> For the complete documentation index, see [llms.txt](https://infra.newerasec.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://infra.newerasec.com/infrastructure-testing/gaining-access/nac-bypass.md).

# NAC Bypass

## Captive Portal

Certain NAC systems leverage a captive portal authentication system to validate a user's identify before granting access to the rest of the network.

### No SSL

If the captive portal doesn't have TLS protection we can consider MiTM attacks on other users.

## Tools

### silentbridge

<https://github.com/s0lst1c3/silentbridge>

Silentbridge is a toolkit for bypassing 802.1x-2010 and 802.1x-2004.
