License & Deployment Mix: 13 tools – 3 OSS, 4 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)
What Is Network Access Control?
Network Access Control (NAC) is a security framework that enforces policy on devices seeking to access network resources. NAC systems authenticate users and devices, assess endpoint compliance (posture), and dynamically assign network access levels – ensuring that only authorized, healthy devices reach protected resources.
NAC encompasses several core technologies and concepts:
- 802.1X authentication – IEEE standard for port-based network access control; uses EAP (Extensible Authentication Protocol) over wired or wireless connections to authenticate before granting network access
- RADIUS – Remote Authentication Dial-In User Service; the backend authentication server that validates credentials and returns authorization attributes (VLAN, ACL, etc.)
- Device profiling – identifying and classifying devices on the network by MAC address, DHCP fingerprint, HTTP user-agent, SNMP data, and other attributes
- Guest access – captive portal workflows that allow visitors temporary, restricted network access with sponsor approval or self-registration
- Posture assessment – checking endpoint health (OS patches, antivirus status, disk encryption, firewall state) before granting full access
- MAC Authentication Bypass (MAB) – fallback authentication for devices that cannot perform 802.1X (printers, IoT, cameras); authenticates by MAC address
- VLAN assignment – dynamically placing devices into the correct VLAN based on identity, device type, and compliance status
- Network segmentation – micro-segmentation or macro-segmentation to isolate device groups and limit lateral movement
- BYOD – Bring Your Own Device onboarding workflows that provision certificates, install agents, or configure supplicants on personal devices
- Compliance enforcement – quarantining or remediating non-compliant devices until they meet security policy requirements
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
Feature Matrix
| Feature | PacketFence | FreeRADIUS | OpenNAC |
|---|---|---|---|
| 802.1X | Yes | Yes | Yes |
| Device profiling | Yes | No | Basic |
| Guest portal | Yes | No | Yes |
| Posture assessment | Yes | No | Basic* |
| VLAN assignment | Yes | Yes | Yes |
| BYOD onboarding | Yes | No | Limited |
| Built-in PKI | Yes | No | No |
| Management UI | Yes | No | Yes |
* = Enterprise Edition only
| Feature | Portnox | Foxpass | SecureW2 |
|---|---|---|---|
| 802.1X | Yes | Yes | Yes |
| Device profiling | Yes | No | No |
| Guest portal | Yes | No | No |
| Posture assessment | Yes | No | MDM* |
| VLAN assignment | Yes | Basic | Yes |
| BYOD onboarding | Yes | Yes | Yes |
| Built-in PKI | Yes | Yes | Yes |
| Management UI | Yes | Yes | Yes |
* = via MDM integration only
| Feature | Cisco ISE | ClearPass | Mist NAC |
|---|---|---|---|
| 802.1X | Yes | Yes | Yes |
| Device profiling | Yes | Yes | Basic |
| Guest portal | Yes | Yes | Yes |
| Posture assessment | Yes | Yes | Limited |
| VLAN assignment | Yes | Yes | Yes |
| BYOD onboarding | Yes | Yes | Limited |
| Built-in PKI | Yes | Yes | No |
| Management UI | Yes | Yes | Yes |
| Feature | Forescout | FortiNAC | ExtremeCtl | NPS |
|---|---|---|---|---|
| 802.1X | Proxy | Yes | Yes | Yes |
| Device profiling | Yes | Yes | Yes | No |
| Guest portal | Basic | Yes | Yes | No |
| Posture assessment | Yes | Yes | Yes | No* |
| VLAN assignment | Yes | Yes | Yes | Yes |
| BYOD onboarding | No | Basic | Basic | No |
| Built-in PKI | No | Basic | No | No** |
| Management UI | Yes | Yes | Yes | MMC |
* = NAP deprecated in Windows Server 2016 ** = uses Microsoft AD CS (separate role)
Deployment Comparison
| Tool | Type | Platform | Cloud | On-Prem |
|---|---|---|---|---|
| PacketFence | On-prem | Linux | No | Yes |
| FreeRADIUS | On-prem | Linux/BSD | No | Yes |
| OpenNAC | On-prem | Linux | No | Yes |
| Portnox Cloud | SaaS | Browser | Yes | No |
| Foxpass | SaaS | Browser | Yes | No |
| SecureW2 | SaaS | Browser | Yes | No |
| Cisco ISE | On-prem | VM/Appliance | Ltd* | Yes |
| Aruba ClearPass | On-prem | VM/Appliance | No | Yes |
| Juniper Mist | SaaS | Browser | Yes | No |
| Forescout | Hybrid | VM/Appliance | Hybrid | Yes |
| FortiNAC | On-prem | VM/Appliance | No | Yes |
| ExtremeControl | Hybrid | VM | Hybrid | Yes |
| Microsoft NPS | On-prem | Windows | No | Yes |
* = ISE in the Cloud is limited availability
Licensing Comparison
| Tool | License | Type | Cost |
|---|---|---|---|
| PacketFence | GPL-2.0 | Open source | Free |
| FreeRADIUS | GPL-2.0 | Open source | Free |
| OpenNAC | GPL-2.0 / Prop | Open core | Free / Paid |
| Portnox Cloud | Proprietary | SaaS | Per-device |
| Foxpass | Proprietary | SaaS | ~$3/user/mo |
| SecureW2 | Proprietary | SaaS | Per-device |
| Cisco ISE | Proprietary | Subscription | ~$4-8/ep/yr |
| Aruba ClearPass | Proprietary | Subscription | Per-endpoint |
| Juniper Mist | Proprietary | Subscription | Included* |
| Forescout | Proprietary | Subscription | Per-device |
| FortiNAC | Proprietary | Sub/Perpetual | Per-device |
| ExtremeControl | Proprietary | Subscription | Per-device |
| Microsoft NPS | Included | Win Server | Free** |
* = included with Mist subscription ** = included with Windows Server license
SSO / OIDC Comparison
OIDC is the preferred SSO protocol; the notes below assume Authentik as the IdP.
| Tool | OIDC | SAML | LDAP | AD | Authentik Notes |
|---|---|---|---|---|---|
| PacketFence | Portal | No | Yes | Yes | LDAP outpost; OIDC portal |
| FreeRADIUS | N/A | N/A | Yes | Yes | LDAP outpost |
| OpenNAC | No | No | Yes | Yes | LDAP outpost |
| Portnox | Admin | Admin | Sync | Sync | OIDC/SAML admin |
| Foxpass | No | Admin | Yes | Sync | SAML admin |
| SecureW2 | Portal | Admin | Yes | Yes | OIDC/SAML portals |
| Cisco ISE | No | Admin | Yes | Yes | SAML admin; LDAP outpost |
| ClearPass | Portal | Admin | Yes | Yes | SAML admin; OIDC portal |
| Mist NAC | Admin | Admin | Ext | Via AAD | OIDC/SAML dashboard |
| Forescout | No | Admin | Yes | Yes | SAML admin |
| FortiNAC | No | Admin* | Yes | Yes | SAML admin (NAC-F) |
| ExtremeCtl | No | Admin | Yes | Yes | SAML via XIQ |
| NPS | N/A | N/A | N/A | Yes | AD only; no Authentik |
N/A = not applicable (RADIUS server, not web-based) * = FortiNAC-F version
Best SSO support: Portnox Cloud and Juniper Mist offer OIDC SSO for admin consoles. ClearPass and SecureW2 support OIDC for guest/onboarding portals. All commercial NAC platforms support SAML for admin console SSO.
802.1X authentication: all tools use LDAP/AD for user authentication in 802.1X flows. Authentik LDAP outpost enables integration with tools that support LDAP backends.
