MetaDefender NAC by OPSWAT is a network access control solution that provides device visibility, identity-based authentication, and endpoint compliance enforcement within a zero-trust security framework. It discovers and categorizes managed, unmanaged, BYOD, and IoT devices using both agent-based clients and agentless techniques such as deep device fingerprinting and DHCP analysis. The system performs pre-connection authentication checks via 802.1x and supports multiple authentication protocols, including RADIUS, SAML, and LDAP, through integration with directory services. The solution is available in on-premises and SaaS deployment models and is managed through a central console.
Once connected, the platform evaluates endpoint security posture against configured policies to control network access. It enforces these policies by integrating with network infrastructure, including switches and wireless controllers, to dynamically assign devices to specific network segments or VLANs and apply Access Control Lists (ACLs). For Layer 2 enforcement, the system utilizes RADIUS for dynamic VLAN assignment and post-connection authorization updates. It also supports Layer 3 integration options, such as Policy-Based Routing, for environments without Layer 2 capabilities. The system captures contextual intelligence for reporting and can share data bi-directionally with external security systems for automated incident response.