You need to enable port security on you catalyst switches, using 802.1x
If port security is enabled for only one Media Access Control (MAC) address on the port, only that MAC address will authenticate via the RADIUS server. All other MAC users will be denied access, which eliminates the security risk of additional users attaching to a switch to bypass authentication. When 802.1X with port security is implemented in the multiple authentication mode, all hosts attempting to connect through a switch port will be required to authenticate using 802.1X.
hope this helps,
Rowan