Simgenet NAC Server — Industrial Network Access Control (802.1X, TACACS+, PKI)
Simgenet NAC Server — Industrial Network Access Control (802.1X, TACACS+, PKI)
Simgenet NAC Server is an industrial network access control (NAC) server that identifies every device joining the network and every person administering network devices, authorises them by role and records every decision. Its software is developed entirely in-house at Simgenet. With a core + site-node architecture the site keeps running even when the link to the centre is lost; IEEE 802.1X/MAB decide who may connect, RADIUS/TACACS+ decide who may administer; the built-in PKI (CA, SCEP, EST, OCSP) means certificates are never carried by hand. For substations, rail systems, industrial plants and government networks; within the IEC 62443 framework.
Simgenet NAC Server — Industrial Network Access Control
Simgenet NAC Server is a network access control server that identifies every device joining the network and every person administering network devices, authorises them by role and records every decision. A Core defines the policy; Site nodes in the field run the same software and answer the requests of switches and access points locally. Designed for industrial networks: device identity by certificate, MAC-based for IEDs/PLCs, administrator access via TACACS+; when the centre is lost, the site keeps running. The software is developed entirely in-house at Simgenet; it is not an adaptation of an off-the-shelf package.
Built for Industrial Reality
Enterprise NAC products think like a city centre: user laptops, guest portals, a permanent link to the centre. In the field there are IEDs, PLCs, RTUs and cameras; the WAN goes down; the engineer logs into the switch from the console. Instead of guest portals and user agents, NAC Server is built on device identity, local continuity and device administration, and was developed together with our own switch (SMG-SW), time server (GNSS Server) and test platform (SVP).
Who May Connect: 802.1X, MAB and Dynamic Authorisation
- Authentication: IEEE 802.1X EAP-TLS (device certificate and chain validation; certificate–MAC match is part of the decision) · PEAP / EAP-TTLS (local user database) · MAB for IEDs, PLCs, cameras and sensors without certificates; MAC-spoofing suspicion detection · unregistered device: reject or monitoring VLAN.
- Authorisation and enforcement: role → VLAN (RFC 3580), Filter-Id → access list and vendor attributes for dynamic ACLs · port class (timing / protection / general): ports carrying timing are recognised · CoA / Disconnect (RFC 5176) for session teardown, VLAN change and re-authorisation from the centre · quarantine and time-limited, audited break-glass exceptions.
- Monitor mode → enforce mode: every deployment starts in monitor mode — decisions are produced, reported but not enforced; the inventory fills and profiles are verified; switching to enforcement is an administrator decision, reversible with one click.
- Device profiling and inventory: passive collector (OUI, DHCP, SNMP), OT device library (relays, RTUs, PLCs, IEDs, GNSS/PTP), bulk import and API; Simgenet devices are recognised instantly.
- "Why was it rejected?" on one screen: the live authentication log lists every attempt with time, MAC, identity, profile, switch/port, policy, rejection reason and continuity state.
The Centre Goes Down, the Site Keeps Running: Core, Site Node and Standby Core
One software, two roles. Policy, inventory, PKI and reporting live in the core; authentication requests are answered in the field, at the nearest node, within milliseconds. Everything between core and site is signed and versioned.
- Site node on its own: the last approved policy and the local decision table live on the node; 802.1X/MAB and dynamic-VLAN decisions continue when the WAN is down — up to 30 days without the centre (configurable). Continuity modes (normal → restricted → continuity) are visible in the panel and the event log; when the link returns, events are forwarded and the policy gap closes automatically.
- Standby core and load sharing: the second core stays in sync; it takes over when the primary fails and hands back when it returns; single-writer principle. Site nodes are spread across the two cores by "home core" selection — no idle capacity. The switch knows several nodes as RADIUS/TACACS+ servers.
- Change safety: policy and device records are distributed as signed, generation-numbered packages; validated → applied → confirmed stages; a faulty generation is rolled back in one step. Software updates follow the same path: signed package, A/B installation, rollback.
Who May Administer: RADIUS and TACACS+ Device Administration
- RADIUS: administrator login with privilege level (admin / operator / viewer), RFC 2865/2866/2869; Message-Authenticator mandatory in both directions (closed to BlastRADIUS-class attacks); accounting; RadSec (RADIUS/TLS, RFC 6614) server; Status-Server.
- TACACS+ (RFC 8907): authentication, session privilege level 0–15, command authorisation — administrator-defined command sets (permit/deny patterns) and ready-made classes (view / no-config / full); every command decision in the audit log; TACACS+ over TLS 1.3 (RFC 9887).
