80Enabling the quiet timerAfter the quiet timer is enabled on the switch, when a client fails 802.1X authentication, the switchrefuses further authentication requests from the client in a period of time, which is specified by thequiet timer (using the dot1x timer quiet-period command).Follow these steps to enable the quiet timer:To do… Use the command… Remarks1. Enter system view system-view —2. Enable the quiet timer dot1x quiet-period RequiredDisabled by defaultEnabling the re-authentication functionIf periodic re-authentication is enabled on a port, the switch will re-authenticate online users on theport at the interval specified by the periodic re-authentication timer. This is intended to track theconnection status of online users and update the authorization attributes assigned by the server,such as the VLAN and QoS Profile, ensuring that the users are in normal online state.Follow these steps to enable the periodic re-authentication function:To do… Use the command… Remarks1. Enter system view system-view —2. Enter Ethernet interface view interface interface-type interface-number —3. Enable periodic re-authentication dot1x re-authenticate RequiredDisabled by default• After an 802.1X user passes authentication, if the authentication server assigns a re-authentication intervalfor the user through the session-timeout attribute, the assigned re-authentication interval will take effectinstead of that specified on the switch. The re-authentication interval assignment varies by server type. Formore information, see the specific authentication server implementation.• VLAN information assigned to the same user before and after re-authentication can be different.However, if the server assigns VLAN information before re-authentication, it must assign that informationafter re-authentication; if the server assigns no VLAN information before re-authentication, it cannotassign that information after re-authentication.Configuring a guest VLAN• If the traffic from a user-side switch carries VLAN tags and the 802.1X authentication and guest VLANfunctions are configured on the access port, it is recommended to configure different VLAN IDs for thedefault VLAN of the port, and 802.1X guest VLAN. This is to ensure the normal use of the functions.