Passbeam

Which switches do 802.1X properly, and which ignore re-authentication?

Passbeam works with any switch that speaks 802.1X to a RADIUS server, but switches differ in one thing that matters after the device is already connected: whether they re-authenticate. This table is what we have measured on our own hardware, and it is worth a minute before you rely on revocation being immediate.

Why re-authentication is the one to care about. A certificate is checked when a device joins. Revoking it stops the next join — it does not reach a link that is already up. So Passbeam asks the switch to re-run the check on a timer, by sending Session-Timeout with Termination-Action = RADIUS-Request on every accept. On equipment that honours it, a revoked certificate is off the network within the hour and nobody notices the re-check. On equipment that ignores it, the device keeps the access it was given until the port cycles — and this is invisible from the dashboard, which will show the certificate revoked while the device is still connected.

Where a switch ignores the timer, suspending the person or device in Entra ID still works exactly as it should; it simply does not take effect when you would expect. If that matters on a given site, the reliable lever is the port — bouncing it forces a fresh authentication.

Measured on our own hardware unless the row says otherwise. Dates matter — firmware changes.
Equipment802.1XRe-authenticates on our timerHow we know
UniFi USW Pro 48 PoEYesYes — hourly, on the dotMeasured 1 Sep 2026: 31 re-authentications over four days on a 3600s timer
UniFi US-8-150WYesNot measuredAuthenticated a printer on the first attempt; the interval was never timed
UniFi US-8-60W (Gen 1)YesNoMeasured 1 Sep 2026: 2 accepts over the same four days, on the same 3600s timer, against the Pro 48's 31
UniFi USW Ultra and Flex MiniNo — the setting does not existUbiquiti documents these two families as the exception; confirmed on a USW Ultra 60W, where there is nothing to switch on
Netgear GS724Tv4Setting exists, sends nothingMeasured: a complete, correct configuration, port reported Held, and zero Access-Requests ever left the switch

Check your own rather than trusting this table. Set a re-authentication interval on the client's Access rules, then open the authentication log and count the accepts for one device over a few hours. One accept proves nothing — an interval needs two to show itself. If a device that has been connected all day has a single accept, that switch is not re-authenticating, whatever its datasheet says.

Anything not listed is almost certainly fine: this table exists because of the exceptions, not because support is narrow. See “Which switches and access points does Passbeam support?” for the general answer.

Related questions

Still stuck? Ask us, or read the rest of the knowledge base.