NACVIEW
NACVIEW: Polish NAC (Network Access Control) technology. Full network device visibility, 802.1X access control, automatic VLAN segmentation, IoT/OT profiling.

Key Features
- Full network visibility - every device identified
- 802.1X and RADIUS - network access control
- Automatic VLAN segmentation
- IoT and OT device profiling
- Guest portal (captive portal)
Table of Contents
What is NACVIEW?
NACVIEW is a Polish NAC (Network Access Control) platform - a system that sees every device on your network and controls who/what can connect to it. It answers the fundamental question: “What exactly is running on my network?”
Main functions:
- Visibility - automatic detection and profiling of every device
- Access Control - 802.1X, RADIUS, VLAN assignment
- Segmentation - automatic device isolation according to policies
- Response - automatic blocking when threats detected
What problem does it solve?
flowchart LR
subgraph Without NAC
A[Who is on the network?] --> B[Don't know]
B --> C[Shadow IT]
C --> D[Risk]
end
subgraph With NACVIEW
E[Every device] --> F[Identified]
F --> G[Assigned to VLAN]
G --> H[Controlled]
end
style A fill:#dc2626,stroke:#b91c1c,color:#fff
style B fill:#dc2626,stroke:#b91c1c,color:#fff
style C fill:#dc2626,stroke:#b91c1c,color:#fff
style D fill:#dc2626,stroke:#b91c1c,color:#fff
style E fill:#22c55e,stroke:#16a34a,color:#fff
style F fill:#22c55e,stroke:#16a34a,color:#fff
style G fill:#22c55e,stroke:#16a34a,color:#fff
style H fill:#22c55e,stroke:#16a34a,color:#fff
Typical problems NACVIEW solves:
- Don’t know how many devices are on the network (shadow IT)
- Guests connect to production network
- IoT/OT devices are on the same network as computers
- No automatic incident response
How does NACVIEW work?
flowchart TD
A[Device connects] --> B[Switch asks NACVIEW]
B --> C{Known device?}
C -->|Yes| D[Check policy]
C -->|No| E[Profile device]
D --> F[Assign VLAN]
E --> G[Guest VLAN / Quarantine]
style A fill:#6366f1,stroke:#4f46e5,color:#fff
style B fill:#8b5cf6,stroke:#7c3aed,color:#fff
style C fill:#f59e0b,stroke:#d97706,color:#fff
style D fill:#22c55e,stroke:#16a34a,color:#fff
style E fill:#f59e0b,stroke:#d97706,color:#fff
style F fill:#22c55e,stroke:#16a34a,color:#fff
style G fill:#dc2626,stroke:#b91c1c,color:#fff
Process:
- Device connects to switch port
- Switch (802.1X) asks NACVIEW via RADIUS
- NACVIEW identifies device (MAC, certificate, user)
- Checks security policy
- Assigns appropriate VLAN (or blocks)
Main features
Network Visibility
Complete device inventory
- Continuous network scanning
- Profiling (type, OS, vendor)
- Location (switch, port)
- Connection history
Access Control
802.1X and RADIUS
- 802.1X authentication (EAP)
- MAC Authentication Bypass
- AD/LDAP integration
- Certificates (PKI)
Segmentation
Automatic VLAN
- Dynamic VLAN assignment
- Per device/user policies
- Microsegmentation
- IoT/OT isolation
Guest Portal
Captive portal
- Self-registration
- Sponsor approval
- Temporary access
- Company branding
IoT/OT Profiling
Devices without 802.1X
- Device fingerprinting
- IoT profile database
- Anomaly detection
- Automatic classification
Automation
Incident response
- SIEM integration
- Auto-blocking on alert
- Device quarantine
- API for automation
Device Profiling
NACVIEW automatically identifies devices based on:
| Method | What it detects | Example |
|---|---|---|
| MAC OUI | Manufacturer | Apple, HP, Cisco |
| DHCP fingerprint | Device type | Windows 11, iPhone, Printer |
| HTTP User-Agent | Browser, OS | Chrome on macOS |
| SNMP | Device details | Switch model, firmware |
| Active scan | Open ports, services | SSH, HTTP, SNMP |
Profile example:
Device: 00:1A:2B:3C:4D:5E
Type: IP Camera
Vendor: Hikvision
Model: DS-2CD2143G0-I
Location: Switch-Floor2, Port 15
VLAN: IoT-Cameras (VLAN 150)
Status: Active
Architecture
flowchart TD
A[NACVIEW Master] --> B[Collector 1]
A --> C[Collector 2]
B --> D[Switch/AP branch 1]
C --> E[Switch/AP branch 2]
A --> F[Active Directory]
A --> G[SIEM]
A --> H[Firewall]
style A fill:#6366f1,stroke:#4f46e5,color:#fff
style B fill:#8b5cf6,stroke:#7c3aed,color:#fff
style C fill:#8b5cf6,stroke:#7c3aed,color:#fff
style D fill:#22c55e,stroke:#16a34a,color:#fff
style E fill:#22c55e,stroke:#16a34a,color:#fff
Components:
- Master Server - centralized management, database, policies
- Collectors - distributed across locations, collect network data
- Integrations - AD, SIEM, firewall, EDR
Integrations
Network Infrastructure
Cisco, HPE Aruba, Extreme, Huawei, Fortinet
Identity
Active Directory, LDAP, Azure AD, Okta
SIEM
Splunk, QRadar, Microsoft Sentinel, Elastic
Firewall
Fortinet, Cisco
EDR/XDR
CrowdStrike, Microsoft Defender, SentinelOne
ITSM
ServiceNow, Jira Service Management
For whom?
