EAP and 802.1X (Extensible Authentication Protocol and IEEE 802.1X)
802.1X is the port access control framework that keeps a client off the network until it authenticates, and EAP is the step-by-step exchange it carries between the client, the access point and the RADIUS server.
The network analogy
A login handshake where the switch or access point only relays messages and the authentication server makes the decision, repeated for every client that joins.
Why it matters for wireless
Every step of the exchange waits on the one before it, so a full authentication on join or roam costs more than one round trip to the server and can outlast a control connection's timeout.
802.1X is the access control framework: the access point holds a client’s traffic back until an authentication server says the client may through. EAP is what runs inside it. The access point does not judge the client. It relays EAP messages to the RADIUS server, which carries them in EAP-Message attributes and answers each one with the next message for the client. The authentication method lives on the server, not in the access point.
The exchange is strictly serial. EAP is a lock-step protocol: after the first Request, no new Request goes out until a valid Response comes back, so only one packet is ever in flight. Each step is therefore a round trip from client to access point to RADIUS server and back. A full join or roam takes more than one of them, and the count depends on the EAP method. With 802.1X, the client has to complete the entire EAP key exchange before it can deauthenticate from its current BSSID, which Apple says might take several seconds. Fast transition is the 802.11r mechanism meant to shorten this, and one vendor’s configuration guide covers it with 802.1X key management. Apple notes that fast transition can work with 802.1X depending on the Wi-Fi hardware. See slow roam and full reauthentication, authentication server latency, key rotation and reauthentication timers and fast roam mismatch.
EAP does not make a roam slow by itself. What it does is make every step wait on a round trip to the server, so measure the full exchange against the control connection’s timeout.
About this page
Built from 5 sources: 2 standards bodies and labs, 1 protocol owner or alliance, 1 vendor document and 1 other source. Researched and drafted with AI assistance, then reviewed and approved by Ben Rutter on . How pages are made
- First published
- Last updated
Cite this page
Plain
Ben Rutter. "EAP and 802.1X (Extensible Authentication Protocol and IEEE 802.1X)." OT Wireless, published October 6, 2026. https://otwireless.com/glossary/eap-and-802-1x/
APA 7
Rutter, B. (2026, October 6). EAP and 802.1X (Extensible Authentication Protocol and IEEE 802.1X). OT Wireless. https://otwireless.com/glossary/eap-and-802-1x/
BibTeX
@misc{rutter2026eapand8021x,
author = {Rutter, Ben},
title = {{EAP and 802.1X (Extensible Authentication Protocol and IEEE 802.1X)}},
year = {2026},
howpublished = {\url{https://otwireless.com/glossary/eap-and-802-1x/}},
organization = {OT Wireless},
}