802.1X model
The supplicant is the client, the authenticator is usually a switch or access point, and the authentication server is commonly RADIUS. Wired access uses EAPOL between client and switch; the authenticator then uses RADIUS towards the authentication service.
RADIUS
RADIUS carries authentication and authorisation information and can return attributes such as a VLAN assignment. Design redundant RADIUS services and define what happens when they are unavailable.
EAP methods
EAP-TLS uses certificates and is well suited to managed devices. PEAP and EAP-TTLS use protected tunnels around an inner authentication method. Choose based on client support, certificate lifecycle and security requirements.
Certificates
EAP-TLS depends on correct client and server certificates, trusted certificate chains, suitable EKUs and accurate time. Expired certificates and missing trust chains are common causes of authentication failures.
Dynamic VLANs
RADIUS can assign a VLAN based on identity or policy where the infrastructure supports it. Define explicit fallback behaviour so authentication failure does not accidentally result in unrestricted access.
Troubleshooting
- Confirm link or wireless association.
- Check client time and certificate validity.
- Verify trust chains.
- Check RADIUS reachability and shared secrets.
- Read the authentication server's actual reject reason.
- Check EAP method and policy matching.
- Verify returned VLAN attributes and DHCP.
- Use a packet capture to separate EAPOL, RADIUS and DHCP stages.
Related tool
Inspect authentication and network traffic when configuration alone does not explain the failure.