NETVISS One · Eight products. One console. Zero blind spots. See the platform →
Unified Zero Trust & IT Operations Platform

See it. Secure it. Run it.

One platform for every device, network, endpoint and decision.

Eight products that share one device list, one set of rules and one screen. Start with any of them. Add the rest without starting over.Access control, performance, traffic, configuration, endpoints, vulnerabilities, IT operations and ZT-VPN on one inventory, one policy engine and one event bus.

Tailor this site for

Live access log Simulation
1,284auth / min99.4%allowed12quarantined3blocked
TimeEndpointWhereMethodVerdictPolicy applied

Zero Trust Network Access Control (NAC)

Network access control that knows every device the moment it connects and decides where it may go. Works with any switch and any vendor, with or without 802.1X.

Knows every device the moment it connects and decides where it may go. Works with any switch, any hypervisor and any mix of enforcement, without changing your network.

Also called

network access control, NAC, ZTNAC, zero trust NAC, zero trust network access, 802.1X alternative, device onboarding, guest network access, BYOD access control, network admission control.

What it does

  • IPAM Live IP address management from discovery. Subnets, leases and conflicts in one view.
  • Switch port management See and change port state, VLAN and description across vendors from one screen.
  • BYOD & guest Self-registration, sponsor approval and time-limited access for visitors and personal devices.
  • WLC management Apply the same access policy to wireless controllers as to wired ports.
  • Anomaly detection & prevention Flags devices that change behaviour or spoof identity, and acts on policy.
  • 802.1X and non-802.1X Use 802.1X where it works, out-of-band everywhere else. Mix per site.
  • SNMP & SPAN Optional data sources and enforcement paths for richer visibility.
  • AI Enforcer AI-assisted profiling and enforcement for devices that don’t identify themselves.
  • MSP-ready Multi-tenant from day one, with separate customers in one console.
  • Multi-mode enforcement ARP, ICMP, DHCP and TCP enforcement, 802.1X, SNMP, SPAN, inline, agent and sensor control. Use one or all, per site.
  • Zero touch deployment No switch changes, no agents, no re-cabling. NETVISS fits the network you already run.
  • One touch isolation Cut any device off the network from its record in one click.
  • Device registration Staff, guest and IoT devices registered with an owner and an approval flow.
  • Technology integrations Built-in integrations with the identity, security and IT tools you already run.
  • Deploy anywhere On-premises, cloud or hybrid, on any major hypervisor or on a bare-metal server.

Common concerns

802.1X rollout takes months and stalls on legacy devices
Out-of-band mode starts with one trunk port and one free IP per VLAN
A rogue device on a meeting-room port
Detected, profiled and quarantined as it connects
Guest and BYOD requests flood the helpdesk
Self-service onboarding portal with sponsor approval
IP address spreadsheets and conflicts
Built-in IPAM, fed by live discovery
Wi-Fi and wired policies managed in different consoles
One policy for switch ports and wireless controllers
Strange behaviour from a known device
Anomaly detection and automatic prevention

Questions and answers

Do we need 802.1X?
No. Out-of-band mode needs a trunk port tagged with all VLANs and one free IP per VLAN. Use 802.1X where it already works and mix modes per site.
Do we need agents on every device?
No. Discovery and profiling are agentless. An agent is available when you want deeper endpoint posture.
Can branches use different modes?
Yes. Each site can use out-of-band, 802.1X, SNMP or SPAN. Only out-of-band sites need a local sensor.
Can we start with NAC and add more later?
Yes. Add any module licence later. It appears in the same console with no redeploy or reconfiguration.
Where can it run?
On-premises, in the cloud or hybrid. On VMware ESXi, Microsoft Hyper-V, Nutanix AHV, KVM, or directly on a bare-metal server.
Which enforcement modes can we use?
ARP, ICMP, DHCP and TCP enforcement, 802.1X, SNMP, SPAN, inline, agent and sensor. Use one, or combine them site by site.
Do we have to change our network?
No. Deployment is zero touch: no new switches, no re-cabling and no changes to how your network is built.
What problem does NV-ZT-NAC solve?
It tells you every device on your network, who owns it and where it is plugged in, then decides what each device may reach. Unknown or risky devices are isolated automatically, on wired, wireless and remote connections.
How long does a first deployment take?
A first site is usually discovering devices on the first day. Enforcement follows once you have reviewed what was found and agreed the policies, typically within the first weeks.
Do we have to change our switches or network design?
No. Deployment is zero touch: no switch replacement, no re-cabling and no redesign. NETVISS works with the switches, controllers and VLANs you already run.
Can it run on-premises, in the cloud or both?
Yes. On-premises, in the cloud or hybrid, on VMware ESXi, Microsoft Hyper-V, Nutanix AHV, KVM or a bare-metal server.
What are the enforcement modes?
ARP, ICMP, DHCP and TCP enforcement, 802.1X, SNMP, SPAN, inline, agent and sensor control, plus AI Enforcer. Use one or combine several, site by site.
We have branches with different equipment. Is that a problem?
No. Each branch can use the enforcement mode that suits its equipment. Out-of-band branches use a small sensor; 802.1X, SNMP and SPAN branches connect straight to the central cluster.
Does it include IP address management?
Yes. IPAM is built in and fed by live discovery, so subnets, leases and conflicts are always current.
Can it manage switch ports and wireless controllers?
Yes. Switch port management and WLC management are included, so one policy covers wired and wireless access.
How are guests and personal devices handled?
Through self-registration and sponsor approval, with time-limited access and their own network segment. No helpdesk ticket needed.
What is one touch isolation?
From any device record, one click moves the device to quarantine and cuts it off from everything else. The action is logged and can raise a ticket.
Does it detect spoofed or misbehaving devices?
Yes. Anomaly detection flags devices that change behaviour or impersonate another device, and can quarantine them by policy.
Which systems does it integrate with?
Directory and identity providers, endpoint and security tools, SIEM, SOAR and ticketing systems. Integrations are built in, and the other NETVISS modules share the same device record.
How does it help with audits?
Every device, access decision and change is recorded. You can show auditors who connected, when, where and under which policy, from one console.
Does it help contain ransomware?
Yes. Segmentation limits lateral movement, and devices showing risky behaviour or failing posture can be isolated automatically before an infection spreads.
Is it suitable for managed service providers?
Yes. It is multi-tenant, so an MSP can run many customers from one console with separate policies and reports.
How is it licensed?
As an annual subscription that includes software, implementation, support and maintenance.

Often deployed with

  • Vulnerability Assessment & Management Scans everything you run, from network gear and servers to laptops, websites and applications, and tells you what to fix first and exactly how.
  • Unified Endpoint Management An agent for Windows, Linux and macOS that shows everything about each computer and lets IT act on it remotely: restart it, lock it, install software, fix it, or join a live session.
  • IT Operations Management Your service desk and asset register in one place, for IT and beyond: tickets, requests, changes, problems, knowledge, software licences and renewals.

Guides

Book a demo