What do you do to prevent devices in an End-System Group from joining guest and jumping directly to their spot in the NAC policy? My concern is a corporate device is connected to the guest wireless and now traffic is not encrypted and the device now ...