The Challenge

Managing Certificate-Based Authentication

Migrating from passwords or shared secrets to certificate-based authentication (e.g., EAP-TLS) is often difficult. It requires complex rules, certificate distribution, and managing user/device issues across platforms, a burden that weighs even heavier on lean IT teams.

Maintaining Availability And Scale

Traditional NAC appliances and RADIUS servers (e.g., NPS, FreeRADIUS) require complex configuration steps for redundancy, failover, and geographic scale. Maintaining on-premises infrastructure and software updates has also become costly and cumbersome, often leading to missteps.

Security That Doesn’t Hamper User Productivity

Zero Trust is often a complex and confusing initiative that is difficult for IT and users to grasp. Lean IT teams struggle to ensure strong authentication without hampering user productivity or minimizing security risk. Authentication must deliver a consistent experience and outcome that is seamless for all.

Key Benefits of Nile RADIUS Service

Complexity-free EAP-TLS support

A purpose-built and easy-to-rollout service that natively leverages core Nile Access Service features such as a simple UI, built-in authorization and enforcement, and per-device visibility.

Seamless authentication to authorization workflows

When access control is designed into your network fabric, it provides a single dashboard for everything needed to fingerprint devices, leverage a simple RADIUS Service for authentication, and take advantage of built-in authorization and enforcement capabilities.

Cloud availability and multi-site scale

Buying, distributing, and maintaining a cluster of appliances is replaced with a highly available cloud instance that scales up or down depending on your immediate needs. Lean IT teams no longer face the traditional interoperability and deployment challenges of the past

A predictable reachability model

Appliances that may be compromised, taken down for repair or software upgrades, or are no longer supported by the original vendor are eliminated. Reliable cloud access also means separate teams no longer need to perform changes or updates if virtual machines are used.

Simplified integration and operations

As-a-Service benefits include automated software updates, instant access to new features, and built-in Zero Trust capabilities with every Nile Access Service deployment, delivering time and resource savings that third-party NAC or cloud RADIUS add-ons can’t match.

Cloud-enhanced Zero Trust protection

Organizations of all sizes and types instantly gain cloud provider-enforced encryption, compliance, and access controls not available via on-premises appliances, which require manual intervention, unnecessary complexity, or an exhaustive strain on internal or external IT resources.

Simplicity Over Complexity

Authentication Without NAC Appliances

Once the Nile RADIUS Service is active, no manual tasks are required to begin. All transactions are secured automatically via gRPC tunnels. The sole configuration step is defining Policy rules. The Chaining of Policy rules even makes it easy to use existing identity stores or IdP and/or MDM solutions, and supports the following enhanced authentication requirement:

 

Rules based on Policy Chaining that include:

  • Intune compliance
  • SCIM for continuous authentication
  • A restricted access policy, right out of the box
  • RADIUS service monitoring
  • Device authentication visibility for easy troubleshooting

 

Because the Nile Access Service and Nile RADIUS are vertically integrated, the “Restricted Policy” will automatically quarantine a device that is not recognized. With a redesign of outdated legacy principles, Nile eliminates the need for third-party integrations and the complexity that comes with them.

 

 

 

 

How is the Nile RADIUS Service consumed?

A Nile Access Service Extension

While Nile integrates with a variety of existing solutions, the Nile RADIUS Service is simply added to a standard Nile Access Service subscription to completely offload the management of traditional RADIUS solutions (either those that reside in NAC appliances or in the cloud). It is designed for security-conscious customers and for lean IT teams that want to eliminate complexity and unpredictable budget hits.

Frequently Asked Questions

Why does Nile offer a cloud-based RADIUS option?

Nile customers can take advantage of our Core Trust Service features, such as per-device isolation, built-in authorization and policy creation, device fingerprinting, colorless ports, and a single point of management to eliminate complexity and the support of third-party NAC and RADIUS solutions.

Can I use the Nile RADIUS Service for a non-Nile Network?

The Nile RADIUS Service is designed to exclusively operate with the Nile Access Service as it utilizes.

Does Nile handle the distribution of Certificates onto endpoint devices?

Nile’s customers will continue to use their existing Certificate Authority (CA) to distribute and update certificates, such as Windows Servers and Group Policy Objects (GPOs) or MDM services such as Microsoft Intune.