I'd be glad if someone could point me to the right track for getting a clear picture of failed authentications with a 2960, 802.1X and EAP-TLS. I've assigned guest vlans to the switch-ports and I'm able to see successfull authentications in the (free)radius-server logs, but I don't see any message in logs if a client is assigned to the guest-vlan. One might say, this is part of the radius-server, agreed, but what if the client does not even try to authenticate with dot1x, because it may lack this function, or uses another method by default? Is anyone else here, who made a similar experience within a bigger installation and solved this? Maybe SNMP-Traps are an Option here? I'd simply like to see what's going on.