RADIUS, LDAP, DIAMETER, sflow, TACAS+, SNMP (all versions), UPS, lights-out management, and similar should never-ever be deployed to public-facing networks. These should remain segregated on internal VLANs used for infrastructure only.<p>For wireless 802.1x, use clients certs; managed campus APs may still need a tunnel to a RADIUS box, but that's okay.