hi, you wouldnt be able to have the post in shutdown mode - or EAP would never be undertaken.
you need to configure the cisco switch so that it does 802.1x authentication (see cisco docs on how to configure the switch for 802.1x and for RADIUS) then you simply configure FreeRADIUS to send back the VLAN attribute - the switch can be configured so that no EAP or unsuccesful EAP gets different VLAN alan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

