Home › Modules › Access Control
Access Control
Uplivra answers TACACS+ and RADIUS for your network gear itself, decides who may log in to which device and run which commands, keeps a record of everything, and writes the device commands for you.
Choose Access Control if you want to…
Control who logs in to switches, routers and firewalls, what commands they run, and which devices get on the network (TACACS+, RADIUS, MAB).
- What to count
- The network devices that ask Uplivra: switches, routers, firewalls, wireless controllers. People and endpoints don't count.
- Example
- 20 switches, 2 firewalls and 2 routers use Uplivra for admin logins: Access Control for 24, $120 a month.
Every admin login, one set of rules
Shared "admin" passwords on every switch are the first thing an auditor asks about. With Access Control your switches, routers and firewalls ask Uplivra who may log in. Each person uses their own name: either a login you create in Uplivra, or their Active Directory or LDAP account through the groups you pick.
Rules say who may log in where:
- by group, device type, tag, site, time of day or maintenance window;
- with which privilege level or device role.
The first rule that fits decides. Try a rule shows what would happen, rule by rule, before anyone depends on it.
Commands, checked one by one
With TACACS+ the device asks Uplivra before every command. Command sets list what each group may run:
- allow or deny a command start or a pattern;
- approve: a second person approves it first.
Risky commands such as reload, write erase or no aaa wait for that approval and then run once. Every command is recorded with who ran it, where and when.
Temporary admin access
For a change window or an incident, ask for higher rights on chosen devices for a set time, with a reason and a ticket number. A second person approves it, the clock starts, and the access ends by itself. Uplivra records everything done under it against the ticket.
The device commands, written for you
Pick a network device and its maker. Uplivra writes the commands that point it at the Access Control service:
- a check before you start;
- a local fallback login;
- a test from a new session;
- the way back.
Port access (MAB)
Devices that can't log in (printers, cameras, phones) are let onto access ports by MAC address, maker or the type Uplivra already found. Each kind can be put in its own VLAN. Start in monitor mode: nothing is blocked, and the log shows what would have been, so you can switch to enforcing with confidence. Laptops and phones can use 802.1X with certificates (EAP-TLS) instead, with the VLAN from your rules and Wi-Fi keys handed to the access point. RadSec carries RADIUS over TLS, port sessions let you disconnect or recheck a device (change of authorization), and you can import your devices from ISE, ClearPass or NPS keeping their shared secrets.
Keeps working when a link is down
Put an Access Control node at each site: a small Linux or Windows machine that answers your devices from a signed copy of the rules. Logins keep working when the main Uplivra server, or the link to it, is down. Two nodes make a pair that share everything (the log, the newest rules, each other's health) over mutual TLS: HTTPS across sites, a direct encrypted link in the same site. Each node keeps its own encrypted store, and the main server stays the one place you change rules and read the log. Nodes are included at no extra cost. How nodes work
One node answers about 20,000 TACACS+ command checks or 400 full 802.1X certificate logins a second on 2 CPU cores, far more than a small or mid-size business needs. The second node is for staying up. Sizing
See it, prove it
- Dashboard: success rate, response times, failures by reason, person and device, and devices sending with the wrong key.
- Findings: failed logins followed by an admin login, admin logins from a new address, logins from two sites at once, unusual hours. Each is marked informational, suspicious or high risk; findings alert people and never block anyone by themselves.
- Records for audits: the log is kept for a year by default (PCI DSS 10.5.1), searchable and exportable. Admin sessions through Uplivra's browser terminal are recorded command by command, and can be flagged, blocked or ended live.
Built in, not bolted on
Uplivra's TACACS+ and RADIUS servers are Uplivra's own code, written from the standards (RFC 8907, 2865 and 2866). RADIUS requires Message-Authenticator by default, so it's protected against the Blast-RADIUS attack. Shared keys are random and different for every device, and stored encrypted. Device passwords can live in the Secrets vault and change on a schedule.
Pricing
$5 per network device per month: each switch, router, firewall or controller that asks Uplivra. People, endpoints and ports don't count. See pricing · Read the guide
Other modules
Core monitoring
Availability, services, SNMP and websites, with alerts people act on
$2.00 → $1.00 per device per month, graduated. Free for up to 15 devices; from the 16th, every device is billed. $25 a month minimum; 15% off when paid yearlyNetwork Pro
Ports, network map and traffic flows on every device
+$2 per device per monthLog Intelligence
Collect, search and keep every log, encrypted and tamper-evident
$299–$1,799 per year by monthly volume (price and plan sizes under review)Upgrade & Lifecycle
Firmware, end-of-life dates and upgrades with proof they worked
$2 per device per monthCompliance & Evidence
Controls tested every day, evidence ready for the audit
$5 per device per monthPacket Capture
Record all the time, pull the moment it went wrong
$499 per capture collector per year: 1 SPAN port, up to 1 GbpsITSM Integration
Changes, approvals and incidents in the ticketing system you already use
$1 per device per month (price under review)Vulnerability Scanning
Know which boxes are exposed, and who owns the fix
$5 per device per monthNative Service Desk
A help desk linked to your devices and alerts
$5 per help desk agent per monthUplivra Intelligence
Ask your network what's wrong, in plain words
$1,599 per year, one flat rate for any number of devices (free for the first 6 months on new installations) (price under review)Automation & Remediation
Runbooks for the routine fixes, with approval when you want it
$1 per device per month (price under review)MSP multi-tenant
Every customer in one console, and a router to reach them
$49 per month plus $5 per customer (price under review)PCI CDE Monitoring
Monitoring built for the cardholder data environment
$4 per card-environment system per month, $49 minimum (price under review)