Why this exists

The problem Atlas Access solves

Without Atlas Access

A visitor plugs their laptop into a meeting room port and gets full LAN access. An employee brings a personal device with active malware — it joins the Wi-Fi and starts scanning. An IoT camera on the same VLAN as the file server gets compromised. None of these events generate an alert. The network does not know what is connected to it.

With Atlas Access

Every device must authenticate. A domain laptop presents an EAP-TLS certificate and gets VLAN 20. A printer uses MAC Authentication Bypass and lands in VLAN 40. A visitor's phone gets a captive portal and VLAN 30 (guest) with no internal access. An unknown device goes to VLAN 99 (quarantine). PacketFence profiles every device — OS, type, vendor — and logs every connection event.

Architecture

How it works

Atlas Access — 802.1X authentication flow with dynamic VLAN assignment
Architecture overview — Atlas Access component relationships

Regulatory compliance

What Atlas Access satisfies

Regulation / ControlRequirementAudit evidence
NIS2 Art. 21(2)(i)Only authenticated and authorised devices connect to the networkFreeRADIUS accounting log · VLAN assignment audit
BSI INF.1.1Physical and logical access control to all network portsPacketFence device inventory · 802.1X policy export
BSI NET.1.2All network access logged, unknown devices quarantined automaticallyPacketFence quarantine log · VLAN assignment history
GDPR Art. 32(1)(b)NAC ensures only authorised endpoints can access personal dataFreeRADIUS auth log · denied access event log
DORA Art. 9(4)(a)Access management preventing rogue device access to ICT systemsPacketFence violation log · remediation audit
CRA Annex I §2(e)Devices require authentication before network access — secure by defaultEAP-TLS policy config · certificate issuance log

Standalone installation

Install one component — no full integration required

Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.

FreeRADIUS — standalone install

FreeRADIUS 3.2.x. 802.1X EAP-PEAP and EAP-TLS. Integration with one 802.1X-capable switch. Three client types tested: domain laptop, non-domain laptop, printer (MAB). Accounting log to Atlas Observe.

  • FreeRADIUS 3.2.x install
  • EAP-PEAP + EAP-TLS config
  • 1 switch integration
  • 3 client type tests
  • Accounting log configured
  • 5-day post-install support

€ 560

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

Captive portal — PacketFence

PacketFence 13.x guest captive portal. Self-registration with email verification or sponsor approval. Custom branding. GDPR consent with timestamp logging. VLAN 30 assignment. Bandwidth limits per device.

  • PacketFence captive portal
  • Self-registration + sponsor flow
  • Custom branding
  • GDPR consent + timestamp log
  • VLAN 30 assignment
  • 5-day post-install support

€ 740

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

RADIUS + Wi-Fi 802.1X

FreeRADIUS for WPA3-Enterprise. EAP-TLS using certificates from step-ca PKI. Integrated with the MikroTik CAPsMAN controller (or any 802.1X-capable AP controller). Dynamic VLAN assignment per group. Tested with 3 device types.

  • WPA3-Enterprise config
  • EAP-TLS with step-ca PKI certs
  • AP controller integration
  • Dynamic VLAN per group
  • 3 device type tests
  • 5-day post-install support

€ 430

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote
Note: Standalone components do not include cross-product integration. To have it fitted into your existing environment, add the Integration package from the consulting section below.

Ready-made boxes

Foundation · Plus · Enterprise — fixed price, plug & play

Three boxes, three fixed prices. Each one ships pre-configured and pre-hardened: you power it up, work through a short quick-start guide, and it runs. No audit, no project phase, no consulting engagement required. Need it fitted into an existing environment instead? See the consulting packages below.

Foundation

5–50 users · 1 site · single server

Pre-configured · quick-start guide included

€ 1,760

Net, excl. VAT · one-off fixed price · hardware not included

  • FreeRADIUS single node
  • EAP-PEAP for domain devices
  • MAB for IoT/printers
  • Guest captive portal
  • Dynamic VLAN assignment
Order this box
Enterprise

500+ users · multi-site · cluster-ready

Pre-configured · quick-start guide included

€ 3,040

Net, excl. VAT · one-off fixed price · hardware not included

  • FreeRADIUS cluster multi-site
  • Full PacketFence NAC
  • BYOD self-service portal
  • IoT segmentation automation
  • Compliance posture checking
Order this box

Consulting services

Need more than the box?

The boxes are built to run on their own. When you want one fitted into what you already have, add a fixed-price package — no open-ended day rates.

Installation & handover

We install the box in your environment, connect it to your network and DNS, and hand it over configured and documented. Remote, or on-site within 100 km of Hamburg.

  • Installed and connected on your side
  • Admin walkthrough session
  • Configuration handed over documented

€ 890

Net, excl. VAT · fixed price

Request this package

Integration into your environment

Connecting the box to what you already run — Active Directory, an existing DNS or firewall, your monitoring or SIEM — including migration of existing data.

  • Integration with 2 existing systems
  • Data / config migration
  • Rollback plan and test protocol

€ 1,890

Net, excl. VAT · fixed price

Request this package

Compliance mapping & audit support

We map the delivered configuration to NIS2, BSI IT-Grundschutz or DORA controls and hand over the evidence package your auditor will ask for.

  • Control mapping per regulation
  • Evidence package for the auditor
  • Gap list with remediation steps

€ 1,490

Net, excl. VAT · fixed price

Request this package
Larger scope? Multi-site rollouts, custom engineering and ongoing operations are quoted individually. Tell us what you need and we come back with a fixed price.

A Cisco ISE alternative: open-source NAC with PacketFence

Cisco ISE is capable but costly — per-endpoint licences, dedicated appliances and an annual subscription. PacketFence delivers 802.1X network access control (NAC) as an open-source alternative: MAC authentication, guest portals, device profiling and automatic isolation — with no per-port or per-endpoint licence fees.

Self-hosted on your hardware and integrated with FreeRADIUS and your switching. We plan the rollout, migrate your access policies and hand over the documented configuration.