ENSP WLAN三层旁挂组网直接+隧道转发实验

实验拓扑图

实验关键:

        1. AP管理:vlan50的网关配置在SW上,dhcp分配地址时加option 43 sub-option 2 ip-address 192.168.100.2,为AP指明AC的capwap源地址

        2. 直接转发模式:业务vlan10的网关配置在SW上

        3. 隧道转发模式:业务vlan20的网关配置在AC上(不能设置在SW上,否则终端无法获取IP地址,因为数据直接走capwap隧道封装)

        4. SW上和AP互联的接口trunk,允许10和50,PVID设置为50

        5. AP上线时可先将认证改为不认证,待上线后再改为MAC认证

R2R1ACSW
#
interface GigabitEthernet0/0/0
 ip address 12.1.1.2 255.255.255.0
#
interface LoopBack0
 ip address 2.2.2.2 255.255.255.255
#

ip route-static 1.2.3.4 255.255.255.255 12.1.1.1
#
#
acl number 3000 
 rule 5 permit ip
#
 
nat address-group 0 1.2.3.4 1.2.3.4
#
interface GigabitEthernet0/0/0
 ip address 12.1.1.1 255.255.255.0

 nat outbound 3000 address-group 0
#
interface GigabitEthernet0/0/1
 ip address 192.168.100.1 255.255.255.0
#
interface GigabitEthernet0/0/2
 ip address 192.168.200.1 255.255.255.0
#
interface LoopBack0
 ip address 1.1.1.1 255.255.255.255
#
ospf 1 router-id 1.1.1.1
 default-route-advertise
 area 0.0.0.0
  network 1.1.1.1 0.0.0.0
  network 192.168.200.1 0.0.0.0
#
ip route-static 0.0.0.0 0.0.0.0 12.1.1.2

ip route-static 192.168.20.0 255.255.255.0 192.168.100.2
#
#
vlan batch 20 100
#

dhcp enable
#
interface Vlanif20
 ip address 192.168.20.1 255.255.255.0
 dhcp select interface
#
interface Vlanif100
 ip address 192.168.100.2 255.255.255.0
#
interface GigabitEthernet0/0/1
 port link-type access
 port default vlan 100
#
ip route-static 0.0.0.0 0.0.0.0 192.168.100.1
#

capwap source interface vlanif100
#
wlan
 security-profile name guest
  security wpa-wpa2 psk pass-phrase %^%#,Ce1C15)@2$7Y-F9>=q$g#G6U{B"WYXhck7Te322
%^%# aes-tkip
 security-profile name office
  security wpa-wpa2 psk pass-phrase %^%#=*lX>uZ!T--.'Q9CV6y5[H%GB`D[x>!;$Q4/k38~
%^%# aes-tkip
 ssid-profile name guest
  ssid guest
 ssid-profile name office
  ssid office
 vap-profile name guest
 
forward-mode tunnel
  service-vlan vlan-id 20
  ssid-profile guest
  security-profile guest
 vap-profile name office
  service-vlan vlan-id 10
  ssid-profile office
  security-profile office
 regulatory-domain-profile name china
 ap-group name home
  regulatory-domain-profile china
  radio 0
   vap-profile office wlan 1
   vap-profile guest wlan 2
  radio 1
   vap-profile office wlan 1
   vap-profile guest wlan 2
  radio 2
   vap-profile office wlan 1
   vap-profile guest wlan 2
 ap-id 0 type-id 56 ap-mac 00e0-fc96-8050 ap-sn 210235448310351ADC01
  ap-name AP1
  ap-group home
 ap-id 1 type-id 56 ap-mac 00e0-fcde-67c0 ap-sn 210235448310FB280B33
  ap-name AP2
  ap-group home
#
#
vlan batch 10 50 200
#

dhcp enable
#
ip pool vlan50
 gateway-list 192.168.50.1
 network 192.168.50.0 mask 255.255.255.0
 excluded-ip-address 192.168.50.101 192.168.50.254
 
option 43 sub-option 2 ip-address 192.168.100.2
#
interface Vlanif10
 ip address 192.168.10.1 255.255.255.0
 
dhcp select interface
#
interface Vlanif50
 ip address 192.168.50.1 255.255.255.0
 
dhcp select global
#
interface Vlanif200
 ip address 192.168.200.2 255.255.255.0
#
interface GigabitEthernet0/0/1
 port link-type access
 port default vlan 200
#
interface GigabitEthernet0/0/2
 
port link-type trunk
 port trunk pvid vlan 50

 undo port trunk allow-pass vlan 1
 
port trunk allow-pass vlan 10 50
 stp edged-port enable
#
interface GigabitEthernet0/0/3
 
port link-type trunk
 port trunk pvid vlan 50

 undo port trunk allow-pass vlan 1
 
port trunk allow-pass vlan 10 50
 stp edged-port enable
#
interface LoopBack0
 ip address 3.3.3.3 255.255.255.255
#
ospf 1 router-id 3.3.3.3
 import-route direct
 area 0.0.0.0
  network 3.3.3.3 0.0.0.0
  network 192.168.200.2 0.0.0.0
#

隧道转发模式下数据包封装

实验效果(2.2.2.2为R2上loopback 0接口地址)

实验详细配置

R1配置:

<R1>dis cur
[V200R003C00]
#
 sysname R1
#
 snmp-agent local-engineid 800007DB03000000000000
 snmp-agent 
#
 clock timezone China-Standard-Time minus 08:00:00
#
portal local-server load portalpage.zip
#
 drop illegal-mac alarm
#
 set cpu-usage threshold 80 restore 75
#
acl number 3000  
 rule 5 permit ip 
#
aaa 
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default 
 domain default_admin 
 local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
 local-user admin service-type http
#
firewall zone Local
 priority 15
#
 nat address-group 0 1.2.3.4 1.2.3.4
#
interface GigabitEthernet0/0/0
 ip address 12.1.1.1 255.255.255.0 
 nat outbound 3000 address-group 0 
#
interface GigabitEthernet0/0/1
 ip address 192.168.100.1 255.255.255.0 
#
interface GigabitEthernet0/0/2
 ip address 192.168.200.1 255.255.255.0 
#
interface NULL0
#
interface LoopBack0
 ip address 1.1.1.1 255.255.255.255 
#
ospf 1 router-id 1.1.1.1 
 default-route-advertise
 area 0.0.0.0 
  network 1.1.1.1 0.0.0.0 
  network 192.168.200.1 0.0.0.0 
#
ip route-static 0.0.0.0 0.0.0.0 12.1.1.2
ip route-static 192.168.20.0 255.255.255.0 192.168.100.2
#
user-interface con 0
 authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
#
wlan ac
#
return

R2配置:

<R2>dis cur
[V200R003C00]
#
 sysname R2
#
 snmp-agent local-engineid 800007DB03000000000000
 snmp-agent 
#
 clock timezone China-Standard-Time minus 08:00:00
#
portal local-server load portalpage.zip
#
 drop illegal-mac alarm
#
 set cpu-usage threshold 80 restore 75
#
aaa 
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default 
 domain default_admin 
 local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
 local-user admin service-type http
#
firewall zone Local
 priority 15
#
interface GigabitEthernet0/0/0
 ip address 12.1.1.2 255.255.255.0 
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
interface LoopBack0
 ip address 2.2.2.2 255.255.255.255 
#
ip route-static 1.2.3.4 255.255.255.255 12.1.1.1
#
user-interface con 0
 authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
#
wlan ac
#
return

AC配置:

<AC6005>dis cur
#
 set memory-usage threshold 0
#
ssl renegotiation-rate 1 
#
vlan batch 20 100
#
authentication-profile name default_authen_profile
authentication-profile name dot1x_authen_profile
authentication-profile name mac_authen_profile
authentication-profile name portal_authen_profile
authentication-profile name macportal_authen_profile
#
dhcp enable
#
diffserv domain default
#
radius-server template default
#
pki realm default
 rsa local-key-pair default
 enrollment self-signed
#
ike proposal default
 encryption-algorithm aes-256 
 dh group14 
 authentication-algorithm sha2-256 
 authentication-method pre-share
 integrity-algorithm hmac-sha2-256 
 prf hmac-sha2-256 
#
free-rule-template name default_free_rule
#
portal-access-profile name portal_access_profile
#
aaa
 authentication-scheme default
 authentication-scheme radius
  authentication-mode radius
 authorization-scheme default
 accounting-scheme default
 domain default
  authentication-scheme radius
  radius-server default
 domain default_admin
  authentication-scheme default
 local-user admin password irreversible-cipher $1a$j^g}"am6~1$@TmDZOokG1(4o6A\'X
Q3B4S-BS{@S+:,(#Y(6(C%$
 local-user admin privilege level 15
 local-user admin service-type http
#
interface Vlanif20
 ip address 192.168.20.1 255.255.255.0
 dhcp select interface
#
interface Vlanif100
 ip address 192.168.100.2 255.255.255.0
#
interface GigabitEthernet0/0/1
 port link-type access
 port default vlan 100
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
 undo negotiation auto
 duplex half
#
interface GigabitEthernet0/0/8
 undo negotiation auto
 duplex half
#
interface NULL0
#
 snmp-agent local-engineid 800007DB03000000000000
 snmp-agent 
#
ssh server secure-algorithms cipher aes256_ctr aes128_ctr
ssh server key-exchange dh_group14_sha1
ssh client secure-algorithms cipher aes256_ctr aes128_ctr
ssh client secure-algorithms hmac sha2_256
ssh client key-exchange dh_group14_sha1
#
ip route-static 0.0.0.0 0.0.0.0 192.168.100.1
#
capwap source interface vlanif100
#
user-interface con 0
 authentication-mode password
user-interface vty 0 4
 protocol inbound all
user-interface vty 16 20
 protocol inbound all
#
wlan
 traffic-profile name default
 security-profile name guest
  security wpa-wpa2 psk pass-phrase %^%#,Ce1C15)@2$7Y-F9>=q$g#G6U{B"WYXhck7Te322
%^%# aes-tkip
 security-profile name office
  security wpa-wpa2 psk pass-phrase %^%#=*lX>uZ!T--.'Q9CV6y5[H%GB`D[x>!;$Q4/k38~
%^%# aes-tkip
 security-profile name default
 security-profile name default-wds
 security-profile name default-mesh
 ssid-profile name guest
  ssid guest
 ssid-profile name office
  ssid office
 ssid-profile name default
 vap-profile name guest
  forward-mode tunnel
  service-vlan vlan-id 20
  ssid-profile guest
  security-profile guest
 vap-profile name office
  service-vlan vlan-id 10
  ssid-profile office
  security-profile office
 vap-profile name default
 wds-profile name default
 mesh-handover-profile name default
 mesh-profile name default
 regulatory-domain-profile name china
 regulatory-domain-profile name default
 air-scan-profile name default
 rrm-profile name default
 radio-2g-profile name default
 radio-5g-profile name default
 wids-spoof-profile name default
 wids-profile name default
 wireless-access-specification
 ap-system-profile name default
 port-link-profile name default
 wired-port-profile name default
 serial-profile name preset-enjoyor-toeap 
 ap-group name home
  regulatory-domain-profile china
  radio 0
   vap-profile office wlan 1
   vap-profile guest wlan 2
  radio 1
   vap-profile office wlan 1
   vap-profile guest wlan 2
  radio 2
   vap-profile office wlan 1
   vap-profile guest wlan 2
 ap-group name default
 ap-id 0 type-id 56 ap-mac 00e0-fc96-8050 ap-sn 210235448310351ADC01
  ap-name AP1
  ap-group home
 ap-id 1 type-id 56 ap-mac 00e0-fcde-67c0 ap-sn 210235448310FB280B33
  ap-name AP2
  ap-group home
 provision-ap
#
dot1x-access-profile name dot1x_access_profile
#
mac-access-profile name mac_access_profile
#
return

SW配置:

<SW>dis cur
#
sysname SW
#
vlan batch 10 50 200
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
dhcp enable
#
diffserv domain default
#
drop-profile default
#
ip pool vlan50
 gateway-list 192.168.50.1
 network 192.168.50.0 mask 255.255.255.0
 excluded-ip-address 192.168.50.101 192.168.50.254
 option 43 sub-option 2 ip-address 192.168.100.2
#
aaa
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default
 domain default_admin
 local-user admin password simple admin
 local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10
 ip address 192.168.10.1 255.255.255.0
 dhcp select interface
#
interface Vlanif50
 ip address 192.168.50.1 255.255.255.0
 dhcp select global
#
interface Vlanif200
 ip address 192.168.200.2 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
 port link-type access
 port default vlan 200
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk pvid vlan 50
 undo port trunk allow-pass vlan 1
 port trunk allow-pass vlan 10 50
 stp edged-port enable
#
interface GigabitEthernet0/0/3
 port link-type trunk
 port trunk pvid vlan 50
 undo port trunk allow-pass vlan 1
 port trunk allow-pass vlan 10 50
 stp edged-port enable
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
interface LoopBack0
 ip address 3.3.3.3 255.255.255.255
#
ospf 1 router-id 3.3.3.3
 import-route direct
 area 0.0.0.0
  network 3.3.3.3 0.0.0.0
  network 192.168.200.2 0.0.0.0
#
user-interface con 0
user-interface vty 0 4
#
return

<think>好的,用户的问题是关于ENSP中二层AC组网隧道转发配置和原理。我需要先理解用户的需求,然后结合提供的引用内容来组织回答。首先,用户可能已经了解了一些基本概念,比如二层组网和直连转发,现在想深入隧道转发的配置和原理。 根据提供的引用,特别是引用1、2、3,里面提到了组网的不同转发模式。比如引用1详细讨论了+三层+隧道转发,而引用2和3是关于二层直连转发实验隧道转发直接转发的区别在于数据流经AC与否,这点需要明确说明。 首先,我应该解释二层AC组网的基本结构,说明AC的位置和连接方式。然后,区分隧道转发直接转发的不同,强调隧道转发中数据需要经过AC封装处理,而直接转发则不经过。接下来,需要详细说明隧道转发的配置步骤,可能包括VLAN划分、AC与AP的通信、业务VLAN和隧道配置,以及安全策略等。同时,要结合引用中的配置示例,如引用3中的VAP配置,可能需要调整到隧道模式。 另外,用户可能对隧道转发的工作原理感兴趣,比如CAPWAP协议的作用,数据封装解封装的过程。这部分需要简明扼要地解释,确保用户理解数据是如何通过隧道传输的。 最后,生成相关问题时要覆盖用户可能进一步询问的方向,比如与直连转发的对比、配置注意事项、适用场景以及CAPWAP协议的具体作用等。需要确保问题有针对性,能够帮助用户深化理解。 需要注意的是,回答中要正确使用LaTeX格式,虽然这里可能涉及的技术术语较多,但数学公式可能较少,所以主要检查标号和格式是否正确。同时,引用标识要正确对应,比如引用1对应隧道转发组网配置,引用3涉及VAP配置等。 总结回答结构:先介绍二层组网,再对比两种转发模式,详细讲解隧道转发的配置步骤和原理,最后总结其优缺点和应用场景。确保每一步都清晰,并引用相关参考资料。</think>### ENSP二层AC组网隧道转发配置与原理 #### 一、二层AC组网基础 在华为ENSP中,**二层AC组网**指AC(接入控制器)通过二层交换机连接到网络,不直接参与用户数据传输,仅负责管理AP(接入点)和控制信令[^1]。AP与AC之间通过**CAPWAP协议**建立隧道,实现配置下发、状态同步等功能。 #### 二、隧道转发直接转发的区别 1. **直接转发(Direct Forward)** 数据流量由AP直接转发至上层网络,不经过AC[^2]。 2. **隧道转发(Tunnel Forward)** 所有用户数据需通过CAPWAP隧道封装后传输至AC,再由AC解封装并转发至目标网络[^3]。 #### 三、隧道转发配置步骤 1. **基础网络规划** - 划分管理VLAN(AP与AC通信)和业务VLAN(用户数据)。 - 示例:管理VLAN 100,业务VLAN 101。 2. **AC配置** ```bash # 创建AP组并关联VAP模板 [AC] wlan [AC-wlan-view] ap-group name tunnel-group [AC-wlan-ap-group-tunnel-group] vap-profile vap-tunnel wlan 1 radio all # 配置CAPWAP隧道模式为隧道转发 [AC-wlan-view] forward-mode tunnel # 关键步骤[^1] # 配置业务VLAN [AC-wlan-view] service-vlan 101 ``` 3. **AP注册与隧道建立** - AP通过DHCP获取IP地址后,自动与AC建立CAPWAP隧道。 - 验证命令:`display ap all` 查看AP状态为“normal”。 4. **安全策略(可选)** ```bash # 配置WPA2-PSK认证 [AC-wlan-view] security-profile name sec-tunnel [AC-wlan-sec-prof-sec-tunnel] security wpa2 psk passphrase 12345678 aes ``` #### 四、隧道转发原理 1. **数据封装流程** - 用户数据(如IP报文)由AP接收后,通过CAPWAP隧道添加外层IP头(源IP为AP,目的IP为AC)。 - AC解封装后,根据业务VLAN将数据转发至目标网络[^1]。 2. **优势与限制** - **优势**:集中管控流量,支持高级策略(如QoS、流量过滤)。 - **限制**:AC需处理所有数据,可能成为性能瓶颈。 #### 五、典型组网拓扑 ``` [AP] ---(Trunk, VLAN 100/101)---> [二层交换机] ---(Trunk, VLAN 100)---> [AC] | +---(Access, VLAN 101)---> [上层网络] ```
评论
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
红包 添加红包
表情包 插入表情
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值