IEEE 802.1X

Port-Based Access Control for Enterprise Networks

What is IEEE 802.1X?

IEEE 802.1X network access is port-based access control for IEEE 802 local-area networks. The IEEE standard defines three principal roles: a supplicant requesting access, an authenticator controlling the port, and an authentication server evaluating credentials. Extensible Authentication Protocol over LAN (EAPOL) carries exchanges between the endpoint and authenticator. Before authorization, the controlled port limits ordinary service access while an uncontrolled path permits the authentication conversation. RADIUS is commonly used between an authenticator, such as a switch or wireless access point, and the backend server, but it is not the whole 802.1X architecture. The standard supplies an enforcement framework; identity proofing, authentication method, and authorization policy remain deployment decisions.

What is IEEE 802.1X used for?

Enterprises use IEEE 802.1X on wired switch ports and WPA2- or WPA3-Enterprise wireless networks to authenticate users or devices before granting connectivity. Network Access Control (NAC) platforms can use the result for role assignment, segmentation, reauthentication, and dynamic policy where the infrastructure supports those functions. Certificate-based EAP methods can strengthen machine identity, but they create dependencies on Public Key Infrastructure (PKI), identity stores, certificate enrollment, and renewal. Resilient authentication servers, controlled guest and IoT exceptions, fallback governance, and monitoring are essential. Weak EAP methods, broad pre-authentication access, fail-open behavior, and expired machine certificates can turn an intended Zero Trust enforcement point into an outage source or a bypass.

Continue reading

Attack Surface
Total Exposure to Cyber Threats
CIA Triad
Core Principles of Information Security
Sherwood Applied Business Security Architecture (SABSA)
Business-Driven Security Architecture

Please note!
Any use of this website requires prior agreement to our Terms of Use, Privacy Policy, and Cookie Policy.
If you do not fully agree to all of them, do not use this website.