What is Centralized Wireless & 802.1X Authentication?
In a centralized enterprise network, Lightweight Access Points (LAPs) offload management, security, and roaming functions to a central Wireless LAN Controller (WLC). User authentication is offloaded to enterprise identity providers using 802.1X / EAP and RADIUS servers.
CAPWAP Control & Data Tunnels: Control frames are DTLS-encrypted over UDP 5246. Data frames are encapsulated over UDP 5247 back to the WLC.
Supplicant (Client): Initiates EAPoL (EAP over LAN) frames to request access using user/machine credentials or digital certificates.
Authenticator (WLC / AP): Relays 802.1X EAP messages between the wireless client and the backend AAA server by encapsulating EAP within RADIUS packets.
Authentication Server (ISE / RADIUS): Validates user credentials, processes certificate exchanges (EAP-TLS/PEAP), and returns RADIUS Access-Accept/Reject along with VLAN and DACL attributes.
Key Security & Authentication Terminology
EAPOL (EAP over LAN): The encapsulation protocol used by IEEE 802.1X to carry EAP packets between the Supplicant client and Authenticator.
RADIUS Access-Request / Challenge: RADIUS messages used by the WLC to exchange challenge/response payloads with Cisco ISE / AAA servers.
4-Way Handshake: WPA2/WPA3 key negotiation occurring post-authentication to generate Pairwise Transient Keys (PTK) for over-the-air encryption.