IEEE 802.1X

The IEEE standard for port-based network access control: a device (supplicant) must authenticate through the switch or access point (authenticator) to a server before the port opens.

IEEE 802.1X, whose current edition is 802.1X-2020, is port-based network access control for wired and wireless networks. It names three roles. The supplicant is the device asking to join. The authenticator is the switch or wireless access point it connects to. The authentication server is commonly a RADIUS server. Until the device is authenticated, the port commonly passes only authentication traffic, apart from exceptions an administrator configures, such as a guest VLAN or MAC-based bypass for devices that cannot run a supplicant.

The exchange is carried by the Extensible Authentication Protocol, as EAP over LAN between supplicant and authenticator and commonly inside RADIUS beyond it. In the pass-through arrangement, the authentication server runs the EAP method and decides whether authentication succeeded; the authenticator relays the exchange, enforces the result by opening the port or placing the device in a VLAN, and may apply access policy of its own. The method, such as EAP-TLS or PEAP, sets the strength. It underpins network access control and the Enterprise modes of WPA2 and WPA3.

Exam relevance: a scenario is likely to test the roles. Two common traps are that the switch authenticates the user, when it relays and enforces, and that the authentication server talks directly to the laptop, when the authenticator sits between them.