NACVIEW MAKES sense when:
- • Don't know exactly what's on your network
- • Have many IoT/OT devices to secure
- • Need network segmentation (VLAN)
- • Want to control guest access
- • Looking for Polish product with local support
NACVIEW DOESN'T make sense when:
- • Small network (< 50 devices) - may be overkill
- • Switches don't support 802.1X
- • Already have NAC (Cisco ISE, Aruba ClearPass)
NACVIEW vs competition
| Aspect | NACVIEW | Cisco ISE | Aruba ClearPass | Forescout |
|---|---|---|---|---|
| Origin | Poland | USA | USA | USA |
| Deployment | Simple | Complex | Medium | Medium |
| Licensing | Per active MAC | Per endpoint | Per endpoint | Per device |
| IoT/OT profiling | Yes | Yes (add-on) | Yes | Yes (core) |
| Price | Competitive | Premium | Premium | Premium |
| Support PL | Local | Distributor | Distributor | Distributor |
NACVIEW advantage:
- Polish company = local support, fast response
- Simpler deployment than Cisco ISE
- Full functionality in one license (no modules)
- Competitive price
Licensing
| Element | Description |
|---|---|
| Model | Per active device (MAC) |
| Period | Last 30 days of activity |
| Functionality | Full (no module division) |
| Components | Master + Collectors (no additional fees) |
Example: If 1500 unique MAC addresses appeared on the network in 30 days, you pay for a license for 1500 devices.
Specifications
| Parameter | Value |
|---|---|
| Deployment | VM (Hyper-V) or appliance |
| Protocols | 802.1X, RADIUS, TACACS+, SNMP |
| Integrations | AD, LDAP, SIEM, Firewall, EDR |
| API | REST API |
| Scaling | Unlimited (Collectors) |
| HA | Master in cluster |
FAQ
Does NACVIEW work with my switches? Yes, if they support 802.1X and RADIUS. Supported: Cisco, HPE Aruba, Extreme, Huawei, Fortinet and others.
What about devices without 802.1X (printers, cameras)? NACVIEW uses MAC Authentication Bypass (MAB) and profiling. Device is identified by MAC and fingerprint.
How long does deployment take? Basic deployment: 2-4 weeks. Full with integrations: 1-2 months.
Do I need all switches supporting 802.1X? No. NACVIEW can operate in visibility mode (monitoring) on ports without 802.1X, and you enable control gradually.
Does NACVIEW block traffic on failure? No. RADIUS timeout = open network (fail-open). You can also configure local cache on switches.
How does firewall integration work? NACVIEW sends device information to firewall. FortiGate can create per-user/device policies.
Is there WiFi network support? Yes. NACVIEW integrates with WiFi controllers (Aruba, Cisco, Fortinet) via RADIUS.
Does nFlo deploy NACVIEW? Yes. Design, deployment, 802.1X configuration, infrastructure integration, training.
Inquire about NACVIEW
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
CIS Security Audit
Cybersecurity
Harden system configurations with CIS Benchmarks. Block 85% of common attacks.
Cloud Security Audit and Protection
Cybersecurity
Check AWS/Azure/GCP security before attackers find misconfigurations. CSPM + manual review.
Web Application Penetration Testing
Cybersecurity
One SQL injection = access to entire database. Find vulnerabilities before hackers do.
From Our Knowledge Base
Articles related to this solution
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
A deepfake on a video call, voice cloning and AI-powered CEO fraud mean real losses in the millions. Learn how these scams work and the proven defenses, including second-channel verification.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist