说明:
AC与AP属于不同的网段
vlan2:AP1管理vlan
vlan3: AP2管理vlan
vlan100:AC1管理网段
vlan10:业务网段1
vlan20:业务网段2
AC1: 是AP1/AP2的DHCP服务器
SW1:是STA1/STA2的DHCP服务器
vlan200:与路由器互联网段
默认AP工作在vlan1
目的:
1.实现全网互通;
2.AP接入采用MAC认证;
3.ssid A 的业务流量采用隧道转发;
4.ssid B 的业务流量采用直接转发;
5.交换机端口放行必要vlan.
步骤一:配置全网互通
sw1:
sysname sw1
#
dhcp enable
#
vlan batch 2 to 3 10 20 100 200
#
interface Vlanif2
ip address 10.2.1.254 255.255.255.0
dhcp select relay
dhcp relay server-ip 10.100.1.1
#
interface Vlanif3
ip address 10.3.1.254 255.255.255.0
dhcp select relay
dhcp relay server-ip 10.100.1.1
#
interface Vlanif10
ip address 10.10.1.254 255.255.255.0
dhcp select interface
#
interface Vlanif20
ip address 10.20.1.254 255.255.255.0
dhcp select interface
#
interface Vlanif100
ip address 10.100.1.254 255.255.255.0
#
interface Vlanif200
ip address 10.200.1.2 255.255.255.252
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 200
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 10 20 100
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 2 10 20
#
interface GigabitEthernet0/0/4
port link-type trunk
port trunk allow-pass vlan 3 10 20
#
ospf 1 router-id 10.1.1.1
area 0.0.0.0
network 10.200.1.2 0.0.0.0
network 10.10.1.254 0.0.0.0
network 10.20.1.254 0.0.0.0
R1:
interface GigabitEthernet0/0/0
ip address 10.200.1.1 255.255.255.252
#
interface LoopBack0
ip address 8.8.8.8 255.255.255.255
#
ospf 1 router-id 8.8.8.8
area 0.0.0.0
network 8.8.8.8 0.0.0.0
network 10.200.1.1 0.0.0.0
sw2:
sysname sw2
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 10 20 \\业务隧道模式转发只需放行vlan2;业务是直接转发只需放行vlan10 20;在这里我们为今后扩展性考虑放行2 10 20
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk pvid vlan 2
port trunk allow-pass vlan 2 10 20
sw3:
sysname sw3
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 3 10 20
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk pvid vlan 3
port trunk allow-pass vlan 3 10 20
AC1:
sysname AC
#
vlan batch 10 20 100
#
dhcp enable
#
ip pool vlan2
gateway-list 10.2.1.254
network 10.2.1.0 mask 255.255.255.0
option 43 sub-option 2 ip-address 10.100.1.1 \\在给ap分配IP的同时告知ap我(ac)的地址【著名的dhcp option43字段】
#
ip pool vlan3
gateway-list 10.3.1.254
network 10.3.1.0 mask 255.255.255.0
option 43 sub-option 2 ip-address 10.100.1.1
#
interface Vlanif100
ip address 10.100.1.1 255.255.255.0
dhcp select global
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20 100 \\理解的难点,业务采用隧道模式转发情况下,在ac处解封装,里层包含了vlan10 与vlan 20的数据包,所以需要放行 10 20
#
ip route-static 0.0.0.0 0.0.0.0 10.100.1.254
步骤二:配置AP上线
[AC]wlan
[AC-wlan-view]regulatory-domain-profile name cn \\创建域管理模板
[AC-wlan-regulate-domain-cn]country-code cn \\创建国家代码
--------------------------------------------------------------------------
[AC-wlan-view]ap-group name test \\创建AP组
[AC-wlan-ap-group-test]regulatory-domain-profile cn \\AP组套用域管理模板
--------------------------------------------------------------------------
[AC]capwap source ip-address 10.100.1.1 \\创建capwap隧道指定源地址(或源接口这里源接口是vlanif100)
--------------------------------------------------------------------------
[AC-wlan-view]ap auth-mode mac-auth \\AP接入方式MAC认证
[AC-wlan-view]ap-id 1 ap-mac 00e0-fc0a-7db0
\\查看ap的mac地址是在ap上输入命令:display interface Vlanif 1
[AC-wlan-ap-1]ap-group test \\加组
[AC-wlan-view]ap-id 2 ap-mac 00e0-fc99-1410
[AC-wlan-ap-2]ap-group test
[AC-wlan-view]ap-id 1 \\给AP命名(小优化)
[AC-wlan-ap-1]ap-name ap1
[AC-wlan-view]ap-id 2
[AC-wlan-ap-2]ap-name ap2
-------------------------------------------------------------------------
完成以上步骤AP就可以上线,需要注意如果ac先配置DHCP后配置option43需要重启AP使得AP在获取IP的同时知道AC的IP
<AC>dis ap all
Info: This operation may take a few seconds. Please wait for a moment.done.
Total AP information:
nor : normal [2]
--------------------------------------------------------------------------------
-----
ID MAC Name Group IP Type State STA Uptime
--------------------------------------------------------------------------------
-----
1 00e0-fc0a-7db0 ap1 test 10.2.1.187 AP3030DN nor 0 2M:44S
2 00e0-fc99-1410 ap2 test 10.3.1.251 AP3030DN nor 0 1M:45S
--------------------------------------------------------------------------------
步骤三:配置业务上线
[AC]wlan
[AC-wlan-view]security-profile name AB \\创建安全模板
[AC-wlan-sec-prof-AB]security wpa2 psk pass-phrase huawei@123 aes \\创建无线密码
---------------------------------------------------------------------------------
[AC-wlan-view]ssid-profile name A \\创建ssid模板A
[AC-wlan-ssid-prof-A]ssid A
[AC-wlan-view]ssid-profile name B \\创建ssid模板B
[AC-wlan-ssid-prof-A]ssid B
---------------------------------------------------------------------------------
[AC-wlan-view]vap-profile name A \\创建vap模板(虚拟ap)名称A
[AC-wlan-vap-prof-A]forward-mode tunnel \\业务采用隧道模式转发
[AC-wlan-vap-prof-A]service-vlan vlan-id 10 \\绑定vlan10
[AC-wlan-view]vap-profile name B \\配置vap模板(虚拟ap)名称B
[AC-wlan-vap-prof-B]forward-mode direct-forward \\业务采用直接转发(默认转发模式)
[AC-wlan-vap-prof-B]service-vlan vlan-id 20
---------------------------------------------------------------------------------
[AC-wlan-view]vap-profile name A \\在vap中关联安全模板与ssid模板
[AC-wlan-vap-prof-A]security-profile AB
[AC-wlan-vap-prof-A]ssid-profile A
[AC-wlan-view]vap-profile name B \\在vap中关联安全模板与ssid模板
[AC-wlan-vap-prof-A]security-profile AB
[AC-wlan-vap-prof-A]ssid-profile B
---------------------------------------------------------------------------------
[AC-wlan-view]ap-group name test
[AC-wlan-ap-group-test]vap-profile A wlan 1 radio all
[AC-wlan-ap-group-test]vap-profile B wlan 2 radio all