Plug in a cable and you are on the network? On a factory floor, a campus access layer, or a PON central office, that is more realistic than many expect. A new camera defaults to full network access; a visitor's laptop on a desk port reaches the core; someone even jams an illegal device into the OLT uplink to steal bandwidth. 802.1X authentication changes the default-open door into credential-gated access — and it guards not only switches but also the OLT uplink port and the terminal ports hanging off an ONU.
802.1X is port-based: a port stays unauthorized until the endpoint authenticates; only then does business traffic flow.
Three roles: Supplicant (endpoint), Authenticator (switch / OLT), Authentication Server (RADIUS / AAA).
Dumb terminals (cameras, PLCs) that cannot run 802.1X fall back to MAC Authentication Bypass (MAB).
If RADIUS dies, a Critical VLAN (or port shutdown) keeps the link from becoming an open door.
On the OLT: the uplink port authenticates against the core, and ONU user ports transparently pass EAPOL so the OLT terminates the endpoint's 802.1X — distinct from PON-layer ONU registration (SN / LOID).
Strictly, 802.1X is Port-Based Network Access Control. It puts a physical (or logical) port of a switch or OLT into two states: unauthorized (before authentication) and authorized (after). An endpoint that has not authenticated — cable plugged in, NIC light on — is only allowed traffic to the authentication server; all business data is blocked at the door.

Supplicant: the endpoint wanting on the network — a PC, a camera, a device under an ONU — running the EAPOL client.
Authenticator: the device between endpoint and network — an industrial switch or OLT — that forwards authentication messages.
Authentication Server: usually RADIUS (AAA), the one that actually decides "can this endpoint in?"
The industrial switch is always the Authenticator; it stores no usernames or passwords, it only forwards the endpoint's credentials to RADIUS for a verdict.
Endpoint connects → port starts unauthorized → endpoint sends EAPOL-Start → Authenticator forwards to RADIUS → the two walk the EAP handshake (PEAP / MS-CHAPv2 most common, EAP-TLS certificate in high-security scenes) → on pass, RADIUS returns Access-Accept and the port flips to authorized. The idea is the same as "enter password then join Wi-Fi," just moved to the wired port. Authentication only happens at connect time; once authorized, normal forwarding, no added latency.
Cameras, PLCs, and door controllers on a factory floor are mostly "dumb terminals" — no 802.1X client in firmware. Ask them to do an EAP handshake and they only send DHCP. That is where MAC Authentication Bypass (MAB) comes in: when the Authenticator sees a terminal that will not do 802.1X, it uses the terminal's MAC address as the account to check against the RADIUS whitelist; match → admit, no match → drop to an isolated VLAN or shut the port. For production networks we recommend running 802.1X + MAC Authentication Bypass together.
The authentication server is not immortal. When RADIUS is unreachable, the port policy must be decided in advance:
Critical VLAN: temporarily place the endpoint in a restricted VLAN (reach only the ops segment) — business is impaired but not fully cut.
Or configure auth-fail to simply shut the port.
Never "if server unreachable, open everything" — that makes 802.1X meaningless.

Unpacking OLT port authentication, it is useful in at least two places, and it is a different matter from PON-layer ONU registration.
① OLT uplink port authenticates against the core. When the OLT uplinks to a BRAS / core switch, the core side can require port-level authentication. The OLT uplink port enables 802.1X; the OLT acts as the Supplicant with a device certificate or account to authenticate to the peer; in a few deployments the OLT uplink port acts as the Authenticator, admitting only authorized upstream devices. This step stops "illegal device jammed into the central-office uplink to steal traffic."
② ONU user ports transparently pass through; the OLT terminates the endpoint's 802.1X. A terminal (PC, camera) connects to the ONU LAN port; the ONU transparently passes the EAPOL messages to the OLT, which as the Authenticator sends the endpoint credentials up to RADIUS. This way the downstream terminal also enjoys certificate / account-level strong authentication, not just the ONU's SN registration. Rayin Mini GPON OLT series supports access control on both the uplink and the user-side service at the central office; combined with ONU passthrough it can extend 802.1X all the way to the terminal.
