What Is 802.1X? Network Authentication
802.1X is the IEEE standard for port-based network authentication. It verifies a device's identity before granting it network access. It is an essential component of NAC (Network Access Control) and enterprise WiFi authentication using WPA2/WPA3-Enterprise.
How It Works
- Supplicant (client): PC, smartphone, or IoT device
- Authenticator (switch/AP): EAP relay
- Authentication Server: RADIUS (FreeRADIUS, Cisco ISE, Aruba ClearPass, Microsoft NPS)
- The port remains closed until authentication succeeds
- Dynamic VLAN assignment based on identity
EAP Methods
- EAP-TLS: mutual X.509 certificates (the most secure option)
- PEAP-MSCHAPv2: AD credentials (the most common option)
- EAP-FAST: Cisco alternative to PEAP
- EAP-TTLS: used on eduroam
- EAP-PWD: certificate-free authentication (rare)
Use Cases
- WPA2/WPA3-Enterprise WiFi
- Access switches: authenticate the PC before VLAN assignment
- Dynamic segmentation (Cisco TrustSec SGT)
- BYOD enrollment
- IoT onboarding with certificates
MAB (MAC Authentication Bypass)
Fallback for devices without an 802.1X supplicant, such as printers and cameras: authentication using the MAC address stored in the RADIUS database.
Order from OPTINOC
802.1X and NAC deployment with Cisco ISE, Aruba ClearPass, FortiNAC, or FreeRADIUS. Quote within 48 hours.
