Home Support Blog

802.1X Port Authentication on Switches and OLTs: A Practical Guide

Release date:2026-09-14

Plug in a cable and you are on the network? On a factory floor, a campus access layer, or a PON central office, that is more realistic than many expect. A new camera defaults to full network access; a visitor's laptop on a desk port reaches the core; someone even jams an illegal device into the OLT uplink to steal bandwidth. 802.1X authentication changes the default-open door into credential-gated access — and it guards not only switches but also the OLT uplink port and the terminal ports hanging off an ONU.

KEY TAKEAWAYS
  • 802.1X is port-based: a port stays unauthorized until the endpoint authenticates; only then does business traffic flow.

  • Three roles: Supplicant (endpoint), Authenticator (switch / OLT), Authentication Server (RADIUS / AAA).

  • Dumb terminals (cameras, PLCs) that cannot run 802.1X fall back to MAC Authentication Bypass (MAB).

  • If RADIUS dies, a Critical VLAN (or port shutdown) keeps the link from becoming an open door.

  • On the OLT: the uplink port authenticates against the core, and ONU user ports transparently pass EAPOL so the OLT terminates the endpoint's 802.1X — distinct from PON-layer ONU registration (SN / LOID).

802.1X manages the "port"

Strictly, 802.1X is Port-Based Network Access Control. It puts a physical (or logical) port of a switch or OLT into two states: unauthorized (before authentication) and authorized (after). An endpoint that has not authenticated — cable plugged in, NIC light on — is only allowed traffic to the authentication server; all business data is blocked at the door.

image

Three roles, do not confuse them

  • Supplicant: the endpoint wanting on the network — a PC, a camera, a device under an ONU — running the EAPOL client.

  • Authenticator: the device between endpoint and network — an industrial switch or OLT — that forwards authentication messages.

  • Authentication Server: usually RADIUS (AAA), the one that actually decides "can this endpoint in?"

The industrial switch is always the Authenticator; it stores no usernames or passwords, it only forwards the endpoint's credentials to RADIUS for a verdict.

What one authentication looks like

Endpoint connects → port starts unauthorized → endpoint sends EAPOL-Start → Authenticator forwards to RADIUS → the two walk the EAP handshake (PEAP / MS-CHAPv2 most common, EAP-TLS certificate in high-security scenes) → on pass, RADIUS returns Access-Accept and the port flips to authorized. The idea is the same as "enter password then join Wi-Fi," just moved to the wired port. Authentication only happens at connect time; once authorized, normal forwarding, no added latency.

MAC Authentication Bypass as a safety net

Cameras, PLCs, and door controllers on a factory floor are mostly "dumb terminals" — no 802.1X client in firmware. Ask them to do an EAP handshake and they only send DHCP. That is where MAC Authentication Bypass (MAB) comes in: when the Authenticator sees a terminal that will not do 802.1X, it uses the terminal's MAC address as the account to check against the RADIUS whitelist; match → admit, no match → drop to an isolated VLAN or shut the port. For production networks we recommend running 802.1X + MAC Authentication Bypass together.

What if RADIUS goes down

The authentication server is not immortal. When RADIUS is unreachable, the port policy must be decided in advance:

  • Critical VLAN: temporarily place the endpoint in a restricted VLAN (reach only the ops segment) — business is impaired but not fully cut.

  • Or configure auth-fail to simply shut the port.

  • Never "if server unreachable, open everything" — that makes 802.1X meaningless.

    image

802.1X on the OLT

Unpacking OLT port authentication, it is useful in at least two places, and it is a different matter from PON-layer ONU registration.

① OLT uplink port authenticates against the core. When the OLT uplinks to a BRAS / core switch, the core side can require port-level authentication. The OLT uplink port enables 802.1X; the OLT acts as the Supplicant with a device certificate or account to authenticate to the peer; in a few deployments the OLT uplink port acts as the Authenticator, admitting only authorized upstream devices. This step stops "illegal device jammed into the central-office uplink to steal traffic."

