
Networks are intricate enough without introducing additional complexities and risk.
The Safe•Connect NAC solution allows you to create and manage network access policies while retaining your current infrastructure. Its ingenious architecture design integrates simply and easily into your network, providing a framework to implement and manage your specific IT endpoint security policies on user access security, anti-virus and anti-spyware protection, patch maintenance levels, NAT’d access points, and peer-to-peer file sharing.
Safe•Connect is vendor-independent and will work in any heterogeneous network environment. Connecting remote offices and locations to manage LAN (network) access policies from a central point is now plug-and-play. There are no forklift upgrade requirements – no need to expend additional funds to standardize hardware across office locations.
Safe•Connect is also scalable – allowing you to manage thousands of endpoint users with a single appliance.
The result is a more secure, reliable, and predictable IT network
infrastructure that is easy and cost-effective to deploy and maintain. 
NAC
and ROI 
A Business Case for Network Access Control
CLICK HERE to Learn More
and Use Our NAC ROI Calculator
The Safe•Connect Policy Enforcer is a pre-configured hardware and software appliance bundle. It is installed on the customer's premises and connected to an organization’s existing Layer3 switch/router in an out-of-line network fashion. A single Policy Enforcer can manage network access policies for more than 10,000 endpoint devices. The entire system is managed locally by the organization through the Safe•Connect Policy Management Console.
The Safe•Connect Policy Management Console is a centralized web-based portal that allows authorized users (typically a policy administrator) to set the acceptable use standards the Policy Enforcer will implement. Administrators can select from a series of pre-configured policies on authentication, anti-virus or anti-spyware protection, patch maintenance levels, and peer-to-peer file sharing, or create their own using the custom policy builder module. Network access can also be managed by group or location, or based on roles users occupy within the organization. For example, policies can be set for a particular building (i.e., residential dorm or remote office), a specific department (i.e., research or accounting), or by role (i.e., vendor, staff, student, or guest).
The Policy Management Console also displays real-time policy status reporting to provide valuable insight into group or individual policy compliance. User Support Specialists can quickly ascertain the security posture and network access condition of any device on the network by searching IP, MAC Address, or User Name. Granular historical database reporting is also availble for trending analysis, compliance auditing, and archiving.
Organizations can completely customize the look and feel of the policy notification web pages to match company marketing efforts and enhance the end user experience.
The Policy Key is a lightweight software application that ensures the end user is in compliance with an organization’s access policies. The Safe•Connect system recognizes when a computer is not running a Policy Key and redirects the unknown device to a captive registration portal where the user can download a Policy Key, if desired by the organization.
The Policy Key is extremely lightweight and can be installed either individually upon first connection to the local network or pre-distributed to all managed devices using standard software distribution methods. The Policy Key communicates frequently with the Safe•Connect system to validate security posture and receive policy updates. If the Policy Key is uninstalled or disabled, the Policy Enforcer appliance will immediately disallow network access until the end user is re-registered and a Policy Key is installed.
The Policy Key continually assesses the end user's computer for compliance with the following configurable security policies:
If an end user is not in compliance with an organization’s
network access policies, the Safe•Connect solution delivers individualized
remediation guidance and isolates the device from the network using Impulse
Point’s
I-LAN quarantine technology until the policy breach is resolved and the user
returns to a state of compliance.
Impulse
Point’s I-LAN quarantine technology isolates non-compliant endpoint devices
from accessing Layer2 and Layer3 network resources. I-LAN also limits end user
access to designated internal or Internet remediation domains, where it communicates
the actions required to become compliant with the organization’s security
policies and regain network access.
1. The Safe•Connect Policy Enforcer Appliance is installed out-of-line on the organization’s premises and is connected to an aggregation point.
2. The organization configures their desired policies and enforcement rules using the Safe•Connect Policy Management Console by network segment or directory services group.
3. Endpoint devices connecting to the network will be intercepted, authenticated, presented with the organization’s acceptable use policies, and issued a Safe•Connect Policy Key.
4. The Safe•Connect Policy Key certifies that the endpoint device adheres to endpoint security policies on a continuous/real-time basis. It reports non-compliance to the Safe•Connect Policy Enforcer and delivers individualized remediation guidance. The endpoint device remains completely isolated using I-LAN quarantine technology until the policy breach is resolved.
Safe•Connect offers consistent endpoint device support for wired, wireless, and VPN networks.

Safe•Connect is delivered as an operationally managed service. The health of the system is monitored from the Impulse Support Center and Impulse Point is responsible for delivering all necessary hardware and software maintenance, problem determination and resolution, and ongoing feature enhancement. The organization maintains full control of managing their desired endpoint computing policies and enforcement rules via the Safe•Connect Policy Management Console.
Click here to learn more about Impulse Point's Services.