iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A Network Access Server (NAS) is the device or system that gives a user or device access to a network or protected resource. In RADIUS deployments, the NAS is the access-side client: it asks a RADIUS server whether to admit a user, then enforces the answer. The name suggests a server, but in RADIUS terms the NAS is the client, not the server.
What a NAS does
The IETF defines the NAS in terms of its function rather than its hardware. RFC 5080 describes it as “the device providing access to the network,” and RFC 6158 describes it as “a device that provides an access service for a user to a network.” Both definitions focus on the access service itself. A NAS may provide a plain network connection, or it may provide a service layered on top of that connection.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Opengear OM1200 Operations Manager | $2,125.10 | Buy on Amazon |
| 2 |
|
Opengear OM1200 Operations Manager | $2,205.00 | Buy on Amazon |
| 3 |
|
Opengear CM7100 Series - Console Server | $1,595.00 | Buy on Amazon |
| 4 |
|
Juniper IC4500 Infranet Controller Chassis: Unified Access Control Base System | $1,224.69 | Buy on Amazon |
| 5 |
|
JINGCHENGMEI 1U Mini Rack Mount for Dell OptiPlex Micro Form Factor Case | $36.19 | Buy on Amazon |
Because the definition is functional, the same job can be done by very different equipment. The NAS role is set by what the device does during an access attempt, not by its product category.
The NAS is not the RADIUS server
RADIUS separates the device that receives the access request from the system that decides whether to grant it. RFC 2865, the RADIUS authentication and authorization specification published in 2000, describes the NAS as the party that sends an Access-Request. The RADIUS server replies with Access-Accept, Access-Reject, or Access-Challenge. The NAS then carries out that result.
#1 Best Overall
- Serial Ports: 8x RJ-45 ports for console access
- Ethernet: 2x Gigabit Ethernet connections
- Processor: AMD GX-412TC quad-core CPU
- Form Factor: 1U short-depth rack-mount design
- Security: Supports SSH, VPN, and firewall
| Role | What it does | Relationship in the exchange |
|---|---|---|
| Network Access Server (NAS) | Receives the connection attempt, sends the authentication or authorization request, and grants or denies access | Initiates the request (RADIUS client) |
| RADIUS server | Evaluates authentication and authorization requests and may supply policy or service attributes | Responds with accept, reject, or challenge |
| RADIUS proxy | Relays requests between a NAS and remote RADIUS servers | Forwards requests; it is not the access device |
| Diameter server | Processes AAA requests in the Diameter protocol | Replies to the NAS application’s AA-Request |
Two points follow from the table. First, the RADIUS server handles the decision, not the user’s ordinary data traffic. Second, a NAS does not have to store user credentials itself; the protocol relies on a separate AAA service for that decision.
How a NAS access exchange works
The exact packet fields and responsibilities depend on the protocol and the implementation. The general sequence in a RADIUS deployment is:
- A user or endpoint requests access through a NAS, such as a switch port, a wireless access point, or a dial-in or DSL access device.
- The NAS sends an Access-Request with the user’s identity and authentication information to a configured RADIUS server. In Diameter, the NAS application starts with an AA-Request instead.
- The server returns Access-Accept, Access-Reject, or Access-Challenge. An accept can include service attributes, and Diameter can carry policy settings such as filter rules.
- The NAS grants or denies access and applies the service settings it received.
- The NAS may send accounting records to an accounting server, covering items such as session identity, duration, and traffic totals. These records summarize usage; they do not route user traffic through the AAA server.
Where NAS devices appear
Enterprise networks
A switch or wireless access point can act as the RADIUS client and NAS. When it enforces 802.1X authentication, it decides whether a device may join the wired or wireless network based on the RADIUS server’s answer.
Recommended Free Tools
Carrier and subscriber access
ADSL termination equipment and DSLAMs can perform the NAS role for subscriber access and accounting. In this setting the NAS is one part of the operator’s access infrastructure, not a separate server.
Rank #3
- Ideal replacement for legacy terminal servers
- Smart OOB is the next generation of remote management
- Cost effective and best value per port for console management
- Up to 96 Ports in 1 RU form factor
- Save money, reduce complexity for efficient operations
Tunneled remote access
RFC 5080 gives 802.11 and PPP as examples of access services a NAS may provide. RFC 2809 uses the term NAS for the device clients contact to obtain network access. When that device performs compulsory L2TP tunneling, RFC 2809 calls it an L2TP Access Concentrator (LAC).
How the term changes across protocols
The same device is named differently depending on the protocol being discussed:
Rank #4
- IC4500 Infranet Unified Access Controller Base Unit/Security Appliance
- Includes IC4500 chassis with JunOS, power, and (2) built-in 10/100/1G Ethernet
- Includes accessories and documentation
- Features: Firewall protection, VPN support, auto-negotiation, Stateful Packet Inspection (SPI), DoS attack prevention, manageable, High Availability, URL filtering, Deep Packet Inspection (DPI), half duplex mode, full duplex mode, RADIUS support
- Supports 5000 concurrent endpoints
- RADIUS: the NAS is the RADIUS client that sends Access-Requests (RFC 2865).
- IEEE 802.1X and EAP: RFC 5080 says the NAS is also known as the Authenticator.
- Diameter: RFC 4005 defines a Network Access Server Application, in which the NAS opens the exchange with an AA-Request.
RFC 2865 also states that RADIUS is not intended as a general-purpose NAS management protocol. It covers authentication and authorization exchanges, not day-to-day configuration of the device.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Avoid confusing NAS with network-attached storage
Searches for “NAS” often return products for network-attached storage, which are file-storage devices. Those are unrelated to the Network Access Server described here. If your question concerns network login, port access, or RADIUS authentication, the relevant meaning is the access-control role described above.
Quick Recap
Best Value
- Secured Server Mounting Setup: This Mini Rack mount has dedicated slot and bolt to install up one Dell OptiPlex Micro Form Factor Case safely.
- Hinged Structure on Both Sides : The Server rack shelf is hinged design on both sides and makes a Easy Access & Maintenance. Easy Access Network Connections.
- Product Size: 1U High x 19" Wide x 6.6" Deep; Perfect to hold Dell OptiPlex Micro Form Factor Case and Fitting 19 inches Server Rack or Cabinet.
- Simple Installation: It only takes 2 steps to mount your appliance onto the mount easily with included bolt, screws, zip ties and assembly guide. The power supply can be ties onto the mount with the provided zip ties safely.
- Good Air Circulation: Bottom cooling holes for increased air circulation. Made of high quality cold rolled steel.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

