Features

Cloud NAC: network access control delivered as a cloud service

Cloudi-Fi runs 802.1X authentication and policy enforcement from the cloud. Your switches, access points and controllers stay in place as enforcement points, with no NAC appliance or per-site RADIUS server to build and maintain.

Cloud NAC

What is cloud NAC?

The same 802.1X, RADIUS and EAP-TLS protocols, with the policy decision moved to the cloud

Cloud NAC (Cloud Network Access Control) is a network access control service where the RADIUS policy engine runs in the cloud instead of on a local appliance. Your switches and access points forward authentication requests to the service, which checks the identity and returns the access policy to apply.

The protocols stay the same: 802.1X, RADIUS and EAP-TLS. The decision moves to the cloud, and one policy set covers every site, wired and Wi-Fi.

Cloud NAC architecture: the switch or access point stays the enforcement point while the policy decision moves to a cloud RADIUS engine connected to your identity sources.

How cloud NAC works

This is the standard 802.1X exchange, and it completes in a few hundred milliseconds.

  1. A user or endpoint plugs into a switch port or associates with an SSID.
  2. The switch, access point or controller acts as the authenticator and opens a RADIUS request to the cloud service.
  3. The cloud engine checks the credential against a trusted source: Microsoft Entra ID, LDAP or Active Directory, a client certificate, or an approved MAC address.
  4. The engine answers with RADIUS attributes describing the access level, such as a VLAN identifier, a role name or an ACL.
  5. The switch or controller applies those attributes to the port or the wireless session.
  6. The service records the result and keeps the session data available for audit across all sites.
The 802.1X exchange is unchanged. The switch remains the authenticator and the cloud service answers the RADIUS request with the attributes to apply.

Cloud NAC vs on-premises NAC appliances

Traditional NAC puts a policy server, and usually a high-availability pair, in every data centre or large site. That model works, but the operational load grows with the number of locations.

AreaOn-premises NAC applianceCloud NAC
InfrastructurePhysical or virtual appliance per site or regionNo local server to deploy
ResilienceHA pair and disaster recovery node to size and testHandled by the service
UpgradesFirmware and patch cycles owned by your teamManaged centrally, no maintenance window per site
Policy managementPolicy sets replicated per deployment, prone to driftOne policy set applied everywhere
Adding a siteNew node to install, license and integratePoint the network device at the cloud service
ScalingSized on peak authentication loadScales with the service
Adding a site to an appliance-based NAC means another node to install and license. With cloud NAC you point the local equipment at the service already running.

Authentication methods

Endpoints vary in what credentials they can present, so the service accepts several methods at different assurance levels.

Certificate-based authentication (EAP-TLS)

EAP-TLS is the recommended method for managed users and devices. It removes shared passwords and uses the PKI you already run. Your MDM distributes the certificates, including Microsoft Intune.

802.1X with directory credentials

Authenticate corporate identities against Microsoft Entra ID, LDAP or Active Directory, and drive access decisions from group membership you already maintain. See our 802.1X cloud-ready feature for the full authentication detail.

MAC authentication bypass (MAB)

MAC authentication bypass is a controlled fallback for printers, sensors and other endpoints that cannot run a supplicant. The service identifies these devices by MAC address and places them in a restricted segment instead of granting them default access.

Segmentation and least-privilege access

Authentication identifies the device. The attributes returned with the acceptance decide what it can reach on the network. Cloudi-Fi Cloud NAC supports the ones your equipment already understands:

  • Dynamic VLAN assignment based on user identity or device type
  • Role-based access for employees, contractors and departments
  • Isolation or quarantine for unknown and unmanaged endpoints
Identity or deviceMethodAccess returned
Employee, Finance groupEAP-TLSVLAN 40, full corporate access
Contractor802.1X, directoryVLAN 55 with restrictive ACL
IoT sensorMABVLAN 90, isolated
Unknown deviceNo valid credentialQuarantine or no access

Works with your existing network

Cloudi-Fi Cloud NAC is a RADIUS service, so any device that supports 802.1X and RADIUS can act as the enforcement point. There is no hardware to replace: Cisco Meraki, Cisco Catalyst 9800 WLC, Aruba, Fortinet and other 802.1X equipment are all supported.

Browse the deployment guides for vendor-specific configuration.

Corporate access and guest access on one platform

Cloudi-Fi Cloud NAC covers employees and managed devices. Visitors, contractors and personal devices go through Cloudi-Fi's cloud captive portal for self-registration and sponsored access, administered from the same console with one set of logs.

See Cloudi-Fi Guest Access.

Where Cloudi-Fi Cloud NAC fits best

  • Multi-site organisations with many small locations where a local NAC node is disproportionate
  • Networks with a large IoT footprint, where unmanaged devices currently connect through open ports
  • SASE and Zero Trust programs that extend verification down to the port and the SSID
  • Post-merger environments where two directories and two network estates need one access policy
  • Appliance end-of-life, as an alternative to buying the next generation of hardware
Cloudi-Fi white logo

Start with Cloudi-Fi Cloud NAC

Platform

Integrated with the best technologies on the market

Infrastructure agnostic and plug-and-play deployment: rapidly roll-out Cloudi-Fi across global sites with any infrastructure provider

Cloud native, borderless, scalable and global!

Unlocking Universal Zero Trust Network Access on all continents

World map
90+
Countries
500M+
Users and devices
100k+
Secured sites
Platform

One platform for all industries

Cloudi-Fi empowers organizations with a scalable, cloud-based solution to secure users, devices, and data. Designed to integrate seamlessly into existing infrastructures.