- Identity sources: local user and device database; LDAP/AD; external RADIUS and TACACS+. Time trust (GNSS/NTP source, certificate validity window) is part of the decision.
Built-in PKI: Certificates Are Never Carried by Hand
Internal certificate authority (CA) with profile-based issuance; SCEP (RFC 8894) and EST (RFC 7030) for automatic device enrolment and renewal (the old certificate is revoked automatically on re-enrolment); OCSP responder and CRL (signed distribution to sites); revocation checking in EAP-TLS — a revoked certificate is rejected immediately; certificate-lifetime alarms (90/60/30 days).
Management, Monitoring and Integration
HTTPS web panel (TR/EN/FR, role-aware): status dashboard (continuity mode, accept/reject/monitor, policy generation, decision rate), live authentication log, devices, switches, sites, distribution, core HA, continuity readiness, certificate diagnostics, switch recipes. SNMPv3 (authPriv) + SIMGENET-NAC-MIB + notifications; syslog CEF over TLS straight to the SIEM; X.733 alarm management; daily report (JSON/CSV/API, 730-day retention); REST API; one-click support bundle (secret-free). Backup/restore, signed updates, A/B rollback.
Simgenet Ecosystem and Third-Party Devices
Simgenet SMG-SW switches and SMGOS routers: 802.1X authenticator, MAB, dynamic VLAN, Filter-Id, CoA, device-administration RADIUS/TACACS+, common CA — the enforcing side and the deciding side from one vendor. Simgenet GNSS Server: time trust and timing-port awareness. Simgenet SVP: deployment acceptance is measured — 802.1X/MAB/CoA vectors, capacity and takeover time delivered as a report. Standard RADIUS/TACACS+/CoA with third-party switches and access points; ready-made switch recipes for common vendors.
Scale and Acceptance (measured with SVP)
- 400,000+ decisions per day on a single site node; decisions in the field, millisecond class.
- Core takeover < 5 min, failback < 6 min — measured across a 9-site fleet in 3 scenarios; policy distribution to 9 sites < 2 min.
- Operation without the centre for up to 30 days; acceptance test with SVP: 802.1X/MAB/dynamic-VLAN/CoA vectors (known-PASS / known-FAIL), RADIUS security (Message-Authenticator, malformed packets, replay), TACACS+ command authorisation, capacity scale test, takeover/failback — lockable report.
Application Areas
- Power / substation: enrolment of IEDs, PLCs, RTUs and recorders via MAB/EAP-TLS; policy by class of timing and protection ports; regional core + standby core; switch/router administration via TACACS+; IEC 62443-aligned records.
- Rail / industrial plant / government: rejection of non-inventory devices in station and plant networks, gradual transition from monitoring to enforcement, local continuity with the site node, one policy from the centre; central records of administrator access in government networks.
Hardware: the NAC Core runs on Simgenet SMG-NAC104 hardware (1U 19" rack) (Intel® Xeon®, up to 64 GB DDR4, 4 × PCIe Gen3 expansion); the NAC Site node is installed on Simgenet hardware or a virtual machine. Core and site node share one image, the role is selected at installation. The full feature list and reference standards are in the product brochure (EN) under the Documents tab.
| Platform | |
| Product class | Industrial network access control (NAC) and device-administration AAA server; software developed entirely in-house at Simgenet |
| Roles | NAC Core (SMG-NAC-C) · NAC Site node (SMG-NAC-S) · Standby Core — one software image, role chosen at installation |
| Hardware — NAC Core | |
| Model | Simgenet SMG-NAC104 — 1U 19" rackmount |
| CPU / platform | Intel® Xeon® E3-1200 v5 series · Intel® C236 |
| Memory | 4 × DDR4 DIMM, DDR4-2133, up to 64 GB |
| Expansion | 4 × PCIe Gen3 x8 — 1G / 10G / 25G / 40G / 100G network cards |
| Power | 1 × 220 VAC server-grade power supply, 250 W |
| Environment | Operating −20…+60 °C · storage −20…+75 °C · 10–95% relative humidity (non-condensing) |
| EMC | EN 55032 Class A · EN 55035 · IEC 61000-4 series Level 3 |
| NAC Site hardware | Simgenet hardware or virtual machine — chosen per site |
| Access control | |
| Authentication | IEEE 802.1X-2020 EAP-TLS (RFC 5216) · PEAP / EAP-TTLS (local user DB) · MAB · unregistered-device reject / monitor-VLAN mode · MAC-spoofing suspicion detection · re-authentication (RFC 2865 Session-Timeout / Termination-Action) |
