Full 802.1X reauthentication on every roam
Without fast roaming, every handoff on an 802.1X network repeats the whole EAP exchange with the authentication server, and the client passes no data until it finishes.
On this page5 sections
Is this your problem? It presents like this
- Drops happen only while the device is moving, at the points along a route where it changes access points.
- Stationary devices on the same SSID stay connected.
- Every mobile device on the SSID shows it, whatever the model.
- The gap grows when the authentication server is remote, busy, or reached over a congested link.
- The controller or authentication server logs a complete EAP exchange at every roam, not a fast transition.
- Bands
- 2.4 GHz5 GHz5 GHz DFS6 GHz
Why it happens
802.1X puts an authentication server in the path of every join. Without fast roaming, a roam is a join. The client runs the whole EAP-TLS conversation again, with certificates crossing in both directions over several round trips, and then a fresh 4-way handshake. It has to go through full validation and new key generation before it can pass data, and the time depends on the round trip to the authentication server.
You may have timed a quick 802.1X roam in a lab. Vendor figures show how wide the spread really is. One vendor’s roaming primer puts a full-authentication roam at 120 ms to a couple of seconds1, against 4 to 50 ms for 802.11r, and says the low end of each range came from a lab with perfect RF. A plant floor is not that lab.
The handoff is where mobile plant devices are exposed. In a study of 331 AGV disconnections2 at an automotive plant, 85.84% began with a roaming attempt. That study did not single out authentication. It shows the roam is the moment that has to be short.
Fast transition exists to take the server out of the roam. With 802.11r, the key handshake with the target access point happens before the client moves, so fewer frames are exchanged before data flows again. Every roam that repeats the full exchange spends time your application timeout never allowed for.
Where a roam loses time
The outage runs from leaving the old access point until data flows on the new one.
Schematic, not to scale
Without fast roaming, every roam on an 802.1X network repeats the full EAP exchange with the authentication server; with EAP-TLS that is several request and response rounds carrying certificates. Fast BSS transition moves the key exchange into the authentication and reassociation frames, so fewer frames pass before data transfer. Widths show the order of the steps, not measured durations.
Sources: RFC 5216 (EAP-TLS) and Microsoft's Windows driver documentation on fast roaming.
How to confirm it
- Capture over the air at a known handoff point, or pull the controller's client event log, for a device that dropped while roaming.
- Look at what follows the reassociation. EAP Identity, a TLS certificate exchange, and then the 4-way handshake mean a full authentication. An FT authentication, or a PMKID the AP accepts, means fast roaming worked.
- Time the gap from the last data frame on the old access point to the first data frame on the new one, and compare it with the application's connection timeout.
- Check the authentication server log for a new Access-Request from the device at every handoff.
- Check which key management suites the SSID advertises. 802.1X with no FT, OKC, or PMK caching confirms the configuration.
The fix
- Enable 802.11r fast transition on the SSID, after confirming that every client model on it supports FT for 802.1X.
- Where a client cannot do FT, enable OKC or PMK caching if both the client and the network support it, so the roam skips the EAP exchange.
- Shorten and protect the path to the authentication server, so its round trip is short and does not share a congested link.
Prevent it at design time
- Make fast roaming support for your key type a purchasing requirement for every mobile client.
- Measure roam time per client model on the real route before you set application timeouts.
- Count the authentication server's round trip in the timing budget, not just the radio.
About this page
Built from 6 sources: 1 standards body or lab, 1 research paper or thesis and 4 vendor documents. Researched and drafted with AI assistance, then reviewed and approved by Ben Rutter on . How pages are made
- First published
- Last updated
Change history (1)
- First published
Cite this page
Plain
Ben Rutter. "Full 802.1X reauthentication on every roam." OT Wireless, published October 5, 2026. https://otwireless.com/causes/slow-roam-full-reauthentication/
APA 7
Rutter, B. (2026, October 5). Full 802.1X reauthentication on every roam. OT Wireless. https://otwireless.com/causes/slow-roam-full-reauthentication/
BibTeX
@misc{rutter2026slowroamfullreauthentication,
author = {Rutter, Ben},
title = {{Full 802.1X reauthentication on every roam}},
year = {2026},
howpublished = {\url{https://otwireless.com/causes/slow-roam-full-reauthentication/}},
organization = {OT Wireless},
}