All products

AnchorNAC

Know every device on your network.

Full network access control with 802.1X, a policy engine, device inventory, posture assessment and BYOD — plus built-in guest portal with corporate/guest network separation.

~500
Endpoints
Enterprise
802.1X
TEAP / TLS
4 hours
Offline RADIUS
4+
Certified vendors

Key features

802.1X access control

TEAP/TLS + RADIUS with dynamic VLAN assignment.

Policy engine

YAML rule-based, explainable access decisions.

Inventory & profiling

Identify and classify every device on the network.

Posture assessment

LUKS / BitLocker / FileVault disk-encryption checks + auto-remediation.

Guest portal & isolation

Built-in captive portal for guest Wi‑Fi with full corporate/guest VLAN separation.

BYOD (PKI/SCEP)

Secure certificate provisioning to personal devices.

TACACS+ admin AAA

Command-level authorization and audit for network devices.

How it works

Identity → policy → segment → access

  1. 1

    Authenticate

    Corporate devices via 802.1X; guests via captive portal (SMS, sponsor, voucher).

  2. 2

    Apply policy

    The YAML policy engine decides: corporate VLAN, guest VLAN, or quarantine.

  3. 3

    Check posture

    Corporate devices are assessed for encryption and patching; guests are isolated.

  4. 4

    Segment & connect

    Dynamic VLAN routes each device to the right network — full guest/corporate separation.

5651

Two compliance modes

Correlation mode

Firewall syslog + NAC session table = enriched access record.

Inline mode

The Edge N100 bridges traffic and captures the destination (HTTP Host, TLS SNI, DNS) directly.

Multi-vendor network support

Cisco CatalystAruba CXFortiGateMikroTikCisco CatalystAruba CXFortiGateMikroTik

Roadmap: Sophos · SonicWall · Palo Alto · UniFi

Packages

AnchorNAC Enterprise

~500 endpoints

Multi-site, multi-vendor mid-to-large networks.

  • Cloud-managed N100 edge
  • Full NAC core
  • 5651 inline + daily TSA

AnchorNAC Sovereign

Unlimited

Government, defence, air-gapped networks.

  • Fully on-premises
  • Air-gap support
  • Local TSA, high availability

Edge hardware

Edge N100 appliance

Intel N100, fanless, 2×GbE — hardened Linux with LUKS + dm-verity + RAUC A/B OTA.

Offline continuity

If the internet drops, RADIUS keeps running locally for up to 4 hours.

Take control of your network

Let's find the right package for you. Start with a short demo.