SafeConnect NAC

Secure your network by gaining visibility and control

All organizations are faced with the ever-increasing onslaught of unknown devices attempting to access their critical network infrastructure. When it comes to network security, each employee, contractor, customer, or supplier and their devices are a potential threat vector.  Additionally, an everyday challenge for CISOs, Directors, and IT Managers is enforcing network access privileges and security compliance policies without impeding access by their employees, contractors, and customers. These executives, managers, and their staff are also faced with the daunting task of correlating device information and user identity for regulatory compliance and security forensics.

The value of SafeConnect NAC is simply this— by ensuring that every connected device is visible, checked for compliance in real-time, and respectively blocked or allowed in real-time, security incidents can be reduced substantially.  Don’t risk your organization’s data and reputation by exposing it – instead ensure that the security of your network, your constituents’ personal information, and your intellectual property remains intact.

FEATURES AND BENEFITS

Know what’s on your network

Agentless device identification and profiling provides visibility into detailed information for devices on your network: Username, IP address, MAC address, Role, Device Type, Location, Time and Ownership.

SafeConnect NAC uses advanced heuristics and rich pattern analysis for strong device profiling:

Device discovery and profiling
  • SafeConnect NAC discovers new IoT and User Devices that attempt network access
  • SafeConnect NAC can either profile (determine device type) in a passive manner or quarantine the device until device type is explicitly known
  • SafeConnect NAC uses the following techniques to determine device types:
    • Deep Device Fingerprinting
      • DHCP
      • Web Browser User Agent Identification
      • URL Fingerprinting
      • MAC address OID fingerprinting
    • Input from external sources such as
      • in-line network devices (wireless access points, firewalls)
      • database resources

Control IoT or Browser-less Device Access

Whether it’s printers and VOIP phones, smart devices like thermostats and lights, or OT devices specific to your industry, controlling and monitoring these devices can be a real challenge. These devices can represent much of the risk in your environment, and many organizations are addressing this issue through network segmentation. SafeConnect NAC provides a consolidated view of traditional systems, mobile and IoT devices, and now, operational technology (OT) systems; giving you the ability to segment IoT devices either using ACLs or assignment to a specific VLAN from a single dashboard.

SafeConnect NAC allows multiple options designed to meet your varying requirements for these types of devices:

  • Passive Onboarding – You have an option for SafeConnect to recognize certain device types and passively allow them access.
  • Bulk Upload – You have an option to whitelist a group of devices with the MAC address, perhaps maintained in your asset management system, ensuring only these specific MAC addresses will get on the network.
  • Self-Registration – If you are in an environment where you have specific IoT Devices that need identity tied to it, these can be self-registered through the captive portal.

Assess comprehensive device compliance

Whether it’s your organization’s Acceptable Use Policies (AUP) or regulatory requirements, SafeConnect ensures devices on your network adhere and comply accordingly. Windows, macOS, and mobile devices are checked with deep endpoint assessments prior to granting network access to ensure that the device adheres to your AUPs and are also checked in real-time as they move across your network.

Meeting regulatory compliance requirements such as GDPR, HIPAA, PCI DSS, SOX, or GLBA revolve around knowing “who, what, when and where” for devices and users on your network and controlling access to the data your company needs to keep secure. SafeConnect NAC helps you achieve that visibility, security, and control - and automates policies that validate accountability, mitigate vulnerabilities and block evolving threats – ensuring your compliance with recurring audits.



Authenticate your users

Depending upon your environment, you can authenticate your users with multiple methods/protocols. End User AD/LDAP/SAML Authentication prevents unauthorized users from accessing network resources. SafeConnect NAC supports the following authentication types: EAP-PEAP (credential based), EAP-PEAP (machine based), EAP-TLS (certificate based), as well as domain and 802.1X Single Sign-On (SSO).

Secure access for guests, vendors and 3rd parties

End User Captive Portal for authentication of BYOD devices with extensive branding / customization capabilities

Guest Self-Registration automates the process of provisioning temporary network access for your guests. Set up different access levels and approval processes for guests, vendors or other 3rd parties needing access to your network. SafeConnect comes standard with a fully configured SMS gateway that provides international SMS support right out of the box. Device Enrollment with Bulk Upload MAC Address capability enables proper authentication for browser-less devices such as printers, VOIP phones, IP Cameras or any other IOT enabled device including optional network access assignment (VLAN, ACL, Role, Profile, etc.).


