ENGINEERING GUIDE · SECURITY

802.1X & RADIUS Network Access Authentication

Understand 802.1X, supplicants, authenticators, RADIUS, EAP, certificates and dynamic VLAN assignment.

802.1XRADIUS · EAP
The important bit: 802.1X separates the client requesting access, the network device enforcing access and the authentication service deciding whether access is permitted.

802.1X model

The supplicant is the client, the authenticator is usually a switch or access point, and the authentication server is commonly RADIUS. Wired access uses EAPOL between client and switch; the authenticator then uses RADIUS towards the authentication service.

RADIUS

RADIUS carries authentication and authorisation information and can return attributes such as a VLAN assignment. Design redundant RADIUS services and define what happens when they are unavailable.

EAP methods

EAP-TLS uses certificates and is well suited to managed devices. PEAP and EAP-TTLS use protected tunnels around an inner authentication method. Choose based on client support, certificate lifecycle and security requirements.

Certificates

EAP-TLS depends on correct client and server certificates, trusted certificate chains, suitable EKUs and accurate time. Expired certificates and missing trust chains are common causes of authentication failures.

Dynamic VLANs

RADIUS can assign a VLAN based on identity or policy where the infrastructure supports it. Define explicit fallback behaviour so authentication failure does not accidentally result in unrestricted access.

Troubleshooting

  1. Confirm link or wireless association.
  2. Check client time and certificate validity.
  3. Verify trust chains.
  4. Check RADIUS reachability and shared secrets.
  5. Read the authentication server's actual reject reason.
  6. Check EAP method and policy matching.
  7. Verify returned VLAN attributes and DHCP.
  8. Use a packet capture to separate EAPOL, RADIUS and DHCP stages.

Related tool

Inspect authentication and network traffic when configuration alone does not explain the failure.

Packet Capture Analyser →