← Back to list
Security & Privacy
#NAC#802.1X#접근제어#제로트러스트#엔드포인트
Last updated · 2026-10-09

Network Access Control (NAC)

1. Overview

A. Definition and Background

Network Access Control (NAC) is a security control system that identifies and authenticates the devices and users attempting to connect to a network, assesses whether they comply with security policy (integrity, patch level, antivirus status, etc.) through posture assessment, and then allows, blocks, quarantines, or restricts access according to the result. In a word, it is summarized as "a gatekeeper at the entrance of the network that admits only trustworthy people and devices, and only when they are in a trustworthy state."

The fundamental background behind NAC's emergence lies in "the collapse of the traditional perimeter model that granted trust merely because a device was connected to the network." In the past, an enterprise network was structured so that plugging in a LAN cable in the office or connecting to the corporate wireless immediately granted access to internal resources. In other words, "being physically inside" was the implicit premise for "being trustworthy." However, as laptops, smartphones, and IoT devices proliferated, as outsourced workers and visitors connected to the corporate network at will, and as remote work and BYOD (Bring Your Own Device) became routine, this premise no longer held. A single unpatched device, or a single personal laptop infected with malware, exposes the entire network to threats the moment it connects to the internal network.

Historically, NAC gained momentum in the mid-2000s in the wake of incidents of mass worm propagation across corporate networks. At the time, cases repeated in which a laptop infected externally would, as soon as it connected to the corporate network, let a worm spread laterally throughout the interior and paralyze operations, and the idea of "inspecting a device's health status before connection" was productized. Early on it centered on endpoint compliance that checked antivirus and patch status, but it later developed into today's integrated NAC by combining IEEE 802.1X standard authentication, user/device identification, and role-based access control. Recently it has been re-spotlighted as a key means of implementing, at the network layer, the "verify on every connection (never trust, always verify)" principle of Zero Trust architecture.

B. Necessity

A modern enterprise network sees a volume and variety of devices that administrators cannot grasp one by one, constantly connecting and disconnecting. In particular, IoT/OT (operational technology) devices such as CCTV, printers, and sensors cannot have agents installed and are hard to patch, so if left on the network unidentified they become a foothold for attacks. NAC provides visibility into "what is connected to the network" and fundamentally reduces the attack surface by filtering out untrustworthy devices at the entrance.

The necessity of NAC is also clear from the regulatory and compliance perspective. Access-control requirements under ISMS-P, the Electronic Financial Supervision Regulations, and the Personal Information Protection Act require that "only authorized parties access information systems," and NAC makes it possible to automate and demonstrate such controls at the network layer through blocking unauthorized devices and managing access history. Moreover, when a breach occurs, access logs of "when, which device, and as which user connected" become the key basis for root-cause investigation and accountability.

In practice, NAC is a key means of blocking internal spread. Even if ransomware infects one device, if NAC immediately quarantines the abnormal device and restricts accessible segments by role, it can prevent the damage from spreading enterprise-wide. In that it controls "movement on the inside" after a perimeter-only defense has been breached, NAC is an essential layer of Defense in Depth. Ultimately NAC acts not as a "blocking wall" but as a "gateway that screens who is to be admitted and keeps watching even after they enter," filling the gap between perimeter defense and internal control.

C. Key Characteristics

NAC's characteristics condense into three. The first is the combination of Authentication and Posture assessment, judging not only "who/what it is" but also "whether it is safe right now." The second is dynamic, fine-grained Enforcement, adjusting network privileges in real time according to the result — beyond simple allow/block, through VLAN assignment, ACL application, bandwidth limiting, and quarantine-network steering. The third is continuous monitoring, watching changes in device state even after connection and immediately revoking privileges upon policy violation. Combining these three characteristics, NAC functions not as a "check once and done" control but as one that "verifies throughout the entire time it stays connected."