View real-time or historical management reporting

SafeConnect NAC gathers a wealth of real-time and historical context-aware device information called Contextual Intelligence, such as Username, IP Address, MAC Address, Role, Location, Time, Ownership and even Compliance Status. This information allows for more timely and informed security decisions.

Use the Real-time Reporting Dashboard for visibility into who and what is on your network along with a built-in reporting interface for 30 days of detailed device information and 6 months of historical information. These reports can be run on a schedule, on demand, or exported to other tools.

Additionally, a built-in reporting interface provides 30 days of detailed client information and 6 months of historical session information through an easy to use interface that can either be run on demand or scheduled to e-mail reports on a daily, weekly, or monthly basis. This data can also be exported to an external source like a SIEM for longer periods of data retention.


​Integrate to enhance current security investments​

SafeConnect NAC shares the contextual intelligence information it gathers with other security solutions such as identity-based firewalls, web content filters, SIEM, and bandwidth management solutions to enhance their capabilities well beyond the scope of traditional domain devices. 

This capability is bi-directional and can receive alerts from Advanced Threat Detection systems to enforce a real-time quarantine for severe alerts. There will be no incidents of missing a middle-of-the-night critical alert spreading through your company, as it will be blocked immediately.

A sample of our Integration Partners

Use your existing network

With SafeConnect NAC, you have flexible network integration options, which means that in most cases, you’ll be able to implement SafeConnect NAC without changing your current network infrastructure.

Included is a RADIUS server with Layer 2 Network Integration that allows you to authenticate users and devices, control network access using 802.1X and/or by MAC address and assign network privileges for authenticated users and devices. Bulk NAS importing and NAS CIDR notification options are available along with custom RADIUS attribute creation. Network Access Control and Assignment provides wired port level and wireless SSID control. This can be done with Dynamic VLAN Assignment, Downloadable ACLs (dACL), and/or Role Based Access such as Roles, Profiles and Filter-Id.

Optionally, Layer 3 integration bypasses the requirement for RADIUS with Policy Based Routing. This can also be used in addition to basic RADIUS server and MAC address whitelisting for the initial network assignment.

A helpful feature is that controls can be implemented to restrict access to a specific network VLAN based on allowed host types and/or MAC addresses, a feature particularly useful for assigning IoT devices such as printers, VOIP phones and IP Cameras to a segmented VLAN.

Scale capacity and availability as you grow

Leverage VM hardware fault tolerance or purchase the High Availability (HA) option for active/passive nodes. Additionally, multi-node supported clusters are an option for environments of over 25,000 devices.

Install and manage without complicated, lengthy consulting services

Remotely deploy with a time proven 5-step install process with access to engineering support throughout. Once implemented, ongoing support includes: 24x7 proactive monitoring & support, nightly configuration backups and automated updates of new device fingerprints, OS & Antivirus signature updates, and either scheduled or automated version upgrades. See what our customers have to say in Gartner Peer Insights

★★★★★

Account Analyst
Industry: Communications
Role: Sales and Marketing
Firm Size: 500M - 1B USD
Implementation Strategy: Worked with just the vendor

Our network is very wide and handles a large number of devices, managing them all is quite cumbersome because it required a large investment and a lot of time, in addition to that it paralyzed the operations, because our collaborators had to work in other terminals while the process was being carried out. Now with SafeConnect all the computers in the network are connected and managed from the software

★★★★★

Account Analyst
Industry: Services
Role: Product Engineer
Firm Size: 250M-500M USD
Implementation Strategy: Completely internal

We have used this product for our network security at the office. We used this product to block unauthorized access to the network and define some security policies. Key factors that drove our decision were product roadmap and future vision, product functionality and performance and strong services expertise

★★★★★

Systems Engineer
Industry: Education
Role: Enterprise Architecture and Technology Innovation
Firm Size: 500M - 1B USD
Implementation Strategy: Worked with just the vendor

The solution is very reliable, flexible and exceeds our needs. The vendor is very responsive to our changing environment and always willing to assist. Support is great, fast responding and knowledgeable

★★★★

System Administrator
Industry: Finance
Role: Infrastructure and Operations
Firm Size: 250M - 500M USD
Implementation Strategy: Completely internal

An easy to deploy NAC (Network Access Control) solution that helps managing all the wireless devices attempting to estabilish a network connection using the corporate network