy audited

Compliance by design

The access-control evidence an assessor asks for.

Identity-gated admission is the technical enabler for the Access Control and Identification & Authentication families. Skans maps what it enforces to those controls and hands you the evidence — it supports your assessment; it doesn't certify you, and organizational controls stay yours.

  • AC-3 access enforcement — 802.1X plus MAB with RADIUS-assigned VLANs gates the network to trusted devices only.
  • IA-3 device authentication — every admitted device is authenticated by a certificate from your own CA, not a shared password.
  • Live posture, per family — the compliance view maps admission to NIST 800-171 / CMMC control families, with an ISO 27001 crosswalk and a signed, tamper-evident evidence pack you can hand over.
  • Honest scope — Skans supplies the technical evidence; organizational, people and physical controls remain yours via a responsibility matrix, with any gaps tracked in a POA&M.
Skans console · Compliance
The NIST security-posture ring with per-control-family cards including Access Control (AC) and Identification & Authentication (IA)

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.