← Back to Projects

Network Access Control Deployment

September 2026

NAC802.1xPacketFenceCiscoActive Directory
Network Access Control Deployment

Overview

  • A network access control deployment, built during my Cybersecurity Engineer internship at DataProtect
  • Devices authenticate at the switch port using 802.1x, with MAB as the fallback
  • Dynamic VLAN assignment on successful authentication, instead of static port configuration
  • A segmented multi-VLAN network integrated with Active Directory for identity-based access control
  • Built on PacketFence, Cisco IOS, RADIUS and SNMP

The problem

A flat network trusts whatever plugs into it. Once a device has a port, it has the network. Segmenting by VLAN helps, but if VLANs are assigned statically per port, access still follows the cable rather than the person, and keeping it correct becomes a manual job that drifts.

What I built

Authentication at the edge

  • 802.1x authentication at the access layer, so a device identifies itself before the port forwards anything
  • MAB (MAC Authentication Bypass) as the fallback path for endpoints that cannot run an 802.1x supplicant
  • RADIUS carrying the authentication exchange between switch and the NAC engine

Access that follows identity

  • Dynamic VLAN assignment on successful authentication, so the device lands in the right segment automatically
  • A segmented multi-VLAN network design, rather than one flat broadcast domain
  • Active Directory integrated as the identity source behind those decisions

Enforcement and visibility

  • A Cisco switch configured for access-layer enforcement of authentication and compliance policies, using IBNS
  • SNMP for switch state and port events, so the NAC engine reacts to what actually happens on the wire
  • The full environment built and tested in VMware Workstation before going anywhere near production

What I took from it

Identity-based access control is the same idea as the authorisation policies I had written in application code earlier, pushed one layer down the stack. Who you are decides what you reach, and the decision belongs in one place rather than scattered across static configuration.