You'll want to build an access policy that uses RADIUS and 802.1x. For all the other configurables, have a look at the doc @ww provided and make a call on what suites your environment best. As for the auth based on device certificate and MAC address, those policies are configured on the RADIUS server as it will be performing the checks. It will then return and pass or fail, along with the corresponding vlan attribute for that device to be placed in.
... View more