I understand that if we implement 802.1x, our edge switches must support and be configured for 802.1x, but what are the requirements for switches between the edge switches and the Remote Authentication Dial-In User Service (RADIUS) servers the edge switches use for authentication? Do all the switches on our network need to support and be configured for 802.1x?
Intermediate switches don't need to support or be configured for 802.1x. The only switches that must support 802.1x are the ones on which you implement switch-port access control. The 802.1x protocol functions only on the wire between the computer connected to the switch port and the switch port itself. The only communication between the edge switch and the RADIUS server consists of RADIUS packets on UDP port 1812.