PacketFence
iPhone + Android
in Network Access Control Software
- Recognised40% of the score94
- Phone app26% of the score100
- Documented20% of the score100
- Free plan14% of the score100
- Free plan
- Yes
- Paid plans from
- $416.67/mo
- Runs on
- Android, api, iPhone, Linux, Mac, self-hosted, Web, Windows
Summary
PacketFence is an enterprise network access control platform for organizations managing network access. It applies enforcement through SNMP or RADIUS, inline Layer 2 or Layer 3 deployment, VLAN assignment, and quarantine isolation. Authentication options include 802.1X/EAP, directory services, external RADIUS, OAuth2 social login, SAML 2.0, and PKI certificates. Guest access can include self-registration, sponsored access, email or SMS confirmation, and CSV imports. Device onboarding can configure 802.1X profiles for iOS, Android, Windows, macOS, and ChromeOS. The platform checks antivirus status, patch levels, and security-agent presence, and can quarantine devices that fail policy. The self-hosted Community Edition is GPL v2+ and includes unlimited devices and full source code. Listed minimum self-hosted requirements are Debian 12.x or RHEL 8.x, four CPU cores, 16 GB RAM, 200 GB of disk, and a network interface. PacketFence Cloud is managed without customer infrastructure and uses usage-based pricing. Paid plans start at $5,000/yr; a 30-day trial is listed.
Who it is for
PacketFence may suit organizations that need to control wired, wireless, or VPN access and enforce device security policies. The self-hosted edition may fit teams able to manage its listed server requirements.
What is good
- Supports wired, wireless, and VPN access control
- Can quarantine devices that fail policy
- Self-hosted edition includes unlimited devices and source code
- Cloud service does not require customer infrastructure
What to know first
- Self-hosted deployment requires at least 16 GB RAM
- Starter plan limits registered devices to 250
- Community Edition support is through community forums
Samsung Mobile US Press review
PacketFence: the full review
PacketFence offers several access-control and enforcement methods, with both self-hosted and managed cloud options. Review the deployment requirements and device limits associated with the plan you choose.
PacketFence is an enterprise network access control platform for organizations governing wired, wireless, and VPN access. It best suits IT and security teams that need device onboarding, guest access, and policy enforcement in one system. Its broad controls and unlimited-device open-source edition are appealing, but self-hosting requires substantial infrastructure and the paid tiers impose device and guest quotas.
Overview
PacketFence brings authentication, network enforcement, guest workflows, onboarding, and compliance checks together. Organizations can self-host the GPL v2+ edition, with full source code and community contributions, or choose PacketFence Cloud, which runs without customer infrastructure. The Community Edition's unlimited-device allowance is a notable advantage for organizations able to operate it themselves; it does not remove the need to provision and maintain a capable server.
Self-hosting calls for Debian 12.x or RHEL 8.x, four CPU cores, at least 16 GB of RAM, 200 GB of disk, and one network interface. That is a substantial starting footprint, so smaller teams without network administration capacity may be better served by the managed cloud option.
Key features
Enforcement and authentication
Administrators can enforce policies out of band through SNMP or RADIUS, or inline at Layer 2 or Layer 3, then assign VLANs or quarantine devices. Authentication spans 802.1X/EAP through FreeRADIUS, LDAP and Active Directory, external RADIUS, OAuth2 social login, SAML 2.0, and PKI certificates. This breadth is useful for organizations with mixed access methods and identity systems, though it also means PacketFence is best matched to teams prepared to configure network and authentication policies.
Guest access and device onboarding
Guest workflows include self-registration, sponsored access, email or SMS confirmation, password-of-the-day, payment integrations, and CSV bulk import. Self-service provisioning supports iOS, Android, Windows, macOS, and ChromeOS, including automatic 802.1X profile configuration. That combination can reduce manual handling of both visitors and employee devices; paid plans' annual guest quotas matter for organizations with frequent visitor turnover.
Compliance and security integrations
PacketFence checks antivirus status, OS patch level, and security-agent presence, and can quarantine devices that fail policy. It can incorporate signals from FleetDM, osquery, SentinelOne, CrowdStrike, and Microsoft Defender, respond to Snort and Suricata alerts, and use Nessus, OpenVAS, and Rapid7 scan results to trigger violations and isolation. Integration breadth is a strength for teams coordinating NAC with existing security tools, but the platform's value depends on having policies and connected systems to act on those signals.
Administration and resilience
A web administration interface sits alongside command-line tools, a REST API, customizable captive portals, and Perl extension points. High availability uses active/active clustering, automatic failover, Galera synchronous multi-master replication, geographic distribution, and automatic recovery. These capabilities suit organizations that need flexible administration and resilient service, though they imply a more involved deployment than a basic access-control setup.
PacketFence Cloud avoids customer infrastructure, offers a 99.99% uptime SLA and local RADIUS caching during internet outages, and uses usage-based pricing. This is the more appealing route for teams that want managed operations, while self-hosting offers source access and unlimited devices at the cost of server responsibility.
Pricing
PacketFence uses a freemium model, with a 30-day trial and paid plans from $5,000 /year. Choose based on device counts, guest volume, and the support and deployment help your team needs.
| Plan | Price | What it includes |
|---|---|---|
| Community Edition | 0.00 USD per free | Free forever; GPL licensed, unlimited devices, full source code, community forum support, self-hosted. |
| Starter | $5,000 /year | Up to 250 registered devices, 2,500 guest devices/year, business-hours support, self-service onboarding. |
| Premium Support | $5,000 /year | Billed /server/year; 24/7 unlimited support, 1-hour urgent response SLA, yearly version upgrades, performance tuning. |
| Professional | $15,000 /year | Up to 1,000 registered devices, 10,000 guest devices/year, 24/7 Premium support, guided onboarding. |
| Professional Deployment | $20,000 per once | Starting price; architecture design and planning, production rollout assistance, legacy NAC migration, knowledge transfer. |
| Training Services | Starting prices | Basic $8,000; Standard $18,000; Advanced $30,000; remote delivery included. |
| Enterprise | Custom pricing | 10,000+ registered devices, unlimited guest devices, 24/7 Elite support with 1-hour response, white-glove onboarding. |
Community Edition is the clear fit for organizations that can self-host and do not need paid support; unlike Starter and Professional, it has no device cap. Starter suits smaller managed deployments, but its 250 registered-device ceiling and 2,500 annual guest-device allowance can be restrictive. Professional raises those limits to 1,000 and 10,000 respectively and adds 24/7 Premium support and guided onboarding. Premium Support is a separate per-server support choice rather than a device-quota tier. Larger deployments can seek Enterprise custom pricing, while the one-time Professional Deployment package addresses rollout and migration work rather than ongoing licensing.
Platforms
PacketFence supports Android, iOS, Linux, macOS, Windows, web, API, and self-hosted deployments. Its wired, wireless, VPN, and 802.1X controls make it relevant to organizations managing both endpoint onboarding and network access across those environments.
Who it's for
PacketFence is a strong choice for organizations that need varied enforcement and authentication options, guest and BYOD workflows, and compliance-driven isolation, especially when they can connect it to existing security and network systems. Self-hosting favors teams with the infrastructure and operational capacity to run the required server. Teams that want to avoid customer infrastructure can consider PacketFence Cloud; its managed model and uptime SLA address operational concerns, though its usage-based pricing calls for attention to consumption.
Pros and cons
- Pro: The Community Edition has unlimited devices and full source code, giving capable self-hosting teams flexibility without a device cap.
- Pro: Multiple enforcement and authentication methods cover wired, wireless, and VPN access alongside varied identity systems.
- Pro: Guest workflows, self-service onboarding, compliance checks, and security integrations extend policy control beyond basic network admission.
- Pro: PacketFence Cloud includes a 99.99% uptime SLA and local RADIUS caching for internet outages.
- Con: Self-hosting requires a supported Linux server with four CPU cores, 16 GB RAM, and 200 GB disk, a significant commitment for smaller teams.
- Con: Starter and Professional cap registered devices and annual guest devices, so organizations with higher volumes need a different tier.
- Con: The range of controls and integrations is most useful when an organization has the expertise and connected systems to configure and act on them.
Alternatives
For a broader comparison, browse Network Access Control Software or Network Provisioning Software.
- Portnox NAC is another freemium NAC option with a free trial; consider it when its passwordless authentication and continuous risk assessment and remediation match your priorities.
- SecureW2 Cloud NAC is a paid alternative with quote-based pricing; consider it when you prefer to request a quote based on solution type, organization type, and device count.
- FortiNAC is another paid NAC option.
