Guys,
I have been in the 802.1x arena for quite a while. My suggestions on a security level are:
1. Use 40-bit WEP. This keeps the yahoos off your network that are not trying to get in.
2. Use IPSec. This is encrypted IP traffic. Hell, that is encryption inside of encryption. Hack that.
3. If you use W2K Server for DHCP, make it issue certificates and ONLY register the MAC addresses you know and block the others.
THis will allow others to sniff the airwaves, but doubtfully get any usable information.