Hi all. I'm looking for some ideas on how to best control device access to the network. What are some good ways to keep unwanted devices from being able to connect to a production network? Also, what are some good ways to keep excessive traffic suddenly coming from a device that's gone bad (like a NIC) from taking down a network?

Obviously very strict switch port provisioning could be used, but what else? What about NAC or NAP? Anything else?