Hi Theeradet,
Assuming you are using an internal PKI for your certificates.
Did you check for PKI health? e.g. CRL, Delta CRL, ocsp? what are you using for RADIUS? Did you check radius logs for authentication errors rather than just changes? What events were recorded on the client side?
Regards,