Experimental Implementation of Network Access Control with Dynamic VLAN Assignment Using Active Directory, Windows NPS, RADIUS, and IEEE 802.1X
This paper presents and empirically validates an end-to-end Network Access Control architecture that integrates Active Directory, Microsoft NPS, and Cisco IOSvL2 switches to dynamically assign users to specific VLANs based on group membership via IEEE 802.1X authentication, demonstrating 100% success in valid authentication and effective isolation of unauthorized or failed attempts in a virtualized laboratory environment.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
In the digital world of a large organization, the network is the invisible highway that carries every email, file transfer, and video call. For decades, the way this highway was managed was surprisingly simple and static: a physical cable plugged into a wall port determined exactly where a computer could go. If that port was wired to a specific section of the network, anyone who plugged a device into it gained access to that entire section, regardless of who they were. This approach relied entirely on physical security; if an unauthorized person could reach the wall jack, they could walk right into the company's private data. As organizations grew more complex, with employees, students, and guests all needing different levels of access, this "plug-and-play" method became a significant weakness. The solution lies in making the network smart enough to ask, "Who are you?" before it opens the gate, and then directing that person to the specific room they are allowed to enter, rather than leaving the door wide open for anyone with a key.
This is the challenge addressed by a recent study conducted by Abdulraheem Hamoud Mohammed Almaweri at the Académie des sciences et technologies industrielles in Djibouti. The researcher set out to build and test a system that replaces the old, static method with a dynamic one. In this new approach, a computer connects to the network, and the network immediately asks for proof of identity. If the user provides valid credentials, the system checks their role within the organization and automatically assigns them to the correct digital zone. If the user is a staff member, they are sent to the staff network; if they are a student, they are sent to the student network. If the user cannot prove who they are, or if the system that checks their identity goes offline, the network does not simply let them in or leave them stranded. Instead, it gently moves them to a holding area, a digital waiting room where they can be fixed or inspected without risking the rest of the system.
To test if this complex chain of events could work reliably, the researcher built a complete, virtual laboratory. This was not a small experiment with a single computer; it was a full-scale simulation of a corporate network. The setup included a central server acting as the identity keeper, a policy server that made the rules, and a network switch that controlled the physical ports. The researcher created two distinct groups of users: one group representing staff and another representing students. Each group was assigned to a different digital zone, known as a VLAN, which acts like a separate, invisible room within the same building. The staff group was mapped to one room, and the student group to another. The system was designed to use a secure handshake protocol, where the computer and the server exchange encrypted messages to verify identity before any data is allowed to pass.
The researcher then ran a series of twenty-five tests to see how the system behaved under different conditions. In the first set of tests, valid users from both the staff and student groups logged in with their correct passwords. In every single instance, the system successfully identified them and placed them into their correct digital room. The staff members were consistently directed to the staff zone, and the students to the student zone. The speed of this process was also measured. From the moment a user connected their cable to the moment they were granted access, the entire process took just over one and a half seconds. This is fast enough that a human user would not notice any delay, making the security invisible to daily work.
The study did not stop at successful logins; it specifically tested what happens when things go wrong. In one scenario, a user entered the correct username but the wrong password. In another, a user tried to log in with an account that did not belong to any authorized group. In both cases, the system correctly rejected the attempt. Instead of leaving the user with no access or accidentally letting them into the wrong area, the network automatically moved their connection to a quarantine zone. This is a safe, isolated area where the user can be investigated or helped without being able to touch the sensitive parts of the network. The system performed this containment perfectly every time the password was wrong or the account was unauthorized.
Perhaps the most critical test involved simulating a failure of the central authority itself. The researcher turned off the server that was responsible for checking identities, leaving the network switch with no one to ask for permission. In a poorly designed system, this might cause the switch to panic and open all the doors, or to lock everyone out completely. In this experiment, the switch was configured with a safety net. When it realized the server was unreachable, it waited a few seconds and then automatically moved all new connections to the same quarantine zone. This ensured that even when the brain of the system was asleep, the body of the network remained secure, preventing unauthorized access while keeping the door open for remediation.
The results of the twenty-five trials were consistent and clear. The system successfully directed authorized users to their correct zones, rejected unauthorized users, and safely contained failures in every single attempt. The researcher noted that while the system worked perfectly in this controlled environment, the small number of tests means that while the mechanism is proven to work, its long-term reliability in a massive, real-world network would require further study. The study did not claim to have solved every possible security problem, nor did it test every type of authentication method. It focused specifically on proving that a system built from standard, off-the-shelf components could successfully link a user's identity to their network location dynamically.
The findings offer a practical blueprint for how organizations can move away from the old, rigid way of managing network access. By proving that a user's digital location can follow their identity rather than their physical plug, the study demonstrates a path toward networks that are both more secure and more flexible. The system showed that it is possible to build a network that knows who you are, treats you according to your role, and protects itself when things go wrong, all without the user needing to understand the complex machinery working behind the scenes. For the curious observer, the experiment confirms that the dream of a network that adapts to its users, rather than forcing users to adapt to the network, is not just a theoretical idea but a working reality that can be built today.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.