② ONU user ports transparently pass through; the OLT terminates the endpoint's 802.1X. A terminal (PC, camera) connects to the ONU LAN port; the ONU transparently passes the EAPOL messages to the OLT, which as the Authenticator sends the endpoint credentials up to RADIUS. This way the downstream terminal also enjoys certificate / account-level strong authentication, not just the ONU's SN registration. Rayin Mini GPON OLT series supports access control on both the uplink and the user-side service at the central office; combined with ONU passthrough it can extend 802.1X all the way to the terminal.

Do not confuse the two: PON-layer ONU bring-up relies on SN / LOID / Password registered in OMCI (governs "which ONU is legal"); Ethernet-layer 802.1X governs "by what credential does the terminal under the ONU / the upstream device communicate." They are different-layer doors, often stacked.

Switch vs OLT: how 802.1X sits

DimensionIndustrial switchOLT
Typical auth locationAccess port (endpoint directly connected)Uplink port + ONU-passthrough terminal port
Dumb-terminal handlingMAC Authentication Bypass whitelistONU passthrough + MAB, or rely on ONU registration alone
Authenticator rolePort is the AuthenticatorUplink can be Supplicant; user side is Authenticator
FallbackCritical VLAN / shut portSame, plus PON-layer SN registration as fallback
Common combo802.1X + MAB + port isolationUplink 802.1X + ONU registration + service VLAN

How it combines with port isolation and VLAN

802.1X answers "who may enter"; port isolation answers "once in, you only talk to the gateway, not your neighbor"; VLAN answers "which business domain do you enter." Stack the three: a camera enters the surveillance VLAN via MAB, port isolation guarantees it cannot ping the next IPC, and only the management VLAN reaches it for troubleshooting. Rayin industrial switches support 802.1X, MAB, and port isolation at the access layer together — this combination is the standard, near-mandatory access-layer security kit in factory scenarios.

Note: 802.1X, port isolation, and VLAN are complementary layers. 802.1X authenticates the device; port isolation contains lateral movement; VLAN assigns the business domain. Missing any one leaves a gap the other two cannot fully close.

How to choose an access-control method

MethodAuth basisDumb-terminal supportTypical use
802.1XUsername / certificate (EAP)No, needs MAC Authentication BypassOffice / terminal strong auth, OLT uplink
MAC bindingMAC addressYesLightweight whitelist
Port isolationPort policyYesSame-segment inter-access restriction
PortalWeb accountYesGuest temporary access

FAQ

802.1X or MAC binding — which is better?

Strong identity wants 802.1X (certificate / account); dumb terminals can only do MAC Authentication Bypass or MAC binding. Production networks should run 802.1X + MAC Authentication Bypass together.

Can an OLT do 802.1X?

Yes. The uplink port authenticates against the core; ONU user ports transparently pass EAPOL and the OLT terminates the terminal's 802.1X — distinct from PON-layer SN registration.

What if a camera does not support 802.1X?

Use MAC Authentication Bypass, checking the MAC against a whitelist; no match → isolate or shut the port. In an OLT scenario you can also rely solely on legal ONU registration to admit it.

Does a RADIUS outage cut the whole network?

No — configure a Critical VLAN as fallback; the terminal enters a restricted domain while the physical link stays up.

What must the switch and OLT support?

They need EAPOL, a RADIUS client, MAB, and Critical VLAN. Managed switches essentially all have these; the OLT needs central-office firmware that supports uplink / user-side access control.

Conclusion

The access layer is the "access control" of the whole network; 802.1X authentication changes it from "plug in and use" to "credential-gated." Switches guard the directly-connected terminal port, OLTs guard the uplink and the ONU-passthrough terminal port; dumb terminals fall back to MAB, server failure falls back to a Critical VLAN, then stack port isolation and VLAN — industrial and PON access is truly contained. For more access-security capability, see the Rayin website.

Related Reading

About the author: Sara — Sara is a Customer Manager at Rayin with over 10 years of experience in the communications field. In her free time, she enjoys badminton and swimming.

Connect with Sara on LinkedIn


About Rayin: Shenzhen Rayin Technology Co., Ltd. — Company Profile

Get A Quote

You have agreed to this website’s《Privacy Policy》