A transport profile (RFC 6614) that wraps RADIUS in a TLS connection over TCP port 2083, giving the protocol proper encryption and certificate-based mutual authentication between clients and servers. It solves classic RADIUS's weak shared secrets and cleartext attributes, and is the standard way to carry RADIUS safely across the internet — for example between a site and a cloud RADIUS service.
RadSec
RADIUS over TLS