EAP - Extensible Authentication Protocol - is used in network authentication strategies such as IEEE-802.1x (for wired and wireless networks) and for authentication for VPNs. EAP authentication relies on EAP implementation methods such as EAP-TLS and EAP-PEAP and others to authenticate accessing endpoint devices. When implemented correctly (and with related controls) EAP as used in 802.1x can be an effective strategy for layer 2 authentication for network mediums. Unfortunately, the security qualities of EAP methods vary widely with some more being more effective than others. EAP implementations for VPN, wired and wireless network authentication also vary widely and, because of WPA/WPA2’s use of EAP in wireless solutions, some poor presumptions and myths exist about the effectiveness of all EAP implementations. This brief talk illustrates threats to EAPoL (EAP over LAN) solutions by examining network packet captures on each side of the solution - between the accessing client’s supplicant software and the network device and that device and its authentication source. If you like long walks on the beach and tedious walks through gory network packet details, this talk is your jam.