Central NAC Onboard - 802.1X Authentication Resilience to Latency

This test case simulates real-world round-trip time (RTT) conditions and allows us to observe client device behaviour under varying latency levels

Evaluating Client-Side Authentication Resilience to Latency

After the Onboarding process to evaluate client-side authentication resilience to latency for 802.1X authentication against Central NAC we will introduce artificial latency in lab environment to deliberately introduce network latency between the Access Point (AP) and the authentication servers. This setup simulates real-world round-trip time (RTT) conditions and allows us to observe client device behaviour under varying latency levels. The goal is to determine how client devices respond as latency increases and to identify the threshold at which authentication begins to fail or exhibit degraded performance.

Control Scenario: No Latency Introduced

This section outlines the behavior of the client device during 802.1X authentication under ideal network conditions, where no artificial latency is introduced. Observations made here reflect the expected performance in a low-latency, well-connected environment, helping to highlight deviations in client behavior when latency is later introduced.

In the scenario below, the test environment exhibits an ICMP round-trip time (RTT) of less than 20 ms between the access point (AP) and a public server. This value may vary depending on the geographic location and the uplink quality provided by the Internet Service Provider (ISP). Under these ideal conditions, the client takes approximately 3 seconds to complete association and 802.1X authentication on the designated SSID, as provisioned by the HPE Aruba Networking Onboarding app.



ICMP RTT under ideal conditions between AP and a public server
ICMP RTT under ideal conditions between AP and a public server




Client connects to the SSID within 3 seconds
Client connects to the SSID within 3 seconds


Control Scenario: 100ms Latency Introduced

In the scenario below, the test environment has an ICMP round-trip time (RTT) of approximately 100 ms between the access point (AP) and a public server. Under these conditions, the client takes around 4 seconds to complete association and 802.1X authentication to the SSID.

ICMP RTT of 100ms
ICMP RTT of 100ms




Client connects to the SSID within 4 seconds
Client connects to the SSID within 4 seconds


Control Scenario: 250ms Latency Introduced

In the scenario below, the test environment has an ICMP round-trip time (RTT) of approximately 250 ms between the access point (AP) and a public server. Under these conditions, the client takes around 5 seconds to complete association and 802.1X authentication to the SSID.

ICMP RTT of 250ms
ICMP RTT of 250ms




Client takes 5 seconds to connect to the SSID
Client takes 5 seconds to connect to the SSID


Control Scenario: 500-750ms Latency Introduced

In the scenario below, the test environment exhibits an ICMP round-trip time (RTT) ranging between 500 ms and 750 ms between the access point (AP) and a public server. Under these conditions, the client takes approximately 9 to 11 seconds to complete association and 802.1X authentication to the SSID.

ICMP RTT of 500ms
ICMP RTT of 500ms




Client takes 9 seconds to connect to the SSIDs
Client takes 9 seconds to connect to the SSIDs




ICMP RTT of 750ms
ICMP RTT of 750ms




Client takes 11 seconds to connect to the SSIDs
Client takes 11 seconds to connect to the SSIDs


Control Scenario: 1000ms Latency Introduced

In the scenario below, the test environment exhibits an ICMP round-trip time (RTT) of approximately 1000 ms between the access point (AP) and a public server. Under these conditions, we observe that after multiple attempts to connect to the SSID, the 802.1X authentication process times out after approximately one minute.

ICMP RTT of 1000ms
ICMP RTT of 1000ms




802.1X authentication process times out
802.1X authentication process times out




802.1X authentication process times out
802.1X authentication process times out


Conclusion

The results demonstrate that while our authentication infrastructure is capable of supporting high-latency networks, consistent client authentication performance begins to degrade beyond certain thresholds. Based on observed client behavior across varying latency scenarios, it is recommended that the round-trip latency between the access point and the authentication servers not exceed 250 ms to ensure reliable and timely 802.1X authentication. Staying within this latency range provides optimal performance and reduces the likelihood of timeouts or excessive retries during client onboarding.


Last modified: January 30, 2026 (7f47842d)