(一) 配置AP与AC间能够传输CAPWAP报文
1.配置LSW2都加入管理vlan:100
[LSW2]vlan batch 100
[LSW2-GigabitEthernet0/0/1]port link-type trunk
[LSW2-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
[LSW2-GigabitEthernet0/0/2]port link-type trunk
[LSW2-GigabitEthernet0/0/2]port trunk pvid vlan 100
[LSW2-GigabitEthernet0/0/2]port trunk allow-pass vlan 100
[LSW2-GigabitEthernet0/0/2]port-isolate enable
[LSW2-GigabitEthernet0/0/3]port link-type trunk
[LSW2-GigabitEthernet0/0/3]port trunk pvid vlan 100
[LSW2-GigabitEthernet0/0/3]port trunk allow-pass vlan 100
[LSW2-GigabitEthernet0/0/3]port-isolate enable
2.配置AC连接交换机的接口加入vlan 100
[AC1]vlan batch 100
[AC1-GigabitEthernet0/0/1]port link-type trunk
[AC1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
(二)配置AC与上层网络设备互通
1.配置业务vlan 10 20 200
[AC1]vlan batch 10 20 200
[AC1-Vlanif10]ip add 10.1.10.1 24
[AC1-Vlanif20]ip add 10.1.20.1 24
[AC1-Vlanif200]ip add 10.1.200.2 24
2.配置AC缺省路由
[AR1-GigabitEthernet0/0/1]ip add 10.1.200.1 24
[AC1]ip route-static 0.0.0.0 0.0.0.0 10.1.200.1
3.配置AC连接AR1的接口加入VLAN200
[AC1-GigabitEthernet0/0/2]port link-type trunk
[AC1-GigabitEthernet0/0/2]port trunk allow-pass vlan 200
(三)配置AC给AP分配IP地址,AR1给STA分配IP地址:在AC上配置基于接口的DHCP服务器为AP分配IP地址,同时配置AC作为DHCP中继,由AC连接的路由器为STA分配IP地址
- 配置AC通过接口地址池为AP分配IP地址
[AC1]dhcp enable
[AC1]interface Vlanif 100
[AC1-Vlanif100]ip add 10.1.100.1 24
[AC1-Vlanif100]dhcp select interface - 配置AC作为DHCP中继并使能DHCP中继探测用户表项功能
[AC1-Vlanif10]dhcp select relay
[AC1-Vlanif10]dhcp relay server-ip 10.1.10.1
[AC1]int Vlanif 20
[AC1-Vlanif20]dhcp select relay
[AC1-Vlanif20]dhcp relay server-ip 10.1.20.1 - 配置AR1作为DHCP服务器为STA分配IP地址
[AR1]dhcp enable
[AR1]ip pool pool1
[AR1-ip-pool-pool1]gateway-list 10.1.10.1
[AR1-ip-pool-pool1]network 10.1.10.0 mask 24
[AR1]ip pool pool2
[AR1-ip-pool-pool2]network 10.1.20.0 mask 24
[AR1-ip-pool-pool2]network 10.1.20.0 mask 24
[AR1]vlan batch 200
[AR1]interface g6/0/0
[AR1-GigabitEthernet6/0/0]port link-type trunk
[AR1-GigabitEthernet6/0/0]port trunk allow-pass vlan 200
[AR1]ip route-static 10.1.10.0 24 10.1.200.2
[AR1]ip route-static 10.1.20.0 24 10.1.200.2
(四)配置VLAN pool,用于作为业务VLAN:在WLAN无线网络环境中,由于无线用户接入方式和接入位置较为灵活,经常会出现用户在某个地点(例如办公区入口或体育场馆入口)集中接入到同一个无线网络中,然后漫游到其它AP覆盖的无线网络环境下。如果每个SSID中只有一个业务VLAN为无线用户提供无线网络服务,很容易产生接入用户数多的区域IP地址资源不足、而其它区域IP地址资源浪费的现象。通过将VLAN pool配置为无线用户的业务VLAN,实现一个SSID能够同时支持多个业务VLAN。新接入的用户会被动态地分配到VLAN pool中的各个VLAN中,减少了单个VLAN下的用户数,缩小了广播域;同时每个VLAN尽量均匀地分配IP地址,减少了IP地址的浪费
[AC1]vlan pool sta-pool //新建VLAN pool
[AC1-vlan-pool-sta-pool]vlan 10 20 //并将VLAN10和20加入其中
[AC1-vlan-pool-sta-pool]assignment hash //配置VLAN pool中的VLAN分配算法为hash
(五)配置AP上线 - 创建AP组,用于将相同配置的AP都加入同一AP组中
[AC1]wlan
[AC1-wlan-view]ap-group name ap-group1 - 创建域管理模板,在域管理模板下配置AC的国家码并在AP组下引用域管理模板
[AC1-wlan-view]regulatory-domain-profile name domain1
[AC1-wlan-regulate-domain-domain1]country-code cn
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]regulatory-domain-profile domain1 - 配置AC的源接口
[AC1]capwap source interface Vlanif 100 - 在AC上离线导入AP,并将AP加入AP组ap-group1中
[AC1]wlan
[AC1-wlan-view]ap auth-mode mac-auth
[AC1-wlan-view]ap-id 0 ap-mac 00e0-fc8b-7410
[AC1-wlan-ap-0]ap-name area_1
[AC1-wlan-ap-0]ap-group ap-group1
[AC1-wlan-view]ap-id 1 ap-mac 00e0-fcd0-7ad0
[AC1-wlan-ap-1]ap-group ap-group1
[AC1-wlan-ap-1]ap-name area_2 - 查看到AP的State字段为nor时,表示AP正常上线
(六)配置WLAN业务参数
-
创建名为wlan-sec的安全模板,并配置安全策略
[AC1-wlan-view]security-profile name wlan-sec
[AC1-wlan-sec-prof-wlan-sec]security wpa2 psk pass-phrase abc@1234 aes -
创建名为wlan-ssid的SSID模板,并配置SSID名称为wlan-net
[AC1-wlan-view]ssid-profile name wlan-ssid
[AC1-wlan-ssid-prof-wlan-ssid]ssid wlan-net -
创建名为wlan-vap的VAP模板,配置业务数据转发模式、业务VLAN,并且引用安全模板和SSID模板
[AC1-wlan-view]vap-profile name wlan-vap
[AC1-wlan-vap-prof-wlan-vap]forward-mode tunnel
[AC1-wlan-vap-prof-wlan-vap]service-vlan vlan-pool sta-pool
[AC1-wlan-vap-prof-wlan-vap]security-profile wlan-sec
[AC1-wlan-vap-prof-wlan-vap]ssid-profile wlan-ssid -
配置AP组引用VAP模板,AP上射频0和射频1都使用VAP模板wlan-vap的配置
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]vap-profile wlan-vap wlan 1 radio all
(七)配置AP射频的信道和功率
1.配置AP射频0的信道和功率
[AC1-wlan-view]ap-id 0
[AC1-wlan-ap-0]radio 0
[AC1-wlan-radio-0/0]channel 20mhz 6
[AC1-wlan-radio-0/0]eirp 127
2.配置AP射频1的信道和功率
[AC1-wlan-radio-0/0]ap-id 1
[AC1-wlan-ap-1]radio 1
[AC1-wlan-radio-1/1]channel 20mhz 149
[AC1-wlan-radio-1/1]eirp 127
(八)验证结果 -
当Status项显示为ON时,表示AP对应的射频上的VAP已创建成功
-
STA搜索到名为wlan-net的无线网络,输入密码并正常关联后