802.1X from the switch perspective is port authentication, but the VLAN will be assigned based on information returned from the RADIUS server.
The radius server must be configured to return IETF attributes  Tunnel-Type,  Tunnel-Medium-Type, and  Tunnel-Private-Group-ID.
The following link describes 802.1X configuration including the assignments of VLANs using 802.1X.
The following is an article about 802.1X that may also be beneficial. Section 3 describes the configuration of the switch and attributes of the RADIUS server
You may want to reference the following for information about configuring ACS to use the Windows database.
As for setting up VLAN using users or groups that depends on how you choose to set up the IETF attributes. After you get a database defined, you will need to set up the attributes in the Radius server to return the VLAN settings this could be done on a user basis or a group basis. This document describes the attributes.
Recall from the configuring 802.1X documentation
that the following parameters must be configured to return the VLAN.
 Tunnel-Type = VLAN
 Tunnel-Medium-Type = 802
 Tunnel-Private-Group-Id = VLAN NAME
These are the IETF attributes that you will need to configure for the user or group on the server.
my catos is 7.31,I have these commands in it:
set interface sc0 2 192.168.1.2 255.255.255.0
set radius server 192.168.1.11
set radius key cisco123
set dot1x system-auth-control enable
set port dot1x 3/26 port-control auto
then I can ping 192.168.1.11,but always I failed to authen in a XP NOTEBOOK,I don't know how to debug it in catos,bug I can see the failed attemps in ACS:
just unknown NAS,no username and time
in the process of install ACS,one place I select "ietf radius" but not the "cisco tacacs+ server",and another place I select "win2k username database" but not cisco security database
what can I do now?int acs,I just check the 64,65&81,anything else should I check?
I found that sometime I can log in with 802.1x,but sometime can't,after my first login successfully,I unplued the cable and plug it into another vlan(at the same time,I change the ip address),in xp,the local connection seems"authenticating",but it doesnot give the chance to input password and username,and after a long time,the local connection has been disabled,I can't enable it,and I found that in the acs's failed attemps,there is the record"username azbycx",but there is no username azbycx,why?
my acs is 3.01,installed pc is win2k chinese version with sp2,its ie is 5.00 with sp2
doesnot say acs 3.0x must be installed in english version win2k server