We use the solution for Wi-Fi authentication.
macmon Network Access Control provides a comprehensive network security solution focusing on visibility and control over network access in real-time, ensuring only authorized devices connect while offering detailed monitoring and compliance capabilities.

| Product | Mindshare (%) |
|---|---|
| macmon Network Access Control | 2.6% |
| Cisco Identity Services Engine (ISE) | 18.4% |
| Aruba ClearPass | 17.5% |
| Other | 61.5% |
macmon Network Access Control offers powerful features that enhance network security by ensuring policy enforcement and real-time monitoring. It is particularly beneficial for organizations needing a scalable and adaptable system that can operate within complex network environments to provide enhanced device visibility and security. The software's ease of integration and automation capabilities make it ideal for improving security compliance without extensive resource allocation.
What are the key features of macmon Network Access Control?macmon Network Access Control is effectively implemented across industries such as healthcare, financial services, and education. It addresses sector-specific challenges like compliance with stringent regulations in healthcare or ensuring secure connectivity in finance. Its adaptability makes it a strategic choice for diverse verticals needing reliable network security.
macmon Network Access Control was previously known as macmon NAC.
More than 1,500 installations in all over Europe in all industries: Stepchange, Volkswagen, Vivantes Healthcare, MBDA Weapons, APS engineering, Alfred Ritter GmbH (Ritter Sport), Haßberg-Kliniken, 1. FSV Mainz 05 eV., Siempelkamp, AEB etc.
| Author info | Rating | Review Summary |
|---|---|---|
| Wireless Network Engineer at Forvia | 3.5 | I use macmon Network Access Control for Wi-Fi authentication due to its ease of connection with clients. However, troubleshooting is difficult due to a large number of log files per device, making it hard to trace past authentication issues. |
| Senior System Engineer at MOD IT GmbH | 4.5 | We use macmon Network Access Control for VLAN management and compliance checks across multiple locations. Its integration with Cisco switches is valuable, though improvements are needed in single sign-on and interface usability. We've seen a reduction in workload with this solution. |
| Managing Director at a non-profit with 1-10 employees | 5.0 | macmon significantly improved our network security by ensuring only authorized devices access it. It was easy to set up, offers flexible authentication, integrates well, and has excellent support, saving us significant time and money compared to previous solutions. |
We use the solution for Wi-Fi authentication.
The ease of connecting with the client is valuable for me.
There is no information on the protocol where the clients stop to authenticate. There are some policies, but I don't know whether the device stopped on the authentication or authorization levels. I don't know whether it is getting the right certificate. I have to work on assumptions.
If I want to go to the history to see what happened to a client the previous day or two days ago, it will be very hard because the server is used by multiple devices. For every device and user, macmon creates a file into the RADIUS appliance for deep troubleshooting. To troubleshoot, it creates a bunch of files.
If I want to check what happened in the history, I have to check all the files. In some cases, there are 100 files. It is impossible for me to go to each file to see where it happens. It will be good to find the file my client authenticated based on the MAC address. Otherwise, the product must have one file for a specific date. I don't have any problem in terms of dates because it's normal. However, having hundreds of files per day is very hard to troubleshoot.
The solution must allow users to filter files based on dates. It must provide deeper troubleshooting and reduced log. Also, the RADIUS logs are very huge.
I have been using the product for three years. I am using the latest version of the solution.
I rate the solution’s stability a ten out of ten.
I rate the scalability a five out of ten. We had some very big issues with the tool’s scalability. When one of the servers was down, we had synchronization issues. Currently, we have 150,000 endpoints.
The support team responds fast to some of the issues we have. However, the team does not give a fast reply to most of the issues.
When the synchronization issue started, unfortunately, the team did not reply. We had to make some adjustments by ourselves. We did not receive any reply for one or two days. After that, we had a lot of discussions from a business point of view with the team managers. We defined some roles and defined what we wanted. We defined how we want the SLA to be. After that, the communication improved.
Usually, we ask something over email, and they tell us whether it is possible. The message is not clear. We are confused. I rate the technical support a seven or eight out of ten.
Neutral
We were using Cisco Identity Services Engine. We replaced it.
The initial setup is quite easy. I was involved in the deployment from the beginning. The solution is deployed on-premises since we have all the VMs on our site. We have a master VM. The time taken for deployment depends on the site. With macmon, the deployment took one hour per site, not more than that.
We can easily have a RADIUS and NAC solution with less effort. If we want deeper troubleshooting, the product needs improvement. If we have many clients, endpoints, and complex policies, deeper troubleshooting might be needed. The tool is very hard to maintain on a daily basis. Overall, I rate the tool a seven out of ten.

Most of the time, we use it because we have different VLANs for micro-segmentation. We have around thirty production networks and sixty different locations around the world. We assign MAC addresses from clients or machines to the webinar. We also have a software management tool to check if an update has been installed, and if the machine is compliant. If it's not compliant, it will be automatically set to active the next month and put to the NAC and non-compliance.
We have a big factory building with a lot of offices with a lot of network ports. Sometimes they do not get an Ethernet signal when I plug in their notebook. We need to log in with the NetApp address, check the client, and then see if we get the layer of response.
We use it with our Cisco switches so we can see which switch it is actually connected to. We can as well see our clients' statuses, so we can see if an app responded, if the radio authentication was successful, or if we get the layer two response and there's a physical connection. That is valuable.
The single sign-on process can be improved and the interface should be made more user-friendly. The interface is user-friendly but, for example, when we have new people starting to work, they never work with NetOne and it is a bit hard to expand in certain places.
In addition, when I have to pull the last corrected MAC address, I need to put the space between it in order to find the address. If I don't put it in there, I don't get any resources. This needs improvement.
They should maybe add integration with LanSuite. We can include it to see the direct information we get from our LAN Tree. If I click on the MAC address, I will then directly get the hostname, and that will open a tap-in line so I see what the last update was.
It is a highly stable solution. I rate the stability a nine out of ten.
It is a scalable solution. I rate it an eight out of ten.
The technical support team is always keen to help.
Positive
The initial setup was not complex because we were on-site and tested everything in case of any downtime issues.
We have seen an ROI as it has decreased our workload and now we check everything online in the solution.
The solution is not expensive.
macmon is a good solution, but the single sign-in part needs improvement. I would rate the overall solution a nine out of ten.
macmon helps us to know who is in our network. We can be sure that only authorized devices are part of our network. In different areas in the past, it was always so much work to be sure that there were no unknown components in our network. With macmon, we can prevent our network easily from unauthorized access. We now always have good knowledge of who is active in our network. The network components are from different vendors and with macmon we did not have to change all the components to get a restrictive network access policy. We also now can be sure that the network devices are compliant.
Many things have become easier. We have constant insight into which components are active in our network. Automatically, devices are put to the right VLANs, and guests get vouchers for their devices – even if they need LAN-Access.
We can be sure that nobody forgets to block the ports once the guests are gone. The reporting is excellent and we are always informed if someone without permission has tried to get into our network.
We don't have to spend much time with macmon. We can give some parts of administration to office personal, for example, giving out vouchers.
With Macon you are not forced to change your switch infrastructure, macmon handles a variety of vendors. You can also decide where you want which type of authentification. You can use Mac authentification, you can use 802.ix, or stick the Mac address into a special type of operating system. It depends on the personal security level you want to implement.
macmon is able to communicate with a great variety of third-party products. There is communication between macmon and your firewall, as well as with other security solutions.
The API is a great way to get information from other tools.
The service macmon offers is already great. The support is really good, and, if you need some new features, you can always discuss this with the development team. If the feature is something the world needs, they will try to do it.
macmon is going in the right direction. They started with network access and combined it with compliance. At the moment, macmon offers a new solution, called SPD, which refers to Zero Trust. This must be the way for the future. Network access control combined with Zero Trust for remote workers will be great. That way, everyone who works from outside the company can be authorized by several authentication factors.
I've used the solution for several years - likely around 5 or 6.
The stability is good. The new versions are stable and the macmon team always working on performance improvements. You can get support from macmon or macmon partners if you run into issues.
The scalability is very good. You can use macmon in small environments but you can also use it as an enterprise company with locations all over the world.
The support is great. If you need help they are with you in a short amount of time. You can directly talk with someone. You don´t have to do everything by mail.
We used a different solution called Arp Guard. We switched because the solution did not fit the standard of a network access solution. There was an old-fashioned look to the product as well and the support was poor. It always took a long time to get answers. At that time, there was no real documentation.
We never regretted our decision to switch because the road map was and is much more impressive with macmon than by the other vendor.
macmon was easy to set up. We used a virtual appliance and did it step by step. There is a guideline, however, we did it with help from a macmon partner
We did it in-house.
It is difficult to estimate what would have happened without the security improvements by macmon. It's likely we saved several thousand euros over the years. Also, the manpower saved since implementing macmon has been invaluable.
The best way to come to a decision is a proof of concept. Try the solution and have a look at how you can work with it. The pricing is important, however, you should also think about saving time in implementing and working with the solution. In the end, the benefits you get will outweigh the costs.
Licensing by macmon is easy. You have network nodes and server hardware or a virtual appliance or you can go in the direction of server scalability. My commitment is directly to start with a virtual appliance.
We made an evaluation of other options. First, we tried Microsoft tools – however, that was much too difficult. When we started with macmon we had immediate success. We could see our network and see the devices and could easily go online. The VLAN Management was quick to implement and we had no problems with our network devices or with the switch components.
I'd advise new users to just try it. Don't be afraid. Network access control can be implemented in a few days. Later on, the handling is easy. You must not be afraid to have more work than before. The solution helps you to save time and money.