The de facto standard AAA (authentication, authorisation, accounting) protocol used by network equipment to check user and device credentials against a central server. In 802.1X deployments the switch or access point acts as a RADIUS client, forwarding EAP messages to the RADIUS server and enforcing its accept/reject decision. Classic RADIUS runs over UDP ports 1812/1813 and only obfuscates passwords rather than encrypting the whole conversation.