Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

IEEE 802.1X is a standard for controlling access to wired and wireless LANs. It lets a network restrict a port’s normal network service until a device or user has been authenticated and authorized. It defines the access-control framework—not a particular password, encryption algorithm, or complete security setup.

What is 802.1X?

IEEE calls 802.1X “Port-Based Network Access Control.” Its purpose is to let a network administrator restrict use of LAN service access points, or ports, to secure communication between authenticated and authorized devices. The standard specifies a common architecture, functional elements, and protocols that support mutual authentication between clients of ports attached to the same LAN and secure communication between those ports. IEEE Standards Association’s 802.1X-2020 listing identifies the edition published on February 28, 2020, as active and as superseding 802.1X-2010.

802.1X is used for both wired Ethernet and enterprise wireless access. It provides a framework; the chosen authentication method, credentials, authorization rules, network equipment, and configuration determine how a deployment works in practice.

How does 802.1X authentication work?

  1. A client requests access. The endpoint, called the supplicant, connects to a wired switch port or wireless access point.
  2. The endpoint and network exchange authentication messages. EAP (Extensible Authentication Protocol) carries the authentication exchange. Between the endpoint and the network access device, EAP is encapsulated as EAP over LAN, or EAPOL.
  3. The network device consults an authentication server. In common deployments, the authenticator forwards the exchange to a backend authentication server using RADIUS. The server evaluates the request and returns an outcome.
  4. The network applies the result. If the endpoint is authenticated and authorized, the authenticator permits the communication allowed by policy through the controlled port. If not, normal controlled-port access is withheld.

The common message path is Supplicant — EAPOL — Authenticator — RADIUS — Authentication Server, as shown in Cisco’s wired 802.1X deployment guide. RADIUS is a commonly used backend protocol; it is not another name for 802.1X. The IETF’s RFC 3580, published in September 2003, provides guidance on using RADIUS with IEEE 802.1X in Ethernet and 802.11 wireless LAN contexts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
NETGEAR 5-Port Gigabit Ethernet Easy Smart Managed Network Switch (GS305E)
  • GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
  • EASY SMART MANAGED NETWORK SWITCH: Intuitive software interface offers Easy Smart Managed Essentials capabilities to configure VLANs, prioritize traffic with QoS, monitor ports, and manage network security for small businesses.
  • FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
  • SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
  • REGIONAL COMPATIBILITY: Made for use in U.S. & CA only

What are the supplicant, authenticator, and authentication server?

Role What it does Common example
Supplicant The client endpoint that seeks access and participates in authentication. A computer or other endpoint with an 802.1X supplicant.
Authenticator The network-side device that controls access at the port and relays authentication exchanges. A switch in a wired network or an access point in a wireless network.
Authentication server Evaluates authentication requests and returns an authorization result. A RADIUS service in a common deployment.

The endpoint’s supplicant, the authenticator, and the server must be configured to work together. Having equipment that supports 802.1X does not by itself establish a secure or interoperable deployment.

What do the controlled and uncontrolled ports do?

802.1X distinguishes two logical port functions. The uncontrolled port allows authentication and key-management protocols to begin communication. The controlled port carries network communication subject to access control. This separation lets the endpoint and network complete the authentication exchange before ordinary traffic is allowed through the controlled port.

Rank #2
Sale
NETGEAR 8-Port Gigabit Ethernet Easy Smart Managed Network Switch (GS308E)
  • PLUG-AND-PLAY GIGABIT MANAGED SWITCH: 8 x 1Gbps auto-negotiating ports work the moment you plug in — full-gigabit speed over Cat5e/Cat6 cabling.
  • MANAGED, WITHOUT THE COMPLEXITY: Easy Smart web GUI on Windows, Mac or Linux — no app or Windows-only utility, unlike many competing switches.
  • SEGMENT & PRIORITIZE TRAFFIC: Up to 64 VLANs, QoS, IGMP snooping and port mirroring keep voice, video and data fast, secure and organized.
  • BUILT-IN PROTECTION: Auto DoS prevention, loop detection, broadcast storm control and cable test keep your network stable and easy to troubleshoot.
  • RELIABLE 24/7 BACKBONE: Rugged fanless metal housing runs cool and silent at 0 dBA — the managed switch trusted in homes, offices and small business.

The IEEE 802.1 Security Task Group describes 802.1X as requiring mutual authentication of peer systems that want to communicate through their controlled ports, using EAP and its LAN encapsulation, EAPOL. The group also describes MKA, which supports using IEEE 802.1AE MAC Security (MACsec) to cryptographically protect controlled-port communication. MKA and MACsec are related capabilities; they are not features to assume in every 802.1X deployment. See the IEEE 802.1X description and revision context.

What 802.1X does—and what it does not do

  • It does: provide a port-based framework for authentication and access control on LANs.
  • It does not: prescribe one universal password type, guarantee that a network is securely configured, or itself describe a complete encryption solution.
  • It depends on: the EAP method, endpoint supplicant, authenticator implementation, authentication server and policy, credentials, and configuration.
  • It may be paired with: MACsec through MKA where the deployment and equipment support it; this is not universal.

For that reason, “supports 802.1X” is only one compatibility check. The selected authentication method and how certificates or other credentials are handled matter to both security and whether endpoints can connect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
TP-Link 8 Port Gigabit Switch | Easy Smart Managed | Plug & Play | Desktop/Wall-Mount | Sturdy Metal w/ Shielded Ports | Support QoS, Vlan, IGMP and LAG (TL-SG108E)
  • 8 Gigabit Ethernet Ports: Expand your network with 8 high-speed ethernet ports for enhanced connectivity and performance
  • Easy Smart Management: Manage and configure your network effortlessly via a web interface or free software
  • Support VLAN: Segment traffic with up to 32 VLANs simultaneously out of 4K VLAN IDs for better security
  • Network Monitoring: Monitor your network effectively with port mirroring, loop prevention, and cable diagnostics
  • IGMP Snooping: Enhances multicast application performance for improved network efficiency

Do you need 802.1X on your network?

802.1X is relevant when you need network infrastructure to authenticate and authorize devices or users before granting LAN access—for example, in an organization managing wired switch ports or enterprise wireless access. Whether it is suitable depends on the endpoints, network equipment, authentication service, and access policies you can operate.

Before deployment, assess the following:

  • EAP method and certificate validation: Confirm which methods the endpoints, network equipment, and server support, and how validation is configured.
  • Endpoint support and management: Check that the devices’ supplicants are available and can be configured reliably.
  • Authenticator support: Verify 802.1X support on the exact wired switch or wireless access point models and firmware in use.
  • Server, policy, and resilience: Confirm RADIUS integration, authorization policy, and failover behavior.
  • Identity and certificate lifecycle: Decide how identities and credentials are issued, renewed, revoked, and maintained.
  • Visibility and exceptions: Ensure logs provide enough information to diagnose failures, and plan how to handle devices that cannot use 802.1X.

If you need to buy infrastructure, look for a managed Ethernet switch with explicit 802.1X support, but verify the exact model’s supported EAP methods, RADIUS integration, firmware, and administrative features. The “managed switch” label alone does not establish compatibility. Wireless access points can also act as authenticators in wireless deployments.

Rank #4
TP-Link TL-SG1024DE, 24 Port Gigabit Easy Smart Managed Ehternet Switch
  • 24-Gigabit ports provide instant large file transfers
  • 9K Jumbo frame improves performance of large data transfers
  • Effective network monitoring via Port Mirroring, Loop Prevention and Cable Diagnostics
  • Abundant VLAN features improve network security via traffic segmentation
  • IGMP Snooping optimizes multicast applications
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which edition is current?

IEEE lists 802.1X-2020 as the active published standard. The IEEE 802.1 Security Task Group separately reports that a revision project is in progress; that project status does not replace the active published edition.

Quick Recap

SaleBestseller No. 1
NETGEAR 5-Port Gigabit Ethernet Easy Smart Managed Network Switch (GS305E)
NETGEAR 5-Port Gigabit Ethernet Easy Smart Managed Network Switch (GS305E)
REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
$16.99
SaleBestseller No. 3
Bestseller No. 4
TP-Link TL-SG1024DE, 24 Port Gigabit Easy Smart Managed Ehternet Switch
TP-Link TL-SG1024DE, 24 Port Gigabit Easy Smart Managed Ehternet Switch
24-Gigabit ports provide instant large file transfers; 9K Jumbo frame improves performance of large data transfers
$99.99
Bestseller No. 5
TP-Link 16 Port Gigabit Switch | Easy Smart Managed | Plug & Play | Limited Lifetime Protection | Desktop/Wall-Mount | Sturdy Metal w/ Shielded Ports | Support QoS, Vlan, IGMP and LAG (TL-SG116E)
TP-Link 16 Port Gigabit Switch | Easy Smart Managed | Plug & Play | Limited Lifetime Protection | Desktop/Wall-Mount | Sturdy Metal w/ Shielded Ports | Support QoS, Vlan, IGMP and LAG (TL-SG116E)
16 10/100/1000Mbps RJ45 Ports; Plug and play, with No configuration required; Durable metal casing of superior quality and Professional appearance
$59.99
Best Value
TP-Link 16 Port Gigabit Switch | Easy Smart Managed | Plug & Play | Limited Lifetime Protection | Desktop/Wall-Mount | Sturdy Metal w/ Shielded Ports | Support QoS, Vlan, IGMP and LAG (TL-SG116E)
  • 16 10/100/1000Mbps RJ45 Ports
  • Plug and play, with No configuration required
  • Durable metal casing of superior quality and Professional appearance
  • Intelligent management via a web user interface and downloadable Utility
  • Green technology reduces power consumption

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.