IT security

802.1X

Also known as: IEEE 802.1X · Port-Based Network Access Control

In short

802.1X is a standard that only lets a device onto a network port or Wi-Fi after it has successfully authenticated.

802.1X is an IEEE standard for port-based network access control: a device only gets access to a network after it has successfully identified itself to a central server. Without 802.1X, plugging a network cable into any free wall socket, or connecting with a known Wi-Fi password, is enough to become part of the network. The standard shifts access checking from a password alone to a genuine device or user identity.

In practice, a switch or access point asks a new device for its identity via the EAP protocol and forwards it to a RADIUS server, which checks the credentials. Only once that check succeeds does the network port open up; until then, the connected device stays technically isolated. For staff this usually runs invisibly in the background, such as a company laptop signing onto Wi-Fi automatically.

An edge case is devices that don't support 802.1X themselves, such as some printers or older machine controllers – these need a separate exception rule, otherwise they get shut out of the network entirely. A common mistake is also to deploy 802.1X only on Wi-Fi while leaving office network sockets open, even though the same uncontrolled access remains possible through them.

What it means in practice

In many offices, plugging a cable into any free network socket is enough to reach the internal network, a sign that 802.1X is missing. This mainly affects meeting rooms and vacant desks where nobody checks which device gets connected. NDVDL sets up 802.1X on network ports and Wi-Fi wherever uncontrolled physical access is a risk.

Is this handled properly at your site?

We look at how it actually stands with you — and say honestly whether anything needs doing.

IT security & firewall

A term from your quote missing here?

Send us the passage you do not follow. We will explain it — with no obligation to order anything.