Operation Manual – 802.1x-System GuardH3C S3100 Series Ethernet Switches Chapter 1 802.1x Configuration1-21Caution:z The Guest VLAN function is available only when the switch operates in theport-based authentication mode.z Only one Guest VLAN can be configured for each switch.z The Guest VLAN function cannot be implemented if you configure the dot1xdhcp-launch command on the switch to enable DHCP-triggered authentication.This is because the switch does not send authentication packets unsolicitedly in thatcase.z This function is not supported on the S3100-C-EPON-EI Series Ethernet Switches.1.4.5 Configuring 802.1x Re-AuthenticationTable 1-7 Enable 802.1x re-authenticationOperation Command RemarksEnter system view system-view —In systemviewdot1x re-authenticate[ interface interface-list ]Enable802.1xre-authentication onport(s)In portview dot1x re-authenticateRequiredBy default, 802.1xre-authentication isdisabled on a port.Note:z To enable 802.1x re-authentication on a port, you must first enable 802.1x globallyand on the port.z When re-authenticating a user, a switch goes through the complete authenticationprocess. It transmits the username and password of the user to the server. Theserver may authenticate the username and password, or, however, usere-authentication for only accounting and user connection status checking andtherefore does not authenticate the username and password any more.z An authentication server running CAMS authenticates the username and passwordduring re-authentication of a user in the EAP authentication mode but does not inPAP or CHAP authentication mode.1.4.6 Configuring the 802.1x Re-Authentication TimerAfter 802.1x re-authentication is enabled on the switch, the switch determines there-authentication interval in one of the following two ways: