1-22z The guest VLAN function is available only when the switch operates in the port-basedauthentication mode.z Only one guest VLAN can be configured for each switch.z The guest VLAN function cannot be implemented if you configure the dot1xdhcp-launch command on the switch to enable DHCP-triggered authentication. This isbecause the switch does not send authentication packets in that case.Configuring 802.1x Re-AuthenticationFollow these steps to enable 802.1x re-authentication:To do... Use the command... RemarksEnter system view system-view —In system view dot1x re-authenticate[ interface interface-list ]Enable 802.1xre-authenticationon port(s) In port view dot1x re-authenticateRequiredBy default, 802.1xre-authentication isdisabled on a port.z To enable 802.1x re-authentication on a port, you must first enable 802.1x globally andon the port.z When re-authenticating a user, a switch goes through the complete authenticationprocess. It transmits the username and password of the user to the server. The servermay authenticate the username and password, or, however, use re-authentication foronly accounting and user connection status checking and therefore does notauthenticate the username and password any more.z An authentication server running CAMS authenticates the username and passwordduring re-authentication of a user in the EAP authentication mode but does not in PAPor CHAP authentication mode.Configuring the 802.1x Re-Authentication TimerAfter 802.1x re-authentication is enabled on the switch, the switch determines there-authentication interval in one of the following two ways:z The switch uses the value of the Session-timeout attribute field of the Access-Accept packet sent by theRADIUS server as the re-authentication interval.z The switch uses the value configured with the dot1x timer reauth-period command as there-authentication interval for access users.Note the following: