WLAN的无线综合实验
题目很简单,详细的知识点这里就不多说了,如果有需要,后面文章在补充
实验拓扑
IP地址规划设计
1、用户vlan的IP地址
vlan20:172.16.20.0/24
vlan30:172.16.30.0/24
2、管理vlan的IP地址
vlan200:172.16.20.0/24
3、AP vlan的IP地址
vlan2:172.16.2.0/24
vlan3:172.16.3.0/24
4、路由接口的IP地址
(一)-(七):172.16.101.0/30-172.16.107.0/30
一、分析网络拓扑图中的设备层次、功能、配置思路
(一)二层交换机LSW3的功能:存储转发、vlan隔离、身份
1、划分vlan
2、接口处理
3、管理vlan的身份IP配置(IP、子网掩码、网关)
4、MSTP配置
LSW3:
vl ba 2 3 30 20 200
int gi 0/0/1
port link-t trunk
port trunk al vl all
int gi 0/0/2
port link-t trunk
port trunk al vl all
int gi 0/0/3
port link-t trunk
port trunk al vl all
port trunk pvid vlan 2
int gi 0/0/4
port link-t trunk
port trunk al vl all
port trunk pvid vlan 3
int vlan 200
ip add 172.16.200.1 24
quit
ip route-static 0.0.0.0 0.0.0.0 172.16.200.254
stp mode mstp
stp region-configuration
region-name hc
revision-level 1
instance 1 vlan 2 20
instance 2 vlan 3 30 200
active region-configuration
stp instance 1 root secondary
stp instance 2 root secondary
(二)三层设备AC1的功能:路由转发、路由、AC管理
1、接口处理(路由口、唯一身份)
2、多区域ospf配置
3、AP管理配置
3.1AP上线
3.2AP参数
第一步:配置基础有线网络
vl ba 102
int gi 0/0/1
port link-t acc
port def vlan 102
int vlan 102
ip add 172.16.102.2 30
vl ba 107
int gi 0/0/2
port link-t acc
port def vlan 107
int vlan 107
ip add 172.16.107.2 30
int LoopBack 0
ip add 3.3.3.3 32
ospf 1 router-id 3.3.3.3
area 0.0.0.100
network 172.16.102.0 0.0.0.3
network 172.16.107.0 0.0.0.3
network 3.3.3.3 0.0.0.0
第二步:创建ssid(无线网络的名字)
wlan 进入无线配置
ssid-profile name admin 创建一个ssid的配置文件,的文件名叫admin
ssid admin 这个ssid配置文件,的含义,是放出wifi为admin的无线信号
第三步:创建vap(放出几个wifi,就创建一个vap)
vap-profile name admin 创建一个vap配置文件
service-vlan vlan-pool admin vlanid与用户vlan要一致,当有多个vlan的时候可以用vlanPOOL或者建立多个vap模板
ssid-profile admin 含义,关联ssid的admin
第四步:创建ap-group(ap组),并且,把vap关联到ap组
ap-group name admin 创建一个ap组,名字叫admin
vap-profile admin wlan 1 radio all 这个ap组里,下发任务,vap admin的任务
wlan 1 一个编号。如果想让他多做几件事,多几个不同wlan123456
radio all 全频。wifi,2.4G,5G,都发
第五步:把ap加进来
查到ap的mac地址
dis int vlan 1
00e0-fcc3-4d10
wlan回车
ap-mac 00e0-fcc3-4d10 把这个mac加入ac
ap-group admin 把ap加入ap组
第六步: 设置-下ac和ap对接的接口
ac相当于一台三层交换机,可能有多个ip地址,设置用哪个接口回包
capwap source ip-address 3.3.3.3
想要设置密码:
在以上基础上加上密码模版
security-profile name admin 创建密码名称admin
security wpa-wpa2 psk pass-phrase admin aes 创建WiFi密码admin
vap-profile name admin 进入vap
security-profile admin 在vap里面关联密码模版
增加一个ap,将ap加入到组:
ap-mac 00e0-fc3d-5980 添加新加ap的mac地址
ap-group name admin 将新加的ap加入到admin组
(三)三层核心R1和R2的功能:路由转发、路由、身份
1、接口处理(路由口、唯一身份)
2、多区域ospf配置
R1:
vl ba 101 102 103 104
int gi 0/0/5
port link-t acc
port def vlan 102
int vlan 102
ip add 172.16.102.1 30
int gi 0/0/3
port link-t acc
port def vlan 103
int vlan 103
ip add 172.16.103.2 30
int gi 0/0/4
port link-t acc
port def vlan 104
int vlan 104
ip add 172.16.104.2 30
int LoopBack 0
ip add 1.1.1.1 32
int eth 10
trun gi 0/0/2
trun gi 0/0/1
port link-t acc
port def vlan 101
int vlan 101
ip add 172.16.101.2 30
ospf 1 router-id 1.1.1.1
area 0.0.0.100
network 172.16.102.0 0.0.0.3
area 0.0.0.0
network 172.16.101.0 0.0.0.3
network 1.1.1.1 0.0.0.0
area 0.0.0.3
network 172.16.103.0 0.0.0.3
network 172.16.104.0 0.0.0.3
R2:
vl ba 101 105 106 107
int gi 0/0/4
port link-t acc
port def vlan 105
int vlan 105
ip add 172.16.105.2 30
int gi 0/0/3
port link-t acc
port def vlan 106
int vlan 106
ip add 172.16.106.2 30
int gi 0/0/5
port link-t acc
port def vlan 107
int vlan 107
ip add 172.16.107.1 30
int eth 10
trun gi 0/0/2
trun gi 0/0/1
port link-t acc
port def vlan 101
int vlan 101
ip add 172.16.101.1 30
int LoopBack 0
ip add 2.2.2.2 32
ospf 1 router-id 2.2.2.2
area 0.0.0.100
network 172.16.107.0 0.0.0.3
area 0.0.0.0
network 172.16.101.0 0.0.0.3
network 2.2.2.2 0.0.0.0
area 0.0.0.3
network 172.16.105.0 0.0.0.3
network 172.16.106.0 0.0.0.3
(四)三层汇聚LSW1和LSW2的功能:存储转发、vlan隔离、身份、网关、路由
1、划分vlan
2、接口处理
3、管理vlan的主或备网关配置(IP、子网掩码、虚拟网关、优先级、抢占)
4、AP vlan的主或备网关配置(IP、子网掩码、虚拟网关、优先级、抢占)
5、用户vlan的主或备网关配置(IP、子网掩码、虚拟网关、优先级、抢占)
6、MSTP配置
7、DHCP服务器配置(vlan2和vlan20走左边,vlan3和vlan30走右边)
LSW1:
vl ba 2 3 20 30 200
vlan ba 103
int gi 0/0/3
port link-t acc
port def vlan 103
int vlan 103
ip add 172.16.103.1 30
vlan ba 105
int gi 0/0/4
port link-t acc
port def vlan 105
int vlan 105
ip add 172.16.105.1 30
int gi 0/0/5
port link-t trunk
port trunk al vl all
int eth 10
trun gi 0/0/1
trun gi 0/0/2
port link-t trunk
port trunk al vl all
int vlan 2
ip add 172.16.2.252 24
vrrp vrid 1 virtual-ip 172.16.2.254
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 30
int vlan 20
ip add 172.16.20.252 24
vrrp vrid 1 virtual-ip 172.16.20.254
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 30
int vlan 3
ip add 172.16.3.252 24
vrrp vrid 1 virtual-ip 172.16.3.254
int vlan 30
ip add 172.16.30.252 24
vrrp vrid 1 virtual-ip 172.16.30.254
int vlan 200
ip add 172.16.200.252 24
vrrp vrid 1 virtual-ip 172.16.200.254
stp mode mstp
stp region-configuration
region-name hc
revision-level 1
instance 1 vlan 2 20
instance 2 vlan 3 30 200
active region-configuration
stp instance 1 root primary
stp instance 2 root secondary
dhcp enable
ip pool vlan2
network 172.16.2.0 mas 24
gate 172.16.2.254
option 43 sub-option 3 ascii 3.3.3.3
ip pool vlan20
network 172.16.20.0 mas 24
gate 172.16.20.254
dns 8.8.8.8
int vlan 2
dhcp select gl
int vlan 20
dhcp select gl
int loopback0
ip add 4.4.4.4 32
ospf 1 router-id 4.4.4.4
area 0.0.0.3
network 172.16.103.0 0.0.0.3
network 172.16.105.0 0.0.0.3
network 4.4.4.4 0.0.0.0
network 172.16.2.0 0.0.0.255
network 172.16.20.0 0.0.0.255
LSW2:
vl ba 2 3 20 30 200
vl ba 104 106
int gi 0/0/3
port link-t acc
port def vlan 106
int vlan 106
ip add 172.16.106.1 30
int gi 0/0/4
port link-t acc
port def vlan 104
int vlan 104
ip add 172.16.104.1 30
int gi 0/0/5
port link-t trunk
port trunk al vl all
int eth 10
trun gi 0/0/1
trun gi 0/0/2
port link-t trunk
port trunk al vl all
int vlan 2
ip add 172.16.2.253 24
vrrp vrid 1 virtual-ip 172.16.2.254
int vlan 20
ip add 172.16.20.253 24
vrrp vrid 1 virtual-ip 172.16.20.254
int vlan 200
ip add 172.16.200.253 24
vrrp vrid 1 virtual-ip 172.16.200.254
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 30
int vlan 3
ip add 172.16.3.253 24
vrrp vrid 1 virtual-ip 172.16.3.254
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 30
int vlan 30
ip add 172.16.30.253 24
vrrp vrid 1 virtual-ip 172.16.30.254
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 30
stp mode mstp
stp region-configuration
region-name hc
revision-level 1
instance 1 vlan 2 20
instance 2 vlan 3 30 200
active region-configuration
stp instance 2 root primary
stp instance 1 root secondary
dhcp enable
ip pool vlan30
network 172.16.30.0 mas 24
gate 172.16.30.254
dns 8.8.8.8
ip pool vlan3
network 172.16.3.0 mas 24
gate 172.16.3.254
option 43 sub-option 3 ascii 3.3.3.3
int vlan 3
dhcp select gl
int vlan 30
dhcp select gl
int loopback0
ip add 3.3.3.2 32
ospf 1 router-id 5.5.5.5
area 0.0.0.3
network 172.16.104.0 0.0.0.3
network 172.16.106.0 0.0.0.3
network 5.5.5.5 0.0.0.0
network 172.16.3.0 0.0.0.255
network 172.16.30.0 0.0.0.255
(五)测试
AP1:
AP2:
测试完毕,实验结束