I am using my own Radius Server Proxy to authenticate 802.1x packets from Zone Director radius client. My server sits between Windows Access Control Server and The Zone Director and I add dynamic VLAN attributes and re calculate message authenticator in VSA's before sending Access Accept. Somehow the EAP is successful but the 4 step handshake doesn't work and I get multiple request access message chain again. What am I doing wrong here !