- Genian NAC is a freemium alternative with a free trial and cloud-managed or AWS cloud deployment options; consider it if those deployment choices suit your organization.
- ExtremeControl is a paid option from Extreme Networks.
- NACVIEW offers a free NV-20 lifetime licence for one entity, capped at 20 simultaneously authorized endpoint devices; consider it for a small deployment that fits that limit.
- NetAttest EPS is another paid NAC option.
- NACIO is another paid NAC option.
Verdict
Choose PacketFence if your organization needs broad network access enforcement, onboarding, guest handling, and compliance controls, and can either operate its self-hosted infrastructure or budget for a managed service. Its strongest draw is the combination of extensive controls and an unlimited-device open-source edition. Look elsewhere if your team cannot support the self-hosted requirements and the paid device and guest limits do not fit your scale.
PacketFence plans and pricing
All plansCompared on network access control software
- Free plan
- Yespacketfence.com
- Wired access control
- Yespacketfence.com
- Wireless access control
- Yespacketfence.com
- VPN access control
- Yespacketfence.com
- 802.1X support
- Yespacketfence.com
- Deployment model
- hybridpacketfence.com
- Device limit
- 250 devicespacketfence.com
Facts
- Product type
- PacketFence is an enterprise network access control platform that secures network access for organizations.packetfence.com · 1 Oct 2026
- Enforcement
- It supports out-of-band SNMP or RADIUS enforcement, inline Layer 2 or Layer 3 deployment, VLAN assignment, and quarantine isolation.packetfence.com · 1 Oct 2026
- Authentication
- Authentication includes 802.1X/EAP through FreeRADIUS, LDAP and Active Directory, external RADIUS, OAuth2 social login, SAML 2.0, and PKI certificates.packetfence.com · 1 Oct 2026
- Guest and BYOD
- Guest workflows include self-registration, sponsored access, email or SMS confirmation, password-of-the-day, payment integrations, and CSV bulk import.packetfence.com · 1 Oct 2026
- Device onboarding
- Self-service device provisioning supports iOS, Android, Windows, macOS, and ChromeOS with automatic 802.1X profile configuration.packetfence.com · 1 Oct 2026
- Compliance controls
- PacketFence checks antivirus status, OS patch level, and security-agent presence, and can quarantine devices that fail policy.packetfence.com · 1 Oct 2026
- Security integrations
- It integrates compliance signals from FleetDM, osquery, SentinelOne, CrowdStrike, and Microsoft Defender, and responds to Snort and Suricata alerts.packetfence.com · 1 Oct 2026
- Vulnerability scanners
- Scanner integrations include Nessus, OpenVAS, and Rapid7, with scan results able to trigger violations and device isolation.packetfence.com · 1 Oct 2026
- Administration
- The platform provides a web administration interface, command-line tools, a REST API, customizable captive portals, and Perl extension points.packetfence.com · 1 Oct 2026
- High availability
- High availability uses active/active clustering, automatic failover, Galera synchronous multi-master replication, geographic distribution, and automatic recovery.packetfence.com · 1 Oct 2026
- Open source
- The self-hosted edition is GPL v2+, has unlimited devices and full source code, and is developed and maintained by Akamai with community contributions.packetfence.com · 1 Oct 2026
- Deployment requirements
- Self-hosted PacketFence lists Debian 12.x or RHEL 8.x, four CPU cores, 16 GB RAM minimum, 200 GB disk, and at least one network interface.packetfence.com · 1 Oct 2026
- Cloud service
- PacketFence Cloud is managed without customer infrastructure, offers a 99.99% uptime SLA, local RADIUS caching for internet outages, and usage-based pricing.packetfence.com · 1 Oct 2026
Company
- Founded
- 2005packetfence.com · 28 Sept 2026
- Headquarters
- Cambridge, Massachusetts, United Statespacketfence.com · 28 Sept 2026
Best PacketFence alternatives
See all 17Where it ranks on Samsung Mobile US Press
Is PacketFence yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- packetfence.com/features/· checked 1 Oct 2026
- packetfence.com/community/· checked 1 Oct 2026
- packetfence.com/self-host/· checked 1 Oct 2026
- packetfence.com/cloud/· checked 1 Oct 2026
- packetfence.com· checked 28 Sept 2026
- packetfence.com/pricing/· checked 1 Oct 2026