| Authorisation | Role → VLAN (RFC 3580 Tunnel-*) · Filter-Id → access list · dynamic ACL via vendor attributes · port class (timing / protection / general) · quarantine · time-limited break-glass (audited) |
| Dynamic authorisation | CoA and Disconnect (RFC 5176, port 3799), Error-Cause; fallback path for switches without CoA |
| Profiling / inventory | Passive collector (OUI, DHCP, SNMP) · OT device library (relays, RTUs, PLCs, IEDs, GNSS/PTP) · device records and groups · bulk import · API |
| AAA and PKI | |
| RADIUS | RFC 2865 / 2866 / 2869 · Status-Server (RFC 5997) · Message-Authenticator mandatory both ways (BlastRADIUS-protected) · RadSec (RFC 6614) server · accounting · privilege level (RFC 5607) · vendor attributes (enterprise OID) |
| TACACS+ | RFC 8907 — authentication (ASCII/PAP); session privilege level 0–15 and command authorisation (administrator-defined command sets, ready-made classes); every command decision audited; accounting · TACACS+ over TLS 1.3 (RFC 9887) |
| PKI | Internal CA · profile-based issuance (RFC 5280) · SCEP (RFC 8894) · EST (RFC 7030; incl. ECDSA) · OCSP (RFC 6960) · CRL (signed distribution to sites) · EAP-TLS revocation check · lifetime alarms 90/60/30 days |
| Identity sources | Local user/device database · LDAP / AD · external RADIUS · external TACACS+ · certificate (EAP-TLS) · MAC inventory |
| Continuity and HA | |
| Continuity | Local decision table and last approved policy on the site node; modes normal / restricted / continuity; 802.1X/MAB and dynamic-VLAN decisions uninterrupted when the centre is lost — up to 30 days (configurable) |
| HA / distribution | Standby core (automatic takeover / failback, single writer) · site nodes spread across two cores by "home core" (load sharing) · signed generation distribution (expiry, rollback) · decision stages validated → applied → confirmed |
| Management and monitoring | |
| Management | HTTPS web (TR/EN/FR; role-aware admin / operator / viewer) · external TACACS+/RADIUS/LDAP for administrator login · REST API · device-administration (TACACS+) screen · live decisions · "WHY?" diagnostics screen · ready-made templates and switch recipes · support bundle (secret-free) |
| Monitoring | SNMPv3 (authPriv) + SIMGENET-NAC-MIB + notifications · X.733 alarm management · time-trust monitoring (PTP/GNSS/NTP) · daily report (JSON/CSV/API, 730 days) |
| Logging / SIEM | Syslog CEF (RFC 5424) over TLS (RFC 5425) · administrator audit log · time-stamped decision log · retention and rotation policy · secret-free records |
| Security | IEC 62443-4-2 principles (least privilege, session/lockout, audit) · password policy and brute-force lockout · secrets masked on screen and in records · time trust (GNSS/NTP) part of the decision |
| Backup / update | Backup / restore (manifest + checksum, confirmed) · signed software package, A/B installation, rollback · policy-generation rollback |
| Capacity and deployment | |
| Capacity (measured) | 421,000+ decisions/day on one site node · core takeover 161–245 s, failback 234–315 s (9 sites, 3 scenarios) · up to 30 days without the centre · policy distribution to 9 sites < 2 min · report retention 730 days |
| Integration | SMG-SW switch / SMGOS router (802.1X, MAB, dynamic VLAN, Filter-Id, CoA, device-administration AAA, common CA) · Simgenet GNSS Server · Simgenet SVP (compliance vectors) · third-party switches and access points via standard RADIUS/TACACS+/CoA |
| Deployment | NAC Core: Simgenet SMG-NAC104 · NAC Site: Simgenet hardware or virtual machine · Core 4 vCPU / 8 GB / 100 GB · Site 2–4 vCPU / 4–8 GB / 60 GB · site installation: image + enrolment token → automatic registration · commissioning in monitor mode |
| Languages | TR / EN / FR |
| Out of scope | Cloud/SaaS · posture/compliance agent · guest/captive portal · BYOD self-service · Wi-Fi controller function |
| Reference standards | IEEE 802.1X-2020 · RFC 5216 · RFC 2865/2866/2869 · RFC 5997 · RFC 3580 · RFC 5176 · RFC 5607 · RFC 6614 · RFC 8907 · RFC 9887 · RFC 7030 · RFC 8894 · RFC 6960 · RFC 5280 · RFC 5424/5425 · RFC 3411–3418 · RFC 5905 · IEC 62443-3-3 / 62443-4-2 · X.733 |