Device Profiling Comparison
| Tool | Methods | IoT/OT | Accuracy |
|---|---|---|---|
| PacketFence | Fingerbank (DHCP, HTTP, TCP) | Good | Good |
| FreeRADIUS | None | N/A | N/A |
| OpenNAC | DHCP, SNMP | Basic | Basic |
| Portnox | RADIUS, DHCP, agentless | Good | Good |
| Foxpass | None | N/A | N/A |
| SecureW2 | Cert attributes, MDM | Limited | N/A |
| Cisco ISE | 12+ methods, AI/ML | Excellent | Excellent |
| ClearPass | 10+ methods, OnConnect | Excellent | Excellent |
| Mist NAC | Mist AI | Basic | Moderate |
| Forescout | 20+ methods, agentless | Best | Excellent |
| FortiNAC | 21+ techniques | Good | Good |
| ExtremeCtl | DHCP, SNMP, LLDP | Moderate | Moderate |
| NPS | None | N/A | N/A |
Best profiling: Forescout has the deepest agentless profiling, especially for IoT/OT. Cisco ISE and ClearPass are the leaders for traditional NAC profiling. PacketFence’s Fingerbank is the best open-source option.
Scale & HA Comparison
| Tool | Max Endpoints | HA | Clustering |
|---|---|---|---|
| PacketFence | 100K+ | A/P | Galera |
| FreeRADIUS | Unlimited* | External | LB |
| OpenNAC | Unknown | Ent. only | Unknown |
| Portnox | Unlimited | Cloud | Cloud |
| Foxpass | Unlimited | Cloud | Cloud |
| SecureW2 | Unlimited | Cloud | Cloud |
| Cisco ISE | 2M | A/S | 50 nodes |
| ClearPass | 500K | A/S | 25 nodes |
| Mist NAC | Unlimited | Cloud | Cloud |
| Forescout | Millions | A/P | Distributed |
| FortiNAC | 2M | A/P | Replication |
| ExtremeCtl | Enterprise | A/P | Yes |
| NPS | Limited** | Manual | NLB |
* = limited by hardware only ** = practical limit ~50K; no native HA
API Comparison
| Tool | REST API | Auth | Docs |
|---|---|---|---|
| PacketFence | Yes | Token | Swagger |
| FreeRADIUS | No | N/A | N/A |
| OpenNAC | Ent. only | Unknown | Sparse |
| Portnox | Yes | API key | Customer |
| Foxpass | Yes | Token | Public |
| SecureW2 | Yes | API key | Customer |
| Cisco ISE | Yes (ERS+Open) | Basic/OAuth | Public |
| ClearPass | Yes | OAuth2 | Public |
| Mist NAC | Yes | Token | Public |
| Forescout | Yes | Credentials | Customer |
| FortiNAC | Yes (NAC-F) | API key | Fortinet |
| ExtremeCtl | Yes (XIQ) | OAuth2 | Public |
| NPS | No | N/A | N/A |
Best API: Cisco ISE (ERS + Open API + pxGrid) and ClearPass (OAuth2 REST) have the most comprehensive APIs. PacketFence has the best open-source API. Cloud platforms (Portnox, Mist) offer modern REST APIs.
Vendor Lock-in Assessment
| Tool | Lock-in | Notes |
|---|---|---|
| PacketFence | None | OSS; multi-vendor |
| FreeRADIUS | None | OSS; universal |
| OpenNAC | Low | OSS core |
| Portnox | Moderate | SaaS; standard RADIUS |
| Foxpass | Moderate | SaaS; standard RADIUS |
| SecureW2 | Moderate | SaaS; certs portable |
| Cisco ISE | High | TrustSec/SGT Cisco-only |
| ClearPass | Moderate | Multi-vendor RADIUS |
| Mist NAC | High | Requires Juniper Mist |
| Forescout | Moderate | Multi-vendor; agentless |
| FortiNAC | High | Best with Fortinet |
| ExtremeCtl | High | Best with Extreme |
| NPS | High | Requires Active Directory |
Suitability Summary
Open Source Recommendations
For cost-conscious deployments:
- PacketFence – best full-featured open-source NAC; recommended for internal networks
- FreeRADIUS – best standalone RADIUS server; use when full NAC is not needed
- OpenNAC – not recommended due to uncertain project health
Cloud NAC Recommendations
For organizations wanting cloud-managed NAC:
- Portnox Cloud – best cloud-native NAC with full feature set
- SecureW2 – best cloud PKI for certificate-based authentication
- Foxpass – best for simple Wi-Fi 802.1X (not full NAC)
- Juniper Mist – best if already using Juniper Mist networking
Enterprise Recommendations
For large enterprise customers:
- Aruba ClearPass – best multi-vendor enterprise NAC; recommended over ISE for non-Cisco environments
- Cisco ISE – most comprehensive NAC but high cost/complexity; best for Cisco shops
- Forescout – best for IoT/OT visibility and agentless environments
- FortiNAC – most affordable enterprise NAC; best for Fortinet environments
Not Recommended
- ExtremeControl – only for Extreme Networks environments
- Microsoft NPS – RADIUS only; no NAC features; use when nothing else is available
- OpenNAC – uncertain project viability
MSP Integration Notes
- Open source (PacketFence, FreeRADIUS): full MSP engagement (server, config, monitoring)
- Cloud NAC (Portnox, SecureW2, Foxpass): limited MSP role; network and endpoint management
- Enterprise NAC (ISE, ClearPass, Forescout): specialized expertise required; significant MSP engagement
- SSO: Authentik LDAP outpost enables NAC integration for 802.1X user authentication
- Monitoring: all deployments benefit from monitoring stack monitoring (RADIUS metrics, authentication logs)
Tools
13 tools.
