Atlas Access
Network Access Control
Nothing joins the network without proving what it is — 802.1X access control you run and own end to end, no vendor appliance and no per-seat licence.
Why this exists
Without Atlas Access
A visitor plugs their laptop into a meeting room port and gets full LAN access. An employee brings a personal device with active malware — it joins the Wi-Fi and starts scanning. An IoT camera on the same VLAN as the file server gets compromised. None of these events generate an alert. The network does not know what is connected to it.
With Atlas Access
Every device must authenticate. A domain laptop presents an EAP-TLS certificate and gets VLAN 20. A printer uses MAC Authentication Bypass and lands in VLAN 40. A visitor's phone gets a captive portal and VLAN 30 (guest) with no internal access. An unknown device goes to VLAN 99 (quarantine). PacketFence profiles every device — OS, type, vendor — and logs every connection event.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(i) | Only authenticated and authorised devices connect to the network | FreeRADIUS accounting log · VLAN assignment audit |
| BSI INF.1.1 | Physical and logical access control to all network ports | PacketFence device inventory · 802.1X policy export |
| BSI NET.1.2 | All network access logged, unknown devices quarantined automatically | PacketFence quarantine log · VLAN assignment history |
| GDPR Art. 32(1)(b) | NAC ensures only authorised endpoints can access personal data | FreeRADIUS auth log · denied access event log |
| DORA Art. 9(4)(a) | Access management preventing rogue device access to ICT systems | PacketFence violation log · remediation audit |
| CRA Annex I §2(e) | Devices require authentication before network access — secure by default | EAP-TLS policy config · certificate issuance log |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
FreeRADIUS — standalone install
FreeRADIUS 3.2.x. 802.1X EAP-PEAP and EAP-TLS. Integration with one 802.1X-capable switch. Three client types tested: domain laptop, non-domain laptop, printer (MAB). Accounting log to Atlas Observe.
€ 990
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteCaptive portal — PacketFence
PacketFence 13.x guest captive portal. Self-registration with email verification or sponsor approval. Custom branding. GDPR consent with timestamp logging. VLAN 30 assignment. Bandwidth limits per device.
€ 1,290
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteRADIUS + Wi-Fi 802.1X
FreeRADIUS for WPA3-Enterprise. EAP-TLS using certificates from step-ca PKI. Integrated with the MikroTik CAPsMAN controller (or any 802.1X-capable AP controller). Dynamic VLAN assignment per group. Tested with 3 device types.
€ 890
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteFull integration
Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.
5–50 users · 1 site · 1 month on-site
from € 14,400
Net, excl. VAT · fixed price scoped by audit
50–500 users · multi-site · 3 months on-site
from € 42,000
Net, excl. VAT · fixed price scoped by audit
500+ users · multi-site · 6 months on-site
from € 90,000
Net, excl. VAT · fixed price scoped by audit
Cisco ISE is capable but costly — per-endpoint licences, dedicated appliances and an annual subscription. PacketFence delivers 802.1X network access control (NAC) as an open-source alternative: MAC authentication, guest portals, device profiling and automatic isolation — with no per-port or per-endpoint licence fees.
Self-hosted on your hardware and integrated with FreeRADIUS and your switching. We plan the rollout, migrate your access policies and hand over the documented configuration.
All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.
Request audit engagementCopyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz