Revolutionary protection for the
internal network

ARP-GUARD - mehr als Network Access Control

Into the future with security

Maintaining data protection is one of the highest demands on today's companies, because nobody wants to get a bad image by having data theft from the company reported in the press. More attention is still paid to protection against access from outside, although statistics repeatedly point out that the majority of espionage comes from the local network. This is where maximum protection must be offered, which can be implemented with minimal effort and without disrupting internal workflows. 

 A Network Access Control (NAC) solution supports the company in this task. ARP-GUARD is quick and easy to implement as it does not require any changes to the existing network structure. It independently learns the devices in the network and graphically displays an overview of the network with the existing switches and routers. 

lock-arp-guard_small.jpg
zuverlaessiger_schutz.png

ZUVERLÄSSIGER SCHUTZ

Reliable protection for internal LAN and WLAN access, as well as protection for Internet access, is provided by our security solution. Only authorized devices are granted access to your network by ARP-GUARD.

einfache_integration1.png

EINFACHE INTEGRATION

ARP-GUARD ist einfach und schnell zu implementieren, da es keine Veränderungen in der bestehenden Netzwerkstruktur benötigt. Es erlernt selbstständig die Geräte im Netzwerk und stellt eine Übersicht über das Netzwerk mit den vorhandenen Switchen und Routern grafisch dar. 

zentrale_verwaltung.png

CENTRAL ADMINISTRATION

Das zentrale Network Management System bietet eine umfassende Übersicht über alle Geräte in ihrem Netzwerk. Es erkennt jede Adress- oder Zuordnungsänderung, protokolliert diese und stellt alle Veränderungen dar.

Software modules

The individual ARP-GUARD modules at a glance
aufbau_module.png
access.png

Network access protection NAC

RADIUS / 802.1X /EAP with and without certificate, MAC based RADIUS, MAC authentication, user-defined set of rules, central dynamic port security system, guest system with self-registration.

accessplus.png

NAC & VLAN-Management

Beinhaltet Access, Abgrenzung von Netzwerksegmenten, Dynamische und statische Zuordnung, kryptografisches Fingerprinting, Gäste-System mit Selbstregistrierung.

finance.png

Layer 2 IPS & NAC

Beinhaltet Access, Schutz vor Layer 2 Angriffen, Schutz vor fremden und unbekannten Geräten, kryptografisches Fingerprinting, Gäste-System mit Selbstregistrierung.

premium.png

ALL in One

Includes Access+, VLAN management, cryptographic fingerprinting, protection against Layer 2 attacks, guest system with self-registration.

ARP-GUARD - der sichere Schutz für Ihr Netzwerk

With ARP-GUARD you gain complete access control to your network! New devices connected to the network are detected and reported in real time. Devices are uniquely identified using the MAC address or certificates (802.1X). Additional fingerprints, which are created when the devices are learned, increase the level of security. 


 ARP-GUARD thus enables protected and controlled access to the network. With user-defined or company-specific rules for access and security guidelines, you decide how unauthorized devices are handled. This can range from notifying the administrator by e-mail to automatically blocking unwanted devices or transferring them to special quarantine or guest VLANs.

Controlled and secure access to IT networks

Almost all internal company information is accessible via your local network. Existentially highly sensitive data of your company! Recipes, construction plans, contracts, patents. 

 ARP-GUARD ensures that users do not use unauthorized notebooks, smartphones or even wireless access points. Our software solution protects your IT infrastructure from third-party devices carrying malware and unwanted access to your intellectual property! Reliable protection for internal LAN and WLAN access as well as protection for Internet access is provided by our security solution. Only authorized devices are granted access to your network by ARP-GUARD! The protection of your network access is covered in real time as well as the monitoring, localization, detection and testing of newly connected devices. Unique identification of a device is a must. The MAC address or certificates (802.1X) are available here. 

 ARP-GUARD works independently of the manufacturer. You do not have to standardize or even renew your existing infrastructure. ARP-GUARD acts as a guardian and observer of your network, enforcing your specific set of rules - your security policy - from a central location throughout the company.

The ARP-GUARD variants

ARP-GUARD ist so aufgebaut, dass die einzigartige Architektur sowohl bei kleineren, mittleren als auch großen Unternehmen eingesetzt werden kann. Egal welche Größe das Unternehmen hat oder wie der Bedarf gelagert ist, existiert nur eine Management-Ebene, in der ARP-GUARD zentral verwaltet und administriert wird. Je nach Bedarf können Sensoren zur Lastverteilung oder zur Administration von externen Bereichen eingesetzt werden.

Hardware appliance

Im Rahmen der langjährigen Partnerschaft zwischen der Firma SECUDOS und der ISL sind spezielle Appliances für den ARP-GUARD entstanden - ein Bundle aus bewährter Hardware aus dem Hause SECUDOS und der ARP-GUARD Software. Diese Appliances werden mit vorinstallierter ARP-GUARD Software ausgeliefert und erleichtern Ihnen die Inbetriebnahme.

Virtual appliance

The virtual appliance is based on the DOMOS4 operating system and comes with a pre-installed ARP-GUARD instance. It can be set up intuitively within ten to fifteen minutes using the graphical user interface. The virtual ARP-GUARD appliance is available as a 64-bit version and supports VMware, Hyper-V and KVM.

ANY QUESTIONS? WRITE TO US!

ARP-GUARD Fingerprinting

The experts at ISL GmbH have developed a fingerprinting system with and for the ARP-GUARD, which first searches for keys/certificates on the end devices and saves these as a reference value in its database. If the identical device becomes active in the network again, a public key or certificate is downloaded from the end device again and compared with the reference value. If these do not match, the device is removed from the network. In principle, the same session hijacking attacks are possible with fingerprinting as with 802.1X, but here you can easily check other conditions (e.g. based on IP addresses). For end devices that do not support any cryptographic procedures, simple fingerprints can be used based on certain characteristics of the device, so that the security still goes far beyond the MAC address check. 

Fingerprinting is implemented in the ARP-GUARD product and is active in many corporate networks, including over 80 savings banks, which attach great importance to a particularly high level of security.

arp_guard_fingerprint.png

Request your personal

WEBINAR

Example setup with ARP-GUARD sensor

sensorgrafik_arp-guard

We are happy to help you with your questions

Talk to us

Please call us directly

+49 2307 28 50 53 0

or send us an e-mail
info@secudos.de
Image

SECUDOS protects your network with secure and powerful solutions. Reliable, flexible, innovative. We are your experienced partner for digital security, efficiency and compliance.

© 2025 • SECUDOS GmbH


We use cookies

We use cookies on our website. Some of them are essential for the operation of the site, while others help us to improve this site and the user experience (tracking cookies). You can decide for yourself whether you want to allow cookies or not. Please note that if you reject them, you may not be able to use all the functionalities of the site.