Isolation of devices that are vulnerable
If a device comes up as being a risk i.e. old firmware or not sufficiently up to date on OS etc, there should be an option to place those devices into a virtual LAN isolated from the rest of the network until the vulnerabilities have been addressed.
0