Atlas Access
Network Access Control
Nothing joins the network without proving what it is — 802.1X access control you run and own end to end, no vendor appliance and no per-seat licence.
Why this exists
Without Atlas Access
A visitor plugs their laptop into a meeting room port and gets full LAN access. An employee brings a personal device with active malware — it joins the Wi-Fi and starts scanning. An IoT camera on the same VLAN as the file server gets compromised. None of these events generate an alert. The network does not know what is connected to it.
With Atlas Access
Every device must authenticate. A domain laptop presents an EAP-TLS certificate and gets VLAN 20. A printer uses MAC Authentication Bypass and lands in VLAN 40. A visitor's phone gets a captive portal and VLAN 30 (guest) with no internal access. An unknown device goes to VLAN 99 (quarantine). PacketFence profiles every device — OS, type, vendor — and logs every connection event.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(i) | Only authenticated and authorised devices connect to the network | FreeRADIUS accounting log · VLAN assignment audit |
| BSI INF.1.1 | Physical and logical access control to all network ports | PacketFence device inventory · 802.1X policy export |
| BSI NET.1.2 | All network access logged, unknown devices quarantined automatically | PacketFence quarantine log · VLAN assignment history |
| GDPR Art. 32(1)(b) | NAC ensures only authorised endpoints can access personal data | FreeRADIUS auth log · denied access event log |
| DORA Art. 9(4)(a) | Access management preventing rogue device access to ICT systems | PacketFence violation log · remediation audit |
| CRA Annex I §2(e) | Devices require authentication before network access — secure by default | EAP-TLS policy config · certificate issuance log |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
FreeRADIUS — standalone install
FreeRADIUS 3.2.x. 802.1X EAP-PEAP and EAP-TLS. Integration with one 802.1X-capable switch. Three client types tested: domain laptop, non-domain laptop, printer (MAB). Accounting log to Atlas Observe.
€ 560
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteCaptive portal — PacketFence
PacketFence 13.x guest captive portal. Self-registration with email verification or sponsor approval. Custom branding. GDPR consent with timestamp logging. VLAN 30 assignment. Bandwidth limits per device.
€ 740
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteRADIUS + Wi-Fi 802.1X
FreeRADIUS for WPA3-Enterprise. EAP-TLS using certificates from step-ca PKI. Integrated with the MikroTik CAPsMAN controller (or any 802.1X-capable AP controller). Dynamic VLAN assignment per group. Tested with 3 device types.
€ 430
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteReady-made boxes
Three boxes, three fixed prices. Each one ships pre-configured and pre-hardened: you power it up, work through a short quick-start guide, and it runs. No audit, no project phase, no consulting engagement required. Need it fitted into an existing environment instead? See the consulting packages below.
5–50 users · 1 site · single server
€ 1,760
Net, excl. VAT · one-off fixed price · hardware not included
50–500 users · 1–5 sites · HA-ready
€ 2,380
Net, excl. VAT · one-off fixed price · hardware not included
500+ users · multi-site · cluster-ready
€ 3,040
Net, excl. VAT · one-off fixed price · hardware not included
Consulting services
The boxes are built to run on their own. When you want one fitted into what you already have, add a fixed-price package — no open-ended day rates.
Installation & handover
We install the box in your environment, connect it to your network and DNS, and hand it over configured and documented. Remote, or on-site within 100 km of Hamburg.
€ 890
Net, excl. VAT · fixed price
Request this packageIntegration into your environment
Connecting the box to what you already run — Active Directory, an existing DNS or firewall, your monitoring or SIEM — including migration of existing data.
€ 1,890
Net, excl. VAT · fixed price
Request this packageCompliance mapping & audit support
We map the delivered configuration to NIS2, BSI IT-Grundschutz or DORA controls and hand over the evidence package your auditor will ask for.
€ 1,490
Net, excl. VAT · fixed price
Request this packageCisco ISE is capable but costly — per-endpoint licences, dedicated appliances and an annual subscription. PacketFence delivers 802.1X network access control (NAC) as an open-source alternative: MAC authentication, guest portals, device profiling and automatic isolation — with no per-port or per-endpoint licence fees.
Self-hosted on your hardware and integrated with FreeRADIUS and your switching. We plan the rollout, migrate your access policies and hand over the documented configuration.
Copyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz