<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Eap on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/eap/</link><description>Recent content in Eap on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/eap/index.xml" rel="self" type="application/rss+xml"/><item><title>Port-based Network Access Control (IEEE 802.1X)</title><link>https://lesitedefrancois.be/en/security/8021x/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/8021x/</guid><description>&lt;p&gt;&lt;strong&gt;IEEE 802.1X&lt;/strong&gt; is a standard for &lt;strong&gt;Port-Based Network Access Control (PNAC)&lt;/strong&gt; that prevents any device from sending or receiving traffic on a network port until it has successfully authenticated. Originally designed for wired Ethernet and ratified in 2001, it now equally underpins enterprise Wi-Fi (WPA-Enterprise/WPA3-Enterprise), where access points act as the port gatekeeper. The core premise is that physical access to a port — plugging in a cable or being in range of an access point — does not grant network access. The port is logically divided into two channels: the &lt;strong&gt;uncontrolled port&lt;/strong&gt;, which passes only EAP authentication traffic (EAPOL frames), and the &lt;strong&gt;controlled port&lt;/strong&gt;, which is fully blocked until authentication succeeds. Only after the authentication server approves the device does the switch or access point open the controlled port and allow normal traffic. This port-level gate is what separates 802.1X from higher-layer authentication: a device that fails 802.1X receives no IP address, cannot reach any network resource, and cannot even attempt an attack at layer 3.&lt;/p&gt;</description></item></channel></rss>