Eu consegui resolver isso agora (ou principalmente). As portas estão sendo corretamente atribuídas às VLANs como resultado da autenticação RADIUS, no entanto, por algum motivo, depois que o dispositivo é atribuído a um endereço IP do nosso servidor DHCP, nenhum outro tráfego é encaminhado.
Provavelmente, meu roteamento de VLAN está errado ou não estou passando corretamente o tráfego de VLAN nas portas de tronco.
Para qualquer pessoa que encontre isso via google, minha (principalmente) configuração de trabalho é a seguinte:
interface range ethernet all
spanning-tree portfast
exit
interface range ethernet e(1-24)
dot1x multiple-hosts authentication
exit
interface range ethernet g(1-4)
switchport mode trunk
exit
vlan database
vlan 2-6,9-11
exit
interface range ethernet g(1-4)
switchport trunk allowed vlan add 2
exit
interface range ethernet g(1-4)
switchport trunk allowed vlan add 3
exit
interface range ethernet g(1-4)
switchport trunk allowed vlan add 4
exit
interface range ethernet g(1-4)
switchport trunk allowed vlan add 5
exit
interface range ethernet g(1-4)
switchport trunk allowed vlan add 6
exit
interface range ethernet g(1-4)
switchport trunk allowed vlan add 9
exit
interface range ethernet g(1-4)
switchport trunk allowed vlan add 10
exit
interface range ethernet g(1-4)
switchport trunk allowed vlan add 11
exit
interface vlan 2
name netman
exit
interface vlan 3
name lt-sys
exit
interface vlan 4
name pub-sys
exit
interface vlan 5
name lt-clients
exit
interface vlan 6
name guest
exit
interface vlan 9
name lt-voip
exit
interface vlan 10
name lt-print
exit
interface vlan 11
name lt-wifi
exit
interface vlan 6
dot1x guest-vlan
exit
dot1x system-auth-control
interface range ethernet e(1-24)
dot1x re-authentication
exit
interface range ethernet e(1-24)
dot1x max-req 3
exit
interface range ethernet e(1-24)
dot1x mac-authentication mac-and-802.1x
exit
interface range ethernet e(1-24)
dot1x radius-attributes vlan
exit
interface range ethernet e(1-24)
dot1x port-control auto
exit
interface range ethernet e(1-24)
dot1x guest-vlan enable
exit
interface vlan 2
ip address 10.58.2.99 255.255.255.0
exit
hostname sw-1-2
radius-server host 10.58.2.128 key switch priority 2
radius-server host 10.58.3.132 key switch priority 1
aaa authentication dot1x default radius
username bryan password password-hash-was-here level 15 encrypted
clock source sntp
sntp server 10.58.3.128 poll
ip domain-name liketechnologies.local
ip name-server 10.58.3.32 10.58.3.33