Network Access Control (NAC)
Network Access Control aims to do exactly what the name implies—control access to a network with policies, including pre-admission endpoint security policy checks and post-admission controls over where users and devices can go on a network and what they can do.
You would look at a NAC solution for a list of feature controls like:-
User enforcement and education
- Open trouble ticket
- Create traps
- Syslog
- Personalized web message (network use policy, self remediation, etc.)
- Auditable end-user acknowledgement
- Force authentication/password change
- Log-off user, disable user AD account
Application control and remediation
- Application start or stop
- Peer-to-peer/IM start or stop
- Apply updates and patches
Network access control
- Port disable (802.1X, SNMP)
- VLAN control
- VPN disconnect
- ACL block at the switch, firewalls and routers
- Wireless allow/deny
- Quarantine until the devices is remediated
Traffic control
- Virtual firewall
- Update network ACL (switch, router, firewall)
Application control and remediation
- Application start or stop
- Peer-to-peer/IM start or stop
- Apply updates and patches
Operating system control and remediation
- Patch/hotfix update
- Registry configuration
- Process start/stop
Device control
- Disable NIC
- Shutdown PC
- Disable use of peripheral device