How about authenticated VLANS on switches? It takes a client and runs through either LDAP or Radius.