Do not confuse the two: PON-layer ONU bring-up relies on SN / LOID / Password registered in OMCI (governs "which ONU is legal"); Ethernet-layer 802.1X governs "by what credential does the terminal under the ONU / the upstream device communicate." They are different-layer doors, often stacked.
| Dimension | Industrial switch | OLT |
|---|---|---|
| Typical auth location | Access port (endpoint directly connected) | Uplink port + ONU-passthrough terminal port |
| Dumb-terminal handling | MAC Authentication Bypass whitelist | ONU passthrough + MAB, or rely on ONU registration alone |
| Authenticator role | Port is the Authenticator | Uplink can be Supplicant; user side is Authenticator |
| Fallback | Critical VLAN / shut port | Same, plus PON-layer SN registration as fallback |
| Common combo | 802.1X + MAB + port isolation | Uplink 802.1X + ONU registration + service VLAN |
802.1X answers "who may enter"; port isolation answers "once in, you only talk to the gateway, not your neighbor"; VLAN answers "which business domain do you enter." Stack the three: a camera enters the surveillance VLAN via MAB, port isolation guarantees it cannot ping the next IPC, and only the management VLAN reaches it for troubleshooting. Rayin industrial switches support 802.1X, MAB, and port isolation at the access layer together — this combination is the standard, near-mandatory access-layer security kit in factory scenarios.
Note: 802.1X, port isolation, and VLAN are complementary layers. 802.1X authenticates the device; port isolation contains lateral movement; VLAN assigns the business domain. Missing any one leaves a gap the other two cannot fully close.
| Method | Auth basis | Dumb-terminal support | Typical use |
|---|---|---|---|
| 802.1X | Username / certificate (EAP) | No, needs MAC Authentication Bypass | Office / terminal strong auth, OLT uplink |
| MAC binding | MAC address | Yes | Lightweight whitelist |
| Port isolation | Port policy | Yes | Same-segment inter-access restriction |
| Portal | Web account | Yes | Guest temporary access |
802.1X or MAC binding — which is better?
Strong identity wants 802.1X (certificate / account); dumb terminals can only do MAC Authentication Bypass or MAC binding. Production networks should run 802.1X + MAC Authentication Bypass together.
Can an OLT do 802.1X?
Yes. The uplink port authenticates against the core; ONU user ports transparently pass EAPOL and the OLT terminates the terminal's 802.1X — distinct from PON-layer SN registration.
What if a camera does not support 802.1X?
Use MAC Authentication Bypass, checking the MAC against a whitelist; no match → isolate or shut the port. In an OLT scenario you can also rely solely on legal ONU registration to admit it.
Does a RADIUS outage cut the whole network?
No — configure a Critical VLAN as fallback; the terminal enters a restricted domain while the physical link stays up.
What must the switch and OLT support?
They need EAPOL, a RADIUS client, MAB, and Critical VLAN. Managed switches essentially all have these; the OLT needs central-office firmware that supports uplink / user-side access control.
The access layer is the "access control" of the whole network; 802.1X authentication changes it from "plug in and use" to "credential-gated." Switches guard the directly-connected terminal port, OLTs guard the uplink and the ONU-passthrough terminal port; dumb terminals fall back to MAB, server failure falls back to a Critical VLAN, then stack port isolation and VLAN — industrial and PON access is truly contained. For more access-security capability, see the Rayin website.
Advanced VLAN: QinQ and Voice VLAN for Campus and Industrial Use
Isolate Multi-Service on a Passive Optical Network: VLAN and QoS
About the author: Sara — Sara is a Customer Manager at Rayin with over 10 years of experience in the communications field. In her free time, she enjoys badminton and swimming.
About Rayin: Shenzhen Rayin Technology Co., Ltd. — Company Profile