These three characteristics are also the decisive difference that distinguishes NAC from traditional access controls such as firewalls and VPNs. Whereas a firewall judges passage based on "the addressing information of IP and port," NAC judges based on the context and trust state of "whether that device is trustworthy right now." This dynamic, context-based control — in which privileges change for the same user and the same port if a device's patch status deteriorates — fundamentally distinguishes NAC from perimeter appliances that rely on static rules.

2. Overall Structure and Operating Principle of NAC

NAC should be understood not as a single appliance but as a pipeline of identify/authenticate → posture assessment → policy decision → enforcement → monitoring. Below is a structural diagram showing the overall components and control flow.

flowchart LR
  EP["Device (PC/IoT/BYOD)"] --> ENF["Enforcement point (switch/AP/firewall)"]
  ENF --> PDP["Policy decision point (NAC server)"]
  subgraph POL["Policy engine"]
    AUTH["Authentication (802.1X/MAB/Web)"]
    POS["Posture (patch/AV/integrity)"]
    RBAC["Role/policy mapping"]
  end
  PDP --> POL
  POL --> ENF
  ENF -->|"Allow"| PROD["Business network (segment)"]
  ENF -->|"Quarantine"| QNET["Quarantine net (remediate/update)"]
  PDP --> DIR["Identity store (AD/LDAP/RADIUS)"]
  PDP --> MON["Continuous monitoring/CoA"]
  MON --> ENF

The core of this structure is the separation of the "Policy Decision Point (PDP)" and the "Policy Enforcement Point (PEP)." When a device connects to the network, an enforcement point such as a switch, AP, or firewall intercepts the connection request and relays it to the NAC server (the policy decision point). The NAC server identifies the user/device by integrating with an identity store (Active Directory/LDAP/RADIUS), decides "allow/quarantine/block" by combining the posture result with predefined policy, and then returns that decision to the enforcement point to be realized as actual network privilege. This separated structure — decisions made centrally, enforcement carried out at the network edge — is the secret to how NAC maintains consistent policy even on large-scale networks.

A. Key Components

NAC's components divide into four categories by role. The policy server (PDP) is the brain that integrates authentication, posture, and role to decide access eligibility and privileges; representative commercial products include Cisco ISE, Aruba ClearPass, and FortiNAC. The enforcement point (PEP) is the hands and feet that actually apply the decision, including 802.1X-capable L2 switches, wireless APs/controllers, and firewalls. The agent/collector gathers device information and state either installed on the device (agent) or through network traffic and scanning (agentless). Finally, the identity/directory store holds user accounts and device asset information, providing the basis for identification.

A commonly confused point here is the relationship between the enforcement point and the policy server. No matter how refined a decision the policy server makes, if the enforcement point that must enforce it does not support 802.1X, dynamic VLAN, and ACL, the control remains a mere "recommendation." Therefore NAC adoption is not just a matter of installing a server; the premise that enforcement capability must be secured across the network infrastructure (switches/APs) is the first hurdle in practice.

Furthermore, the NAC server does not operate alone; the breadth of its integration with existing infrastructure governs its usefulness. The more it takes in and judges comprehensively — user identity from Active Directory/LDAP, device ownership and purpose from asset management (CMDB), mobile device compliance status from Mobile Device Management (MDM/UEM), and external threat information from threat intelligence and SIEM — the higher the precision of its policy. In other words, NAC delivers its true value when designed not as an "isolated gateway" but as an integration point that gathers signals from multiple security and management systems and converts them into access decisions.

