TechKnowSurge
CompTIA Security+ 3.2 CompTIA Network+ 4.3 ISC2 CISSP 5.6 CompTIA A+ Core 2 2.2 Cisco CCNA 5.8 CompTIA Security+ 4.1
InteractiveSecurityFree

802.1X Authentication Flow Walkthrough

Follow one laptop from a dead switch port to an authorized one, committing to each EAP frame and RADIUS message before it is revealed.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

802.1X is described everywhere as three boxes and a few arrows, and the description survives contact with almost no real question. The details that matter are the ones the diagram omits: an unauthorized port passes EAPOL and nothing else, which is why the supplicant has no IP address and why the whole exchange has to happen at Layer 2; the supplicant opens with a reserved multicast address because it has no way to learn the switch's; the switch translates EAP between two encapsulations and cannot read what it is carrying; the supplicant and the RADIUS server never exchange a single packet directly; Access-Challenge, not Access-Reject, is what a request for more information looks like; the EAP method is agreed between the two endpoints and is nowhere in the switch's configuration; and the Access-Accept carries an authorization as well as a verdict. This activity walks one authentication and asks you to predict each of those before it shows you.

What you'll learn

Aligned to

CompTIA Security+
3.2 Given a scenario, apply security principles to secure enterprise infrastructure.
4.1 Given a scenario, apply common security techniques to computing resources.
CompTIA Network+
4.3 Given a scenario, apply network security features, defense techniques, and solutions.
ISC2 CISSP
5.6 Implement authentication systems
CompTIA A+ Core 2
2.2 Compare and contrast wireless security protocols and authentication methods.
Cisco CCNA
5.8 Compare authentication, authorization, and accounting concepts

Key terms

802.1X
An IEEE standard for port-based network access control that requires devices to authenticate before gaining access to a wired or wireless network, using a supplicant, authenticator, and authentication server (typically RADIUS). It is the foundation of enterprise Wi-Fi security and wired port security using EAP methods.
Supplicant
In the IEEE 802.1X authentication framework, the device or user requesting network access that must prove its identity to the authenticator before being granted access. The supplicant runs an EAP method such as EAP-TLS or PEAP and communicates with the authenticator using EAPoL.
Authenticator
In the IEEE 802.1X framework, the network device (typically a switch or wireless access point) that sits between the supplicant and the authentication server, relaying EAP messages and enforcing whether the port is opened or blocked based on the authentication result. The authenticator does not verify credentials itself; it passes that responsibility to the RADIUS server.
Authentication Server
The server in a network access control framework (such as 802.1X) that validates supplicant credentials and grants or denies network access based on authentication policy. RADIUS is the most common authentication server protocol.
Extensible Authentication Protocol
EAP
Extensible Authentication Protocol is a flexible authentication framework used in wireless networks and PPP connections that supports multiple authentication methods including certificates, tokens, and passwords.
Extensible Authentication Protocol over LAN
EAPoL
A network access control protocol defined in IEEE 802.1X that encapsulates EAP authentication messages over a local area network before a device is granted access to network resources. EAPoL operates at Layer 2 and is the delivery mechanism for EAP methods such as EAP-TLS and PEAP.
Remote Authentication Dial-In User Service
RADIUS
RADIUS is a client-server networking protocol that provides centralized authentication, authorization, and accounting management for users connecting to network access points or VPN services.
Encapsulation
The process of wrapping data with protocol headers as it passes down the layers of the OSI model.
EAP Method
A specific authentication protocol built upon the EAP framework, each designed to support a particular use case such as certificates, passwords, or pre-shared keys.
EAP Transport Layer Security
EAP-TLS
An EAP authentication method that uses TLS with mutual digital certificate authentication for both the client and the authentication server. EAP-TLS is considered one of the most secure 802.1X authentication methods and is widely used in enterprise wireless and wired networks.
Authentication
The process of verifying the identity of a user, device, or system.
Authorization
The process of determining what actions or resources an authenticated user is permitted to access.
Port Security
A Cisco switch feature that restricts which devices can connect to a port by limiting the number of allowed MAC addresses or requiring specific MAC addresses to be present. When a violation occurs, the port can be configured to shut down, restrict traffic, or send an alert.
MAC Address
A 48-bit hardware address assigned to a network interface and written as six hexadecimal octets, such as 00:1A:2B:3C:4D:5E. It identifies a device uniquely on a local network segment, and switches forward frames by looking it up in their MAC address table.
Virtual LAN
VLAN
A logical grouping of network devices that behave as if they are on the same network regardless of physical location.

Topics

Interactive Predict 802 1x Eap Radius Network Access Control Authentication

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →