Glossary · OT security engineering
Network access control (NAC)
Also known as: NAC, Port-based network access control
German: Netzwerkzugangskontrolle (NAC)
In network security, network access control (NAC) is the set of mechanisms that authenticate devices, and optionally users, before they are allowed onto a network, and that assign or restrict their network access according to policy. Port-based NAC is standardized in IEEE 802.1X.
- Security engineering
- OT security
In one sentence
Network access control (NAC) authenticates devices before they join a network and assigns or restricts their access according to policy.
Example
When a technician plugs an unknown laptop into a cell switch, NAC places it in a quarantine VLAN with no access to the controllers until it is authorized.
How it applies
- Engineering: With IEEE 802.1X, a switch port only opens after the connected device authenticates against a server, for example with a certificate. Devices that do not support 802.1X, common in OT, can be admitted by MAC address, which is weaker because addresses can be spoofed.
- Operation: NAC keeps unknown devices out of production zones and helps maintain an accurate Asset inventory. Policies must avoid blocking legitimate replacement devices during urgent repairs.
- Maintenance: Replacing a field device can require registering its identity with NAC. This step must be in the replacement procedure, or the new device will not communicate.
- Documentation: Product documentation should state whether a device supports 802.1X and how credentials are installed. Maintenance instructions for device replacement should include the NAC registration step and whom to contact.
NAC vs. firewall
NAC decides whether a device may connect to the network at all. A Firewall controls what connected devices may communicate across segments.