B. Operating Procedure — the 802.1X Authentication Flow

IEEE 802.1X, NAC's standard authentication method, operates as a three-party structure of Supplicant, Authenticator, and Authentication Server. The supplicant is the device's 802.1X client, the authenticator is the switch/AP, and the authentication server is the RADIUS server. EAPoL (EAP over LAN) is used between the device and the authenticator, and RADIUS between the authenticator and the authentication server; before authentication the port is in a blocked state that passes only authentication traffic. Below is a detailed diagram of the entire process of authentication, posture assessment, and authorization.

sequenceDiagram
  participant S as "Supplicant (device)"
  participant A as "Authenticator (switch/AP)"
  participant R as "Auth server (RADIUS)"
  participant P as "Policy/posture"
  S->>A: Connection attempt (port blocked)
  A->>S: Identity request (EAP-Request/Identity)
  S->>A: Submit credentials (EAPoL)
  A->>R: Authentication request (RADIUS)
  R->>P: Verify user/device + posture request
  P-->>R: Patch/AV/integrity result
  alt Policy satisfied
    R-->>A: Allow + assign VLAN/ACL (Access-Accept)
    A-->>S: Grant business-network access
  else Policy violation
    R-->>A: Assign quarantine VLAN
    A-->>S: Steer to quarantine net (remediate/update)
  end
  Note over A,R: After connection, privileges can change dynamically via CoA

What stands out in this flow is that authentication and authorization, while separated, are bound into a single transaction. The authentication server does not merely return "correct/incorrect"; it carries authorization attributes (RADIUS attributes) such as VLAN ID, ACL, and session timeout in the Access-Accept response. According to these attributes, the enforcement point grants different network segments and privileges depending on the connecting user/device even on the same port. If a device's state changes after connection, RADIUS's CoA (Change of Authorization, RFC 5176) can change or block the privileges of an already-connected session in real time, making "continuous verification during connection" possible.

C. Pre-admission and Post-admission

NAC's point of control is divided into "pre-admission" and "post-admission." Pre-admission performs authentication and posture assessment before a device enters the network, in the manner of "if it is not healthy, do not admit it at all." Because it filters threats at the entrance it is the strongest, but it incurs connection delay as every connection passes through inspection, and it demands substantial enforcement infrastructure.

Post-admission, by contrast, allows connection first but monitors behavior and state after connection and revokes privileges upon policy violation. It provides flexibility for devices whose state changes frequently, or environments where blocking right away would paralyze operations. In practice the two are combined, and dual control is recommended — securing baseline trust with pre-admission at the entrance and continuously watching with post-admission after connection.

The choice between these two points ultimately comes down to the policy judgment of "when to withdraw trust." Pre-admission alone cannot control a device that was healthy at the time of connection but got infected afterward, while post-admission alone cannot stop a dangerous device from entering in the first place. Therefore a mature NAC links the first-pass verification at the moment of connection (pre-admission) and the continuous verification while the connection is maintained (post-admission) through CoA, binding the two points into a single control chain as "continuous trust evaluation" that revokes privileges the moment the state deteriorates. This is exactly where it meets the "continuous verification" principle of Zero Trust discussed later.

3. Comparison of NAC Deployment and Enforcement Methods

A. Agent-based and Agentless

The first axis of NAC design is "how device information is collected." The agent-based approach installs dedicated software on the device to collect deep and accurate state information such as patch level, antivirus status, disk encryption, and processes. It enables detailed posture assessment and automatic remediation, but the agent must be deployed and managed, and it cannot be applied to devices on which an agent cannot be installed, such as IoT/OT devices.

The agentless approach identifies and classifies devices without installing software on them, through DHCP fingerprinting, SNMP, traffic analysis, active scanning, and so on. With no installation burden it broadly covers even IoT and visitor devices, but because the information collected is relatively shallow it has limits for precise posture assessment. Since a real enterprise network is a mix of managed and unmanaged devices, a hybrid approach — applying agents to managed PCs and agentless to IoT and guests — is common.

What is easy to overlook here is the "difference in trust level" of agentless identification. Estimation based on DHCP fingerprinting or MAC OUI (manufacturer identifier) only "guesses" the kind of device, it does not "prove" it, so it can be bypassed if an attacker spoofs a MAC or disguises as a legitimate device. Therefore it is advisable to place agentless-identified devices in generally more restricted segments and to reinforce reliability by cross-verifying multiple identification bases such as active scanning and behavior analysis (multi-attribute matching). Making the trust level of the identification method proportional to the magnitude of privilege granted to that device is a core principle of NAC policy design.

B. In-line and Out-of-band

The second axis is "whether it inserts itself into the traffic path." In the In-line method, the NAC appliance sits on the traffic path and controls by passing all communication directly through it. Enforcement is certain and consistent, but the appliance may become a performance bottleneck and a single point of failure (SPOF). In the Out-of-band method, NAC enforces indirectly from outside the path by issuing commands (VLAN change, CoA) to switches and APs. With little impact on existing network performance and good scalability it is preferred on large networks, but enforcement depends on the switch's supported features. Most large-scale NAC is designed as 802.1X-based out-of-band.

C. Comparison of Enforcement Technologies

NAC enforcement is not a single technology but combines several methods depending on the environment. The table below compares the characteristics of representative enforcement technologies.

Enforcement tech Operating principle Strength Limitation
802.1X Port-based authentication (EAP/RADIUS) Strongest/standard, per-port control Needs support on both device and switch
MAB (MAC Authentication Bypass) Identify by MAC address Accommodates 802.1X-incapable IoT Vulnerable to MAC spoofing
Web authentication (Captive Portal) Browser-redirect authentication Suitable for guest/BYOD Unsuitable for automation/IoT
DHCP/ARP control Quarantine via address assignment/ARP manipulation No switch replacement needed Bypassable, low reliability
SNMP/VLAN change Dynamic VLAN control of switch ports Out-of-band enforcement Vendor/device dependent

The core revealed in this comparison is the "trade-off between strength and accommodation." 802.1X is the most robust but requires support on both the device and the switch, so legacy IoT that does not support 802.1X can only be accommodated with the less secure MAB. In other words, NAC design becomes a matter of portfolio design that hierarchically places the enforcement technology best suited to each device's characteristics, rather than "a single strongest method."

D. Application Cases and a Quantitative Understanding

As a concrete case, universities and hospitals of several thousand people control, with NAC, complex environments where students, patients, visitors, and medical devices are mingled. Faculty/staff PCs are strongly authenticated with 802.1X + agent, hundreds of medical and diagnostic devices are identified by MAB and device fingerprinting and quarantined in dedicated segments, and visitors are provided only an internet-only network via web authentication. If segments are separated by role so that one device's infection does not spread to the whole, even when a breach occurs the scope of damage is confined to that segment.

Quantitatively, NAC's effect manifests as "reduction of attack surface and dwell time." For instance, in an environment where unmanaged devices reach 20–30% of the total, identifying and quarantining them with NAC brings a substantial part of the previously unmanaged attack surface under control. In addition, work that used to take hours to manually find and block an infected device is done within seconds to minutes with CoA-based automatic quarantine, decisively narrowing the window of ransomware's internal spread. However, since such effects are proportional to the accuracy of asset identification and the sophistication of policy, for NAC it is "operational maturity," not "adoption," that decides success or failure.

As another case, consider manufacturing's smart factory. On the production line, hundreds to thousands of sensors, PLCs, and inspection devices not captured in the IT asset register are scattered about, and if they are connected to the corporate network unidentified, they become a fatal attack path leading directly to production stoppage upon external intrusion. Merely applying NAC first in non-intrusive passive mode to fully identify and inventory OT assets makes "previously invisible assets" visible, enabling risk to be assessed quantitatively. In this way, NAC often proves its adoption value by the side effect alone of "automatic acquisition of an asset inventory," even before blocking.

4. Deep Dive — NAC in the Era of Zero Trust and Cloud

Traditional NAC was designed on the premise of a clear perimeter called "the corporate network entrance." However, as remote work, cloud, and SaaS became universal, the situation of "both users and resources being outside the perimeter" became routine, and the network perimeter itself blurred. Accordingly, NAC's role is being redefined. Zero Trust architecture (NIST SP 800-207) demands to "remove trust based on network location and verify all access per resource," and NAC functions as the first gateway that implements this principle at the network layer. That is, NAC judges the trust level and state of devices/users to control network access, and on top of that ZTNA (Zero Trust Network Access) finely controls per-application access, combining into a multi-layered structure.

Technically, too, NAC is evolving in three directions. First, the intelligent-ization of device visibility, going beyond simple MAC/OS identification to automatically classify IoT/OT devices and detect anomalous behavior with AI/ML-based behavior profiling. Second, combination with microsegmentation, dynamically granting fine software-defined (SDN) segments beyond the coarse separation at the VLAN level. Third, Cloud-delivered NAC and SASE integration, moving away from on-premises-appliance-centric models and converging, within the SASE (Secure Access Service Edge) framework, into unified policy together with ZTNA, SWG, and CASB.

Meanwhile, the OT/ICS (industrial control system) environment is NAC's new battleground. For OT devices such as PLCs and HMIs on the production line, availability is the absolute priority, so agent installation or active scanning can cause equipment malfunction; thus an OT-specialized NAC centered on passive identification and non-intrusive monitoring is required. Linking with industrial-security standards such as IEC 62443, a design that quarantines unauthorized devices without production stoppage is emerging as a key challenge. Likely exam directions include ▲compare and explain NAC's pre-/post-admission and enforcement technologies ▲discuss NAC's role in Zero Trust and its relationship with ZTNA ▲present considerations when applying NAC in IoT/OT environments ▲describe the 802.1X authentication flow and the operation of CoA.

5. Considerations and Implications (Professional Engineer's Perspective)

To successfully settle NAC in place, one must approach it from the perspective of "phased rollout and an operating system," not "appliance adoption." A Professional Engineer's answer should discuss the following trade-offs and strategies together.

  • Balance of availability and security (phased rollout): Turning NAC on in full blocking mode from the start blocks even unidentified legitimate devices and paralyzes operations. Therefore a gradual maturity strategy of ① first gaining asset visibility in Monitor mode, ② verifying policy in Audit mode, and then ③ switching to Enforce mode is essential, and fail-open/fail-close policy must be defined in advance to match service characteristics.

  • Accuracy of asset identification (visibility is the premise): All of NAC's controls start from accurately knowing "what is connected." Unless identification accuracy is raised through fingerprinting, directory integration, and asset-management (CMDB) linkage, both mis-blocking due to misclassification and bypass by unauthorized devices occur simultaneously. Asset identification is NAC's starting point and the core capability that governs operational quality.

  • IoT/OT accommodation and enforcement-technology portfolio: How to safely accommodate IoT/legacy devices that do not support 802.1X is the greatest practical challenge. One must hierarchically combine enforcement technologies by device characteristics — identifying by MAB/fingerprinting while compensating for MAC-spoofing risk with dedicated-segment quarantine, and applying non-intrusive passive identification for OT.

  • Linkage strategy with Zero Trust/SASE: NAC should be positioned not as a standalone control but as the network-layer gateway of Zero Trust, and should complete the chain of "access control → continuous verification → automated response" by linking with ZTNA, microsegmentation, and SIEM/SOAR. A design that collects access logs and state changes into SIEM to use as input for threat correlation analysis is desirable.

  • Operational governance and policy lifecycle: NAC policy must be continuously updated as the organization, devices, and work change, and without a system that version-controls, reviews, and deploys policy like code, and an exception approval/expiry management process, policy becomes patchwork over time and control weakens. One must recognize that NAC is a matter of governance as well as technology.

References


In one line: NAC is an access-control system that identifies and authenticates devices/users at the network entrance and inspects their state to dynamically enforce allow/quarantine/block; it combines enforcement technologies such as 802.1X, MAB, and web authentication with pre-/post-admission to match device characteristics, with asset visibility and phased rollout deciding success, evolving into the network-layer gateway of Zero Trust and SASE.