Securing Network Access with 802.1x NAC for a UK Government Department

A secure and robust 802.1x Network Access Control (NAC) solution was designed, implemented, and operated to protect over 10,000 wired and wireless connections for a large UK Government Department. The solution enhanced network security by extending trust to the network edge, monitoring for anomalies, and integrating with key management and monitoring tools.

The project involved deploying a highly available and fault-tolerant Identity Services Engine (ISE) cluster. This infrastructure supported over 10,000 wired and wireless endpoints, ensuring seamless and secure access. The solution extended the network trust boundary to the edge, maintaining continuous monitoring to detect and mitigate anomalous behaviour or unauthorised devices. Logs were securely exported to a centralised data lake for advanced monitoring and analysis.

The Challenge

The UK Government Department required a comprehensive solution to secure its wired and wireless networks. Key challenges included:

Managing access for over 10,000 endpoints.

Ensuring fault tolerance and high availability of the network infrastructure.

Extending security to the network edge to monitor and respond to threats.

Integrating the solution with existing security systems and management processes.

content-image

The Solution

Cybernetica delivered a tailored 802.1x NAC solution, leveraging the Cisco Identity Services Engine (ISE) to address the department’s needs. Key features included:

A fault-tolerant ISE cluster for reliable AAA services (Authentication, Authorisation, Accounting).

Secure integration with Protective Monitoring and Vulnerability Management systems.

Granular Role-Based Access Control via TACACS+/RADIUS for device administration.

Exporting logs to a secure data lake for enhanced SIEM (Security Information and Event Management) capabilities.

Hosting and securing enterprise management toolsets to ensure effective oversight and operations.

content-image

The Outcome

The deployed NAC solution successfully secured the department’s network, enabling scalable, fault-tolerant access control for thousands of endpoints. The integration with enterprise toolsets improved operational visibility and security. By continuously monitoring and managing access, the department strengthened its network boundary and ensured compliance with stringent Government security standards.

content-image

You May Also Like

Showcasing our recent customer success stories across public and private sector.

A new Secure Outbound Web Gateway was developed and implemented for the second-largest UK Government department, enabling secure and efficient web access for 100,000 users. The service included both Secure Access Service Edge (SASE) and on-premise deployments, integrating advanced security technologies to replace a legacy third-party solution.
A new Secure Gateway Service was designed, built, and implemented for the second-largest UK Government department, supporting approximately 100,000 internal users. The solution provided secure connectivity between internal systems and diverse external resources, ensuring high security, performance, and resilience across various environments, including AWS, Azure, PSN, and SaaS services.
A large Government Department sought to design, implement, and operate an 802.1x guest Wi-Fi network, known as GovWiFi, to provide a secure internet connection for Government employees and third parties. Inspired by Eduroam, the solution enables users to roam seamlessly between Government departments while maintaining secure connectivity.

Get Started Today!

We deliver innovative solutions and services tailored to meet the specific needs of each organisation we work with.