需求:内部办公用户使用隧道转发模式Vlan101;访客使用转发模式Vlan102.
配置各终端IP地址
<Huawei>sys
[Huawei]sys R1
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.200.2 30
[R1-GigabitEthernet0/0/0]q
[R1]ip route-static 192.168.101.0 24 192.168.200.1 //配置静态路由,分别是两个业务
[R1]ip route-static 192.168.102.0 24 192.168.200.1
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sys SW1
[SW1]vlan batch 100 101 102 200
SW1]dhcp en
[SW1]int vlanif 101
[SW1-Vlanif101]ip add 192.168.101.254 24
[SW1-Vlanif101]dhcp select int
[SW1-Vlanif101]int vlanif 102
[SW1-Vlanif102]ip add 192.168.102.254 24
[SW1-Vlanif102]dhcp select int
[SW1-Vlanif102]int vlanif 200
[SW1-Vlanif200]ip add 192.168.200.1 30
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/1]port default vlan 200
[SW1-GigabitEthernet0/0/1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port link-type trunk
[SW1-GigabitEthernet0/0/2]port trunk allow-pass vlan all //所以vlan都可以经过AC
[SW1-GigabitEthernet0/0/2]int g0/0/3
[SW1-GigabitEthernet0/0/3]port link-type trunk
[SW1-GigabitEthernet0/0/3]port trunk allow-pass vlan 100
内部工作人员WIFI SSID:work11;隧道模式
<Huawei>sys
[Huawei]sys SW2
[SW2]int g0/0/2
[SW2-GigabitEthernet0/0/2]port link-type trunk
[SW2-GigabitEthernet0/0/2]port trunk allow-pass vlan 100
[SW2-GigabitEthernet0/0/2]port trunk pvid vlan 100 //表示从这个接口进来的流量没有打上任何标签的打上vlan 100标签;打上vlan 100标签之后就可以传到AC上。
[SW2]int g0/0/1
[SW2-GigabitEthernet0/0/1]port link-type trunk
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
<AC6605>sys
[AC6605]vlan batch 100 101 102
[AC6605]int g0/0/1
[AC6605-GigabitEthernet0/0/1]port link-type trunk
[AC6605-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[AC6605-GigabitEthernet0/0/1]int vlanif 100
[AC6605-Vlanif100]ip add 192.168.100.254 24
[AC6605-Vlanif100]dhcp en
[AC6605-Vlanif100]dhcp select int
//上线配置
[AC6605]wlan
[AC6605-wlan-view]regulatory-domain-profile name AAA //进入域管理模板,名字为AAA
[AC6605-wlan-regulate-domain-AAA]country-code CN //无线代码中国,默认是中国,AC信道每个国家不一样
[AC6605-wlan-view]ap-group name keyan //配置AP组,名为keyan
[AC6605-wlan-ap-group-keyan]regulatory-domain-profile AAA //绑定域管理模板
Warning: Modifying the country code will clear channel, power and antenna gain c
onfigurations of the radio and reset the AP. Continue?[Y/N]:y //是否同意绑定
[AC6605]capwap source interface vlanif 100 //隧道的源,直接用端口
[AC6605-wlan-view]ap auth-mode ? //AP分别有三种认证方式
mac-auth MAC authenticated mode, default authenticated mode //MAC地址认证
no-auth No authenticated mode //不认证
sn-auth SN authenticated mode //通过SN码认证
[AC6605-wlan-view]ap auth-mode mac-auth //这里采用MAC认证
[AC6605-wlan-view]ap-id 1 ap-mac 00e0-fca8-54e0 //绑定AP物理地址,在AP设备上输入dis int g0/0/0(根据你所连接端口查找)
[AC6605-wlan-ap-1]ap-name ky001 //修改AP名
[AC6605-wlan-ap-1]ap-group keyan //归属于keyan
Warning: This operation may cause AP reset. If the country code changes, it will
clear channel, power and antenna gain configurations of the radio, Whether to c
ontinue? [Y/N]:y //是否加入到组里面
//无线业务下发
[AC6605]wlan //配置认证模式
[AC6605-wlan-view]security-profile name work //安全模板名字叫work
[AC6605-wlan-sec-prof-work]security wpa-wpa2 psk pass-phrase a12345678 aes //域共享密码a12345678 加密方式使用aes加密
[AC6605]wlan
[AC6605-wlan-view]ssid-profile name work
[AC6605-wlan-ssid-prof-work]ssid work11 //配置无线名
[AC6605-wlan-ssid-prof-work]
[AC6605-wlan-view]vap-profile name vap-work //vap:相当于一个AP设备上在逻辑增加一个AP
[AC6605-wlan-vap-prof-vap-work]ssid-profile work
Warning: This action may cause service interruption. Continue?[Y/N]y //是否确定修改
[AC6605-wlan-vap-prof-vap-work]forward-mode tunnel
[AC6605-wlan-vap-prof-vap-work]service-vlan vlan-id 101 //内部人员放在101
[AC6605-wlan-vap-prof-vap-work]security-profile work //安全用的是work,密码为a12345678
[AC6605-wlan-vap-prof-vap-work]q
[AC6605-wlan-view]ap-group name keyan
[AC6605-wlan-ap-group-keyan]vap-profile vap-work wlan 1 radio 0 //每个ap都开启vap;radio 0:表示2.4G 1:5G
访客配置,直接转发模式 SSID:guest
<SW1>sys
[SW1]int g0/0/3
[SW1-GigabitEthernet0/0/3]port link-type trunk
[SW1-GigabitEthernet0/0/3]port trunk allow-pass vlan 102 100
<SW2>sys
[SW2]int g0/0/1
[SW2-GigabitEthernet0/0/1]q
[SW2]vlan 102
[SW2-vlan102]int g0/0/2
[SW2-GigabitEthernet0/0/2]port link-type tr
[SW2-GigabitEthernet0/0/2]port trunk allow-pass vlan 102 100
[SW2-GigabitEthernet0/0/2]int g0/0/1
[SW2-GigabitEthernet0/0/1]port link-type tr
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan 100 102
<AC6605>sys
[AC6605]wlan
[AC6605-wlan-view]ssid-profile name profile_guest
[AC6605-wlan-ssid-prof-profile_guest]ssid guest
[AC6605-wlan-ssid-prof-profile_guest]q
[AC6605-wlan-view]vap-profile name vap_guest
[AC6605-wlan-vap-prof-vap_guest]forward-mode direct-forward
[AC6605-wlan-vap-prof-vap_guest]service-vlan vlan-id 102 //服务的vlan 102
[AC6605-wlan-vap-prof-vap_guest]security-profile work //安全方式为work上面配置那个;也可以单独创建一个;跟上面配置密码那里大同小异。
[AC6605-wlan-vap-prof-vap_guest]ssid-profile profile_gues //绑定profile_gues
[AC6605-wlan-vap-prof-vap_guest]q
[AC6605-wlan-view]ap-group name keyan //在keyan组里面开启虚拟ap
[AC6605-wlan-ap-group-keyan]vap-profile vap_guest wlan 2 radio all