About this interactive
802.1X is described everywhere as three boxes and a few arrows, and the description survives contact with almost no real question. The details that matter are the ones the diagram omits: an unauthorized port passes EAPOL and nothing else, which is why the supplicant has no IP address and why the whole exchange has to happen at Layer 2; the supplicant opens with a reserved multicast address because it has no way to learn the switch's; the switch translates EAP between two encapsulations and cannot read what it is carrying; the supplicant and the RADIUS server never exchange a single packet directly; Access-Challenge, not Access-Reject, is what a request for more information looks like; the EAP method is agreed between the two endpoints and is nowhere in the switch's configuration; and the Access-Accept carries an authorization as well as a verdict. This activity walks one authentication and asks you to predict each of those before it shows you.
What you'll learn
- Name the supplicant, authenticator and authentication server in an 802.1X exchange, and state which decisions each one is and is not able to make
- Identify the EAP frame types and the RADIUS message types at every step of an 802.1X authentication, and explain how the authenticator translates between EAPOL and RADIUS without reading the payload
- Predict what an 802.1X port does with traffic before, during and after authentication, including the authorization attributes an Access-Accept carries and what a link-down does to the session
Aligned to
CompTIA Security+
3.2
Given a scenario, apply security principles to secure enterprise infrastructure.
4.1
Given a scenario, apply common security techniques to computing resources.
CompTIA Network+
4.3
Given a scenario, apply network security features, defense techniques, and solutions.
ISC2 CISSP
5.6
Implement authentication systems
CompTIA A+ Core 2
2.2
Compare and contrast wireless security protocols and authentication methods.
Cisco CCNA
5.8
Compare authentication, authorization, and accounting concepts
Key terms
- 802.1X
- An IEEE standard for port-based network access control that requires devices to authenticate before gaining access to a wired or wireless network, using a supplicant, authenticator, and authentication server (typically RADIUS). It is the foundation of enterprise Wi-Fi security and wired port security using EAP methods.
- Supplicant
- In the IEEE 802.1X authentication framework, the device or user requesting network access that must prove its identity to the authenticator before being granted access. The supplicant runs an EAP method such as EAP-TLS or PEAP and communicates with the authenticator using EAPoL.
- Authenticator
- In the IEEE 802.1X framework, the network device (typically a switch or wireless access point) that sits between the supplicant and the authentication server, relaying EAP messages and enforcing whether the port is opened or blocked based on the authentication result. The authenticator does not verify credentials itself; it passes that responsibility to the RADIUS server.
- Authentication Server
- The server in a network access control framework (such as 802.1X) that validates supplicant credentials and grants or denies network access based on authentication policy. RADIUS is the most common authentication server protocol.
- Extensible Authentication Protocol
EAP
- Extensible Authentication Protocol is a flexible authentication framework used in wireless networks and PPP connections that supports multiple authentication methods including certificates, tokens, and passwords.
- Extensible Authentication Protocol over LAN
EAPoL
- A network access control protocol defined in IEEE 802.1X that encapsulates EAP authentication messages over a local area network before a device is granted access to network resources. EAPoL operates at Layer 2 and is the delivery mechanism for EAP methods such as EAP-TLS and PEAP.
- Remote Authentication Dial-In User Service
RADIUS
- RADIUS is a client-server networking protocol that provides centralized authentication, authorization, and accounting management for users connecting to network access points or VPN services.
- Encapsulation
- The process of wrapping data with protocol headers as it passes down the layers of the OSI model.
- EAP Method
- A specific authentication protocol built upon the EAP framework, each designed to support a particular use case such as certificates, passwords, or pre-shared keys.
- EAP Transport Layer Security
EAP-TLS
- An EAP authentication method that uses TLS with mutual digital certificate authentication for both the client and the authentication server. EAP-TLS is considered one of the most secure 802.1X authentication methods and is widely used in enterprise wireless and wired networks.
- Authentication
- The process of verifying the identity of a user, device, or system.
- Authorization
- The process of determining what actions or resources an authenticated user is permitted to access.
- Port Security
- A Cisco switch feature that restricts which devices can connect to a port by limiting the number of allowed MAC addresses or requiring specific MAC addresses to be present. When a violation occurs, the port can be configured to shut down, restrict traffic, or send an alert.
- MAC Address
- A 48-bit hardware address assigned to a network interface and written as six hexadecimal octets, such as 00:1A:2B:3C:4D:5E. It identifies a device uniquely on a local network segment, and switches forward frames by looking it up in their MAC address table.
- Virtual LAN
VLAN
- A logical grouping of network devices that behave as if they are on the same network regardless of physical location.
Topics
Interactive
Predict
802 1x
Eap
Radius
Network Access Control
Authentication
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →