Solution — Identity and Access

Identity-Based Network Access

An IP address does not tell you who someone is. XLOG identifies the user through Active Directory and LDAP, the hotspot portal or 802.1x MAC control; it filters the device before it joins the network, ties the rule and the quota to the user, and keeps the record with the username and MAC address.

Why Identity

Let the network show the person, not the IP address

On a network without identity, both the rule and the record hang off an IP address: when the address changes, who did what is lost. With identity-based access, a username and a MAC address stand behind every session; whether you are writing a rule or searching a record, what you are looking for is the person.

On a network without identity
Rules and records hang off the IP address; when the address changes the trail breaks.
Which device joined the network is only understood afterwards.
The corporate user and the guest come in through the same door, undifferentiated.
When you search the records, all you have is an IP and a time.
On an identity-based network with XLOG
Behind every session there is a username and a MAC address.
An unknown device is filtered at the edge, before it joins the network.
The corporate user is verified from the directory, the guest from the captive portal.
Username, MAC address, destination and time can all be searched together in the record.
Verification Methods

Where does the identity come from?

A corporate user is registered in the directory, a guest is not; devices such as printers or cameras have no user at all. XLOG solves all three cases on the same device with separate identity sources; the methods can be used together.

01 — DIRECTORY

Active Directory and LDAP integration

You do not need to keep a separate user list for corporate users; the identity is already on the directory server.

The AD Agent software is used for Windows PCs.
LDAP can also be used among the hotspot verification methods.
Directory integration is on all 12 firewall models.
02 — EDGE

802.1x MAC control and RADIUS MAC filtering

Filtering the device before it joins the network rather than restricting it afterwards. With managed switch integration, client devices are blocked or filtered at the edge.

Works with managed switch integration on both Layer 2 and Layer 3 networks.
Client devices can be blocked or filtered at the edge, before they join the network.
Devices that join the network, or try to, can be tracked live.
Dynamic VLAN assignment can be done with 802.1X RADIUS.
03 — PORTAL

User verification through the hotspot

There is no directory record for guests and rotating users; verification happens at the captive portal. Once verified, the user goes online and their records are kept signed.

Three main authentication methods: ID number, username and password, SMS integration.
Integration with hotel management programs and third-party software is available.
One-time passwords can be created for guests; they can be handed over as a slip from the thermal printer.
Privileged users can connect without seeing the hotspot page.
802.1x MAC Control

Verification happens at two separate points

RADIUS MAC filtering filters the device at the edge, before it joins the network; hotspot and Active Directory verification identify the user after the device has joined. The two points do not replace one another, they complete one another.

Identity-based network access flow diagram The user's device first passes 802.1x and RADIUS MAC control on the managed switch; a device that is not approved is blocked without joining the network. An approved device reaches the XLOG Firewall, where the user is verified with Active Directory, LDAP or the hotspot portal, then goes online, and the access is written into the signed record with the username, the MAC address and the time. BEFORE JOINING THE NETWORK AFTER JOINING THE NETWORK Not admitted to the network An unknown device is filtered at the edge User arrives with a MAC address Managed switch 802.1x MAC control / RADIUS XLOG Firewall Active Directory / LDAP Hotspot captive portal Internet Per-user rule Signed record Username · MAC address · source and destination IP · login and logout time
On Layer 3 networks, XLOG collects ARP information from edge and core switches with SNMP and telnet support; that way the MAC address is added to the log records as well.
Comparison

What each method verifies

Method What it verifies Where it works Typical user
Active Directory / LDAP The corporate user's identity through the directory The corporate network; with AD Agent on Windows PCs Staff
802.1x MAC control Whether the device is authorized to join the network On the managed switch, at the edge Fixed devices
RADIUS MAC filtering Whether the MAC address is on the allow list On Layer 2 and Layer 3 networks with switch integration Printers, cameras, terminals
Hotspot verification The person, with an ID number, username and password or SMS Through the captive portal Guests
Layer 2 filtering A client trying to connect from the internal network, with admin approval On the internal network, on the device A newly defined device
Per-User Rules

Knowing the identity simplifies the rule

Once the user is identified, the rule is no longer written for an IP range but for a person or a group. Speed, quota, filter profile and port permission are all bound to the same identity.

Group-based firewall rule

Group-based rules can be created; the rules you choose apply to the groups you choose.

Per-user and per-MAC speed

Download and upload speed is defined per user or per MAC address, distributing internet speed as needed.

Per-user and per-MAC quota

A quota can be defined; the internet activity of a user who exceeds the quota is cut off by the system. Daily usage is recorded and can be listed by date range.

Timed port permission granted to a user

System administrators can grant users with access permission the right to open a timed port to their own IP; the port closes automatically when the time is up.

Live user monitoring

Currently active users on the system and their quota usage are listed; devices generating excessive traffic are shown at the top.

Reporting

Looking for the answer in the records

With the detailed reporting feature, internet records can be searched by MAC address, source IP, destination IP, username, destination port, domain and date. The internet login and logout times of users who signed in through the hotspot can be listed.

Currently active users on the system and their quota usage are listed as well. Logins to the XLOG system are recorded separately; in other words, who manages the network is on the record too.

Fields that can be searched in the records
MAC address Source IP Destination IP Username Destination port Domain Date
Records are signed with a time stamp and kept signed on the device for 2 years.

Let us look at your user setup

Share how many users you have, whether you use Active Directory and whether you offer guest access; let us work out the verification design together.

Request a demo