Aruba ClearPass
Aruba ClearPass Policy Manager (CPPM) is a leading enterprise NAC platform and Cisco ISE’s primary competitor.
License: Proprietary (proprietary) · Kind: web · Deploy: appliance · SSO: OIDC, SAML
Cisco ISE
Cisco Identity Services Engine (ISE) is the dominant enterprise NAC platform. It provides comprehensive network access control including 802.1X authentication, device profiling, guest access, posture assessment, BYOD onboarding, and TrustSe…
License: Proprietary (proprietary) · Kind: web · Deploy: appliance · SSO: SAML
Extreme Networks ExtremeControl
ExtremeControl (formerly Extreme Networks NetSight NAC) is the NAC component of Extreme Networks’ management platform.
License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: SAML
Forescout eyeSight
Forescout (formerly ForeScout) is an enterprise network security platform focused on agentless device visibility, classification, and control.
License: Proprietary (proprietary) · Kind: web · Deploy: appliance · SSO: SAML
FortiNAC
FortiNAC is Fortinet’s network access control solution, providing device visibility, 802.1X authentication, agentless profiling, guest access, posture assessment, and automated network segmentation.
License: Proprietary (proprietary) · Kind: web · Deploy: appliance · SSO: SAML
Foxpass
Foxpass is a cloud-hosted RADIUS and LDAP service focused on Wi-Fi authentication and network access control.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: SAML
FreeRADIUS
FreeRADIUS is the most widely deployed RADIUS server in the world, handling authentication for a significant share of global internet users.
License: GPL-2.0-only (OSS) · Kind: service · Deploy: docker, native, package · SSO: none
Juniper Mist Access Assurance
Juniper Mist Access Assurance is a cloud-native NAC service built into the Juniper Mist cloud platform.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Microsoft NPS
Microsoft Network Policy Server (NPS) is the RADIUS server included with Windows Server. It provides 802.1X authentication, network policy enforcement, and RADIUS proxy functionality as a built-in Windows Server role.
License: Proprietary (proprietary) · Kind: service · Deploy: native · SSO: none
OpenNAC
OpenNAC Enterprise is a Network Access Control platform developed by OpenCloud Factory (now Whitestack). It provides 802.1X authentication, device profiling, VLAN management, and compliance enforcement with a web-based management console.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: docker, native · SSO: none
PacketFence
PacketFence is the leading open-source Network Access Control solution. Developed by Inverse Inc., it provides a fully featured NAC platform including 802.1X authentication, device profiling, VLAN management, captive portal, guest access, B…
License: GPL-2.0-only (OSS) · Kind: web · Deploy: docker, native, appliance · SSO: OIDC
Portnox Cloud
Portnox Cloud is a cloud-native NAC platform that delivers 802.1X authentication, device profiling, risk assessment, and access control as a service.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
SecureW2
SecureW2 is a cloud platform specializing in certificate-based network authentication. Its core offering is a cloud PKI with managed RADIUS (Cloud RADIUS) that enables passwordless 802.1X authentication via EAP-TLS certificates.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML