Why this exists

The problem Atlas Access solves

Without Atlas Access

A visitor plugs their laptop into a meeting room port and gets full LAN access. An employee brings a personal device with active malware — it joins the Wi-Fi and starts scanning. An IoT camera on the same VLAN as the file server gets compromised. None of these events generate an alert. The network does not know what is connected to it.

With Atlas Access

Every device must authenticate. A domain laptop presents an EAP-TLS certificate and gets VLAN 20. A printer uses MAC Authentication Bypass and lands in VLAN 40. A visitor's phone gets a captive portal and VLAN 30 (guest) with no internal access. An unknown device goes to VLAN 99 (quarantine). PacketFence profiles every device — OS, type, vendor — and logs every connection event.

Architecture

How it works

Atlas Access — 802.1X authentication flow with dynamic VLAN assignment
Architecture overview — Atlas Access component relationships

Regulatory compliance

What Atlas Access satisfies

Regulation / ControlRequirementAudit evidence
NIS2 Art. 21(2)(i)Only authenticated and authorised devices connect to the networkFreeRADIUS accounting log · VLAN assignment audit
BSI INF.1.1Physical and logical access control to all network portsPacketFence device inventory · 802.1X policy export
BSI NET.1.2All network access logged, unknown devices quarantined automaticallyPacketFence quarantine log · VLAN assignment history
GDPR Art. 32(1)(b)NAC ensures only authorised endpoints can access personal dataFreeRADIUS auth log · denied access event log
DORA Art. 9(4)(a)Access management preventing rogue device access to ICT systemsPacketFence violation log · remediation audit
CRA Annex I §2(e)Devices require authentication before network access — secure by defaultEAP-TLS policy config · certificate issuance log

Standalone installation

Install one component — no full integration required

Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.

FreeRADIUS — standalone install

FreeRADIUS 3.2.x. 802.1X EAP-PEAP and EAP-TLS. Integration with one 802.1X-capable switch. Three client types tested: domain laptop, non-domain laptop, printer (MAB). Accounting log to Atlas Observe.

  • FreeRADIUS 3.2.x install
  • EAP-PEAP + EAP-TLS config
  • 1 switch integration
  • 3 client type tests
  • Accounting log configured
  • 5-day post-install support

€ 990

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

Captive portal — PacketFence

PacketFence 13.x guest captive portal. Self-registration with email verification or sponsor approval. Custom branding. GDPR consent with timestamp logging. VLAN 30 assignment. Bandwidth limits per device.

  • PacketFence captive portal
  • Self-registration + sponsor flow
  • Custom branding
  • GDPR consent + timestamp log
  • VLAN 30 assignment
  • 5-day post-install support

€ 1,290

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

RADIUS + Wi-Fi 802.1X

FreeRADIUS for WPA3-Enterprise. EAP-TLS using certificates from step-ca PKI. Integrated with the MikroTik CAPsMAN controller (or any 802.1X-capable AP controller). Dynamic VLAN assignment per group. Tested with 3 device types.

  • WPA3-Enterprise config
  • EAP-TLS with step-ca PKI certs
  • AP controller integration
  • Dynamic VLAN per group
  • 3 device type tests
  • 5-day post-install support

€ 890

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote
Note: Standalone components do not include cross-product integration. Full Atlas Access integration — connecting it into your existing environment — starts with an audit engagement.

Full integration

Foundation · Plus · Enterprise

Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.

Foundation

5–50 users · 1 site · 1 month on-site

1 month on-site

from € 14,400

Net, excl. VAT · fixed price scoped by audit

  • FreeRADIUS single node
  • EAP-PEAP for domain devices
  • MAB for IoT/printers
  • Guest captive portal
  • Dynamic VLAN assignment
  • Basic device profiling
Request audit to start
Enterprise

500+ users · multi-site · 6 months on-site

6 months on-site

from € 90,000

Net, excl. VAT · fixed price scoped by audit

  • FreeRADIUS cluster multi-site
  • Full PacketFence NAC
  • BYOD self-service portal
  • IoT segmentation automation
  • Compliance posture checking
  • ISO 27001 access control evidence
Request audit to start

A Cisco ISE alternative: open-source NAC with PacketFence

Cisco ISE is capable but costly — per-endpoint licences, dedicated appliances and an annual subscription. PacketFence delivers 802.1X network access control (NAC) as an open-source alternative: MAC authentication, guest portals, device profiling and automatic isolation — with no per-port or per-endpoint licence fees.

Self-hosted on your hardware and integrated with FreeRADIUS and your switching. We plan the rollout, migrate your access policies and hand over the documented configuration.

Start with an audit

All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.

Request audit engagement