FRAMEWORK FOR ADVANCED NETWORK TOOL ACCESS CONTROL (eNAC)
A database with disabled MAB entries and a MAB rescue service temporarily enable non-802.1X devices for validation, addressing MAC spoofing vulnerabilities and improving network access security and resilience.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- GM GLOBAL TECHNOLOGY OPERATIONS LLC
- Filing Date
- 2019-05-29
- Publication Date
- 2026-05-21
AI Technical Summary
Existing network access controls using MAC addresses are vulnerable to MAC spoofing, allowing unauthorized devices to gain access by mimicking the MAC address of authorized devices, necessitating enhanced security measures to prevent such fraudulent access.
Implement a database with all MAB entries initially set to disabled or expired states, using a MAB rescue service to temporarily enable non-802.1X-enabled devices for a predetermined period, and validate their access requests with RADIUS authentication, ensuring only authorized devices can connect and track their precise network location.
Prevents unauthorized access by temporarily enabling non-802.1X-enabled devices, enhancing security against MAC spoofing while improving ease of access, redundancy, and facilitating disaster recovery.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
INTRODUCTION
[0001] The present invention relates to network access controls and in particular to security problems related to IEEE 802.1X authentication.
[0002] In this regard, reference is made at this point to the publications US 2012 / 0 216 239 A1 and US 2009 / 0 271 851 A1 for general background information.
[0003] For businesses of all sizes, it is common to use MAC (Media Access Control) address registration as a network access control mechanism, since MAC addresses act as unique identifiers for each device's network interface controller (NIC). MAC addresses thus provide a degree of control over which devices can authenticate to and / or access resources on a given network. However, while MAC addresses are unique identifiers, this is often not the case in practice due to the increasing trend of MAC spoofing. This means that the MAC address of a known and authorized device, such as a printer, scanner, or similar device, can be copied and associated with a completely different device that an attacker might want to introduce into the network.By copying and using the MAC address of a known resource on the network, an attacker can grant their own device full network access. While typical network access controls that use 802.1X security protocols in combination with MAC address registration function as intended, there is a need in the field for new and enhanced network access controls and a control framework that effectively eliminates the potential for MAC spoofing in a MAC-based or MAC authentication bypass-based access control framework (MAB-based access control framework), while improving features for ease of access, redundancy, fault tolerance, and disaster recovery. SUMMARY
[0004] According to the invention, a method for providing extended network access control (eNAC) for a network that uses IEEE 802.1X authentication standards is presented, characterized by the features of claim 1.
[0005] The procedure includes the following: using a database with a large number of Media Access Control (MAB) authentication entries; setting all MAB entries in the database and all new accounts added to the database to a disabled or expired account state; using a MAB recovery application to change the MAC address account state for a non-802.1X-enabled device to an enabled or non-expired account state for a predetermined period of time. The procedure further includes connecting the non-802.1X-enabled device to the network using a Media Access Control (MAC) address for the non-802.1X-enabled device as a unique device identifier, and using a network switch to connect the non-802.1X-enabled device to the network.To request authentication from a non-802.1X-enabled device, the device's MAC address is sent to a Remote Authentication Dial-In User Service (RADIUS) client for authentication against known records. Within the RADIUS client, a connection request generated by the non-802.1X-enabled device connecting to the network is processed. After validating the connection request and determining its validity, the RADIUS device sends a permission validation to the network switch, granting access to the non-802.1X-enabled device. The procedure further includes allowing endpoint authentication of the non-802.1X-enabled device.1X-enabled device during the predetermined time period and preventing unauthorized endpoints (“Rogue Endpoints”) from accessing the network by ensuring that all MAB entries and new accounts in the network are in a disabled or expired account state.
[0006] In another aspect of the present invention, the method for providing an eNAC further includes: determining a precise network location of the non-802.1X-enabled device relative to a previous network position of the non-802.1X-enabled device within a predetermined period of time.
[0007] In yet another aspect of the present invention, the method for eNAC further includes determining an exact network position for each MAB-capable device in the network.
[0008] In yet another aspect of the present invention, the method for eNAC further includes generating an inventory of active MAB ports.
[0009] In yet another aspect of the present invention, the use of a MAB rescue service further includes using the MAB rescue service to enable authorized users to query the status of a MAB-based client access status; and selectively enabling access for the MAB-based client for a predetermined period.
[0010] In yet another aspect of the present invention, a method for eNAC further includes using the MAB rescue service to address client access problems at the facility level; and selectively and securely enabling or not expiring accounts and addressing client access problems at the facility level for a predetermined period.
[0011] In yet another aspect of the present invention, the use of a MAB rescue service further includes the automatic selective activation or non-expiration of accounts for high-priority MAB-based clients for a predetermined period.
[0012] In yet another aspect of the present invention lies the variable predetermined period between about five minutes and about one hour.
[0013] In yet another aspect of the present invention, the automatic selective reactivation or non-expiration of access to high-priority MAB-based clients further includes the reactivation or non-expiration of accounts for physical security clients and physical safety clients at a facility where physical security clients and physical safety clients have been disconnected from the network.
[0014] According to the invention, a system for providing extended network access control (eNAC) for a network is further presented, wherein the system is characterized by the features of claim 10.
[0015] Specifically, the system comprises the following: an account database connected to the network that stores user accounts, wherein, for each of a multitude of network-enabled client devices, each user and network-enabled client device account is set to a disabled or expired state by default, and wherein at least one of the multitude of network-enabled devices is non-802.1X-enabled; and a network-connected Media Access Control Authentication Bypass (MAB) recovery service, wherein the MAB recovery service temporarily and selectively enables or prevents accounts in the account database from expiring for the non-802.1X-enabled devices, wherein the non-802.1X-enabled device is connected to the network and selectively generates access requests to gain access to network resources. The MAB recovery service temporarily prevents non-802.1X-enabled devices from expiring.1X-enabled devices are used for authentication within a predetermined time window, and unauthorized endpoints are prevented from accessing the network by ensuring that all MAB entries and new accounts on the network are in a disabled or expired account state.
[0016] In yet another aspect of the present invention, the selective temporary activation or expiration of accounts further includes determining a precise network location of the non-802.1X-enabled device relative to a previous network position of the non-802.1X-enabled device within a predetermined period of time.
[0017] In yet another aspect of the present invention, the selective temporary activation or expiration of accounts further includes activating or not expiring an account for a non-802.1X-enabled device during the predetermined time window, and when the non-802.1X-enabled device is authenticated to the network, deactivating the account for the non-802.1X-enabled device.
[0018] In yet another aspect of the present invention, the MAB rescue service determines an exact network location of each MAB-enabled device in the network and generates an inventory of active MAB ports.
[0019] In yet another aspect of the present invention, the MAB rescue service includes an interface that allows authorized users to query the status of an MAB-enabled client.
[0020] In yet another aspect of the present invention, the MAB rescue service includes an interface that enables authorized users to detect MAB-enabled client access problems at the facility level; and to selectively and securely enable or prevent accounts from expiring and address client access problems at the facility level for the predetermined time window.
[0021] In yet another aspect of the present invention, the interface further includes settings for automatically and selectively activating or not expiring accounts for MAB-enabled clients of high priority for a predetermined time window.
[0022] In yet another aspect of the present invention, the settings for automatically selectively reactivating or not expiring access to high-priority MAB-based clients further include reactivating or not expiring accounts for physical security clients and physical safety clients at a facility where physical security clients and physical safety clients have been disconnected from the network.
[0023] In yet another aspect of the present invention, the predetermined time window lies between approximately fifteen minutes and approximately one hour.
[0024] In yet another aspect of the present invention, the predetermined time window has an accuracy of approximately one second.
[0025] In yet another aspect of the present invention, a method for providing extended network access control (eNAC) for a network using IEEE 802.1X authentication standards includes: using a database with a plurality of entries for media access control authentication (MAB); setting all MAB entries in the database and all new accounts added to the database to a disabled or expired account state; and using a MAB rescue application to change the account state for a non-802.1X-enabled device to an enabled or unexpired account state for a predetermined period of time. The method further includes connecting the non-802.1X-enabled device to the network using a media access control (MAC) address as a unique device identifier.The procedure further includes validating the access request by determining an exact network location for each MAB-enabled non-802.1X-enabled device relative to previous network locations for the non-802.1X-enabled device within a predetermined time period, and after validating the access request and determining that the access request is valid, allowing endpoint authentication of the non-802.1X-enabled device during the predetermined time, resetting a MAB entry for the non-802.1X-enabled device to the disabled or expired account state in the database as soon as either the non-802.1X-enabled device is no longer valid.1X-enabled device has successfully authenticated the network or the predetermined time period has elapsed; and preventing unauthorized endpoints from accessing the network by ensuring that all MAB entries and new accounts on the network are in a disabled or expired state.
[0026] Further areas of application will become apparent from the description given herein. It is understood that the description and the specific examples serve only for illustrative purposes. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] The drawings described herein serve only for illustration purposes. Fig. Figure 1 is a schematic representation of a network system according to one aspect of the present invention; and Fig. Figure 2 is a flowchart of a method for advanced network access control for a network according to one aspect of the present invention. DETAILED DESCRIPTION
[0028] The term “computer” or “server”, as used herein, generally includes any electronic control device comprising a pre-programmed digital computer or processor, memory or non-transient computer-readable medium capable of storing data such as control logic, software applications, instructions, computer code, software or applications, data, lookup tables, etc., and a transceiver [or input / output ports].
[0029] Computer-readable medium includes any type of medium accessible by a computer, such as read-only memory (ROM), random-access memory (RAM), a hard disk drive, a CD (Compact Disc), a DVD (Digital Video Disc), or any other type of storage. Non-transient computer-readable medium excludes wired, wireless, optical, or other communication links that carry transient electrical or other signals. Non-transient computer-readable medium includes media capable of storing data permanently and media capable of storing data and later overwriting it, such as a rewritable optical disc or an erasable storage device. Computer code, software, or applications include any type of program code, including source code, object code, and executable code.The processor is configured to execute the code or instructions. In some examples, the computer or server also includes a dedicated Wi-Fi controller configured to communicate wirelessly with wireless communication points using the Wi-Fi protocols under IEEE 802.1X.
[0030] The computer or server also includes one or more applications. An application is a software program configured to perform a specific function or set of functions. The application may include one or more computer programs, software components, sets of instructions, procedures, functions, objects, classes, instances, related data, or a portion thereof designed for implementation in suitable machine-readable program code. Applications may be stored in the computer's main memory or in additional or separate memory. Examples of applications include audio or video streaming services, games, browsers, social media platforms, network management systems, directory access and management systems, and the like.
[0031] The following description is merely exemplary.
[0032] With reference to Fig. Figure 1 shows a network access control system, generally referred to by reference numeral 10. The network access control system 10 can be used with a wide variety of public and / or private network systems. The network access control system 10 selectively provides access to a network 12 through a variety of network-enabled devices 14. In some examples, the network-enabled devices 14 are connected to the network via IEEE 802.1X authentication standards. 802.1X authentication generally involves three parties: a requesting participant or device 16, an authenticator 18, and an authentication server 20.The requesting participant 16 is a client or client device, such as a desktop computer 22, a laptop 24, a personal data assistant (PDA), a tablet computer 26, a cellular device such as a smartphone, a network-enabled printer 28, or the like. The requesting participant 16 generates a request to join the network 12. In some examples, the network 12 is a local area network (LAN) or a wireless local area network (WLAN). In other examples, the requesting participant 16 is computer software running on a client device, such as one of the aforementioned desktop computers 22, a laptop 24, a personal data assistant (PDA), a tablet computer 26, a cellular device such as a smartphone, a network-enabled printer 28, or the like. The requesting participant 16 provides credentials to the authenticator 18.The authenticator 18 is a network device, such as an Ethernet switch, a wireless access point, or the like. The authentication server 20 is typically a host device, such as a network server or other such devices. The authentication server 20 uses computer software that supports Remote Authentication Dial-In User Service (RADIUS) and / or Password Authentication Protocol (PAP), Challenge-Handshake Authentication Protocol (CHAP), Extensible Authentication Protocol (EAP), or the like. The RADIUS service provides centralized authentication, authorization, and billing management for users who connect to and use a service on the network 12.
[0033] In some cases, the computer software of the authentication server 20 can run on the device hardware of the authenticator 18. The authenticator 18 acts as a security barrier for a protected network 12. The requesting participant 16 is prevented from accessing the network 18 via the authenticator 12 until the identity of the requesting participant 16 has been validated and verified. That is, until the login credentials of the requesting participant 16 have been validated and authorized, the authenticator 18 prevents the requesting participant 16 from accessing a protected page 28 of the network 12, including routers 30, intranet and internet sites 32, and the like. Using port-based 802.In 1X authentication, the requesting participant 16 provides credentials, such as a username / password or a digital certificate, to the authenticator 18, and the authenticator 18 forwards the credentials to the authentication server 20 for verification. If the authentication server 20 determines that the credentials are valid, the provider 16 is permitted to access resources located on the protected side 28 of the network 12.
[0034] However, in some cases, it must be possible for requesting subscriber devices 16 that are not capable of 802.1X Network Access Control (NAC) to connect to a given network 12. In large networks 12, non-802.1X NAC-enabled devices 16 are quite common. Such non-802.1X NAC-enabled devices 16 can include conventional devices, some printers, fax machines, VoIP phones, door locks, and other physical access control devices within a physical building, and the like. Therefore, targeted loopholes must be created in the 802.1X authentication requirements of the network 12 to allow non-802.1X NAC-enabled devices 16 to connect to the network. The non-802.1X-NAC capable devices 16 are then registered with the network 12 by individual Media Access Control (MAC) addresses via a process known as Media Access Control Authentication Bypass or “MAB”.Since, at least theoretically, the MAC address of a particular device 16 is a unique identifier for that particular device 16, using the MAC address of a particular device 16 to authenticate that device 16 to the network 12 provides a network access control mechanism. To determine the validity and authenticity of access requests for non-802.1X NAC-enabled devices 16, the authentication server 20 includes a database 34 with the accounts "A", "B", "C", and "D", and so on; each account "A", "B", "C", and "D" is associated with a particular device 16. In the example from... Fig. Account 1 is assigned to desktop computer 22, account 22 to tablet computer 26, account 28 to network printer 28, and account 24 to laptop computer 24. However, it should be noted that database 34 may contain fewer or a much larger number of accounts than in Fig. Figure 1 illustrates this. Furthermore, the accounts can represent a wide variety of devices 16 and / or users not specifically described herein. In some examples, however, the MAC addresses are modifiable in software or firmware. Consequently, a MAC address for a particular part of the device 16 hardware may be incorrectly or erroneously assigned to a different device of the requesting subscriber 16. In other words, MAC addresses can be spoofed. Because MAC addresses can be changed in software or firmware for a wide variety of network-enabled devices 16, the use of MAC addresses to register non-802.1X NAC-enabled devices 16 creates a vulnerability in the 802.1X security of the network 12.The security backdoor can be used by an unauthorized system or user to fraudulently access the network using the MAC address of a valid networked device 16. Fraudulent access can be achieved in at least two ways: either by removing the valid networked device 16 from the network authenticator switch 18, or by connecting it to a different networked switch 18 using the same MAC address as the valid networked device 16.
[0035] With reference to Fig. 2 and with continued reference to Fig.Figure 1 shows an extended network access control (eNAC) procedure for network 12, generally indicated by reference numeral 100. The procedure begins at block 102, where all MAB database entries in database 34 are placed in a disabled or expired account state, and where any new accounts added to network 12 via database 34 are also placed in a disabled or expired state. In several aspects, the disabled account state includes disabling predetermined communication ports to prevent unauthorized or otherwise undesirable access by the new accounts or by devices of requesting participants 16 using MAB to access network 12.
[0036] At block 104, a non-802.1X-enabled device 16 requests access to network 12 using the MAC address of device 16 as a unique identifier. At block 106, an 802.1X-enabled network switch 18 requests authentication for the access request from the non-802.1X-enabled device 16. At block 108, upon receiving and identifying a lack of 802.1X capability in the non-802.1X-capable device 16, the network switch 18 sends the MAC address of the non-802.1X-capable device 16 to a RADIUS service 20 hosted on the authenticator 18, the authentication server, or both, for authentication purposes. The RADIUS service processes the access request generated by the non-802.1X-capable device 16's attempt to connect to the network 12 by querying database 34 at block 110 for a user ID and password provided by the non-802.1X-capable device 16.In some aspects, database 34 is an LDAP (Lightweight Directory Access Protocol) system, a directory server like an Active Directory server, a nameserver, or similar systems that access and manage distributed directory information services over an IP (Internet Protocol) network 12. In an example where the MAC address is used as a unique identifier for a particular non-802.1X-enabled device 16, the MAC address acts as both the user ID and password. At block 112, endpoint authentication for the requesting subscriber's device 16 by the RADIUS service fails because the MAB database entries and the new account entries at block 102 have been set to a disabled state. That is, since the MAB database entry for the non-802.1X-enabled device...If the 802.1X-enabled device 16, which requests access, is set to "disabled" or "expired," the RADIUS service rejects the connection authorization request, and the port of network switch 18, which would otherwise have granted network 12 access to the non-802.1X-enabled device 16, remains disabled or expired. Therefore, in block 112, the non-802.1X-enabled device 16 is still unable to connect to network 12.
[0037] Block 114 uses a MAB rescue service hosted on a MAB rescue server to manage the account status MAC records of Devices 16 and to activate MAB entries or accounts for a predetermined duration, time window, or period "T". In several aspects, the MAB rescue service is a computer software application that runs on a variety of computer hardware and allows authorized personnel to access MAB database entries. In some aspects, the MAB rescue service is hosted on the hardware of Authenticator 18, Authentication Server 20, or both. In other aspects, the MAB rescue service is hosted on a distributed computing platform or a cloud computing platform, providing ubiquitous access to authorized users who need access to the MAB rescue service.The predetermined time period “T” can vary according to the type of non-802.1X-enabled device in question, as well as the nature of the specific network system on which the non-802.1X-enabled device is to be used. In one example, the predetermined period “T” is in the range of up to approximately 120 hours. In another example, the predetermined period “T” is between approximately five minutes and one hour. In yet another example, the predetermined period “T” is between approximately fifteen minutes and forty minutes. In still another example, the predetermined period “T” is between approximately twenty and approximately thirty minutes.Although the predetermined period “T” has been described as being in the range of up to approximately 120 hours, it is understood that, depending on the type of device 16 involved, the circumstances of the access request, the location, the failure conditions, and the like, the predetermined period “T” may differ significantly from the ranges specified above. In any case, after the predetermined period “T” has elapsed, the device 16 for which the account was enabled or has not expired (in this example, account “C”) will be prevented from accessing network 12, as the account will be automatically reset to the disabled or expired state. By using the account expiration date attribute in the account for a given MAC address in database 34, a high degree of time-based accuracy can be achieved.This means that the expiration of the predetermined period "T" can be set with an accuracy of approximately one second, with a unique expiration date or time for each individual MAC address account in database 34. Accordingly, no account cleanup is required, and no additional or secondary databases are needed to track the desired expiration dates or times for MAC accounts. Furthermore, no additional load is generated on the servers of directory 34, as no account-level changes are required to place the account in a disabled or expired state when the predetermined period "T" set in the MAB rescue service expires.
[0038] In Block 116, some aspects of the MAB recovery service are accessible to authorized personnel via an administration console (not specifically shown). The administration console can be a web-based interface, a virtual machine, or a server interface on the LAN, WLAN, or more generally, a local intranet or similar. An authorized person with access to the MAB recovery service for eNAC is someone authorized to perform IT support functions within a given network infrastructure. In some examples, the authorized person might be a field technician at a site where the use of the MAB recovery service is required to reconnect the devices 16 to the network 12.In other examples, the authorized person may be someone located remotely who modifies the MAB database entry information in response to a variety of situations at physical locations distant from the authorized person. In some aspects, the variety of situations in which the MAB rescue service is used includes: emergency recovery situations, power outages, server or network failures, lifecycle management processes, installation of new equipment, maintenance, or the like. When the MAB rescue service is used to change an account status for a specific non-802.1X-enabled device 16 for the predetermined period "T", an endpoint device, such as a non-802.1X-enabled device 16, can authenticate using the device's unique MAC information and gain access to the network 12.However, once the device has authenticated with the network, the MAB entry or account for that specific device is automatically reset to the disabled state. Accordingly, if an unauthorized endpoint in block 118, such as a computer, server, or the like, operated by a person seeking to gain access to network 12 through MAC address spoofing, attempts to manipulate the MAC address of a valid endpoint device belonging to the requesting subscriber 16, such an attempt will fail. The attempt will fail because the MAB entry or account of the endpoint device belonging to the requesting subscriber 16 has already been reset to the disabled state. Once the MAB database entry or account of the valid requesting subscriber 16 has been reset to the disabled state, manipulation of the MAC address of the valid device 16 is prevented.
[0039] In one example, a power outage at a facility disconnects a large number of valid devices belonging to requesting subscriber 16 from network 12. While many of the requesting subscribers 16 are 802.1X-enabled and therefore automatically reconnect to network 12, authenticate, and gain access, certain other non-802.1X-enabled devices 16 must reconnect via MAB. A high-priority designation can be assigned to some of the non-802.1X-enabled requesting subscribers 16, while others do not. In some examples, the high-priority designation can be applied to physical security and physical safety devices, such as fire suppression systems, smoke detectors, door locks, and the like.In the MAB rescue service, devices from requesting participants 16 with a high priority designation can be automatically re-registered with the network 12, instead of an authorized person having to manually reactivate the accounts or database entries for each of the devices from requesting participants 16.
[0040] As a measure to enhance security regarding access by requesting participants 16 to the network 12 via MAB authentication rather than 802.1X, the MAB rescue service can also perform a variety of queries against database 34. In some embodiments, the queries against database 34 include historical location information, online time information, and the like. In the example of queries against database 34 for historical location information, the MAB rescue service can determine whether the MAC address of a particular requesting participant 16 has moved between a known previous location on the network 12 and a current location where the requesting participant 16 is making an authentication request.In one example, if the distance traveled between previous and current locations of Network 12 is too great to be reached within a specific timeframe (a so-called "impossible" or "unrealistic" travel scenario) despite generating an otherwise valid authentication request, the MAB rescue service can selectively warn an authorized user of the MAB rescue service or deny them account status changes. In a second example, the lifecycle of a specific device of a requesting subscriber 16 is managed by selectively preventing access to that device when the device's age reaches a predetermined threshold.In the second example, the device management of the requesting subscriber 16's lifecycle device management can prevent or restrict the connection of known older and potentially more vulnerable hardware to network 12. Thus, the MAB rescue service can selectively prevent the activation of an account for a device of the requesting subscriber 16 beyond the predetermined lifecycle of that specific device of the requesting subscriber 16.
[0041] An enhanced network access control framework of the present invention offers several advantages, including a control framework that effectively eliminates the potential for MAC spoofing in a MAC or MAC authentication bypass (MAB)-based access control framework, while simultaneously improving the features for easy access, redundancy, fault tolerance and disaster recovery.
Claims
[1] Method for providing enhanced network access control (eNAC) for a network that uses IEEE 802.1X authentication standards, comprising: Using a database with a large number of entries for Media Access Control (MAB) authentication; Resetting all MAB entries in the database and all new accounts added to the database to a disabled or expired account state; Using a MAB rescue application to change the account status for a Media Access Control (MAC) address for a non-802.1X-enabled device to an enabled or non-expired account state for a predetermined period of time; Connecting the non-802.1X-enabled device to the network using the Media Access Control (MAC) address for the non-802.1X-enabled device as a unique device identifier; Allowing endpoint authentication of the non-802.1X-enabled device for the predetermined duration; and Prevent unauthorized endpoints from accessing the network by ensuring that all MAB entries and new accounts on the network are in a disabled or expired account state. [2] Method for eNAC for a network according to claim 1, further comprising: determining a precise network location of the non-802.1X-enabled device relative to a previous network position of the non-802.1X-enabled device within a predetermined period of time. [3] Method for eNAC for a network according to claim 2, further comprising: Determining an exact network position for each MAB-enabled device in the network. [4] Method for eNAC for a network according to claim 2, further comprising: generating an inventory of active MAB ports. [5] Method for eNAC for a network according to claim 1 wherein the use of a MAB rescue service further comprises: Using the MAB rescue service to allow authorized users to query the status of a MAB-based client access status; and Selective activation of access for the MAB-based client for a predetermined period. [6] Method for eNAC for a network according to claim 5, further comprising: Using the MAB recovery service to address client access problems at the facility level; and Selective and secure activation or non-expiration of accounts and addressing of client access problems at the setup level for a predetermined period. [7] Method for eNAC for a network according to claim 1, wherein the use of a MAB rescue service further comprises the automatic selective activation or non-expiration of accounts for high priority MAB-based clients for a predetermined period. [8] Method for eNAC for a network according to claim 7, wherein the variable predetermined period is between about five minutes and about one hour. [9] Method for eNAC according to claim 7, wherein the automatic selective reactivation or non-expiration of access to MAB-based clients of high priority further comprises the reactivation or non-expiration of accounts for Physical Security Clients and Physical Safety Clients at a facility where Physical Security Clients and Physical Safety Clients have been disconnected from the network. [10] System for providing enhanced network access control (eNAC) for a network, comprising: an account database that is connected to the network and stores accounts for users, wherein for each of a plurality of network-enabled client devices, each of the user and network-enabled client device accounts is set to a disabled or expired state by default, wherein at least one of the plurality of network-enabled devices is non-802.1X-enabled; and a network-linked Media Access Control Authentication Bypass (MAB) rescue service, wherein the MAB rescue service temporarily selectively enables or prevents accounts in the account database for the non-802.1X-enabled devices from expiring, each non-802.1X-enabled device being connected to the network and selectively generating access requests to gain access to network resources, where the MAB rescue service temporarily allows non-802.1X-enabled devices to authenticate within a predetermined time window and prevents unauthorized endpoints from accessing the network by ensuring that all MAB entries and new accounts on the network are in a disabled or expired account state.