sys
sys AC1
vlan batch 10100
dhcp enable
int vlan 10
ip address 192.168.10.124
dhcp select interface
q
int vlan 100
ip address 100.1.1.124
dhcp select interface
q
int g0/0/1
p l t
p t a v 10100
q
wlan
ap auth-mode mac-auth
regulatory-domain-profile name JT
q
ap-group name one
regulatory-domain-profile JT
y
q
ap-id 0 ap-mac 00E0-FC9D-18B0
ap-name AP1
ap-group one
y
q
ap-id 1 ap-mac 00E0-FC2C-3450
ap-name AP2
ap-group one
y
q
capwap source interface vlanif 100
wlan
ssid-profile name JT
ssid huawei
q
security-profile name JT
security wpa-wpa2 psk pass-phrase 123456789 aes
y
q
vap-profile name JT
forward-mode tunnel
service-vlan vlan-id 10
ssid-profile JT
security-profile JT
q
ap-group name one
vap-profile JT wlan 1 radio 1
q
q
ip route-static0.0.0.00192.168.10.2
LSW1
sys
sys LSW1
vlan batch 102030401001000
dhcp enable
int vlan 10
ip ad 192.168.10.224
q
int vlan 20
ip ad 192.168.20.124
dhcp select interface
q
int vlan 30
ip ad 192.168.30.124
dhcp select interface
q
observe-port 1 interface GigabitEthernet 0/0/5int vlan 40
ip ad 192.168.56.224
q
int vlan 1000
ip ad 11.1.1.124
q
int g0/0/1
p l a
p d v 1000
port-mirroring to observe-port 1 both
q
int g0/0/2
p l t
p t a v 10100
q
int g0/0/3
p l t
p t a v 20100
q
int g0/0/4
p l t
p t a v 30100
q
int g0/0/5
p l a
p d v 40
q
ip route-static0.0.0.0011.1.1.2
ip route-static192.168.10.024192.168.10.1
ip route-static100.1.1.024192.168.10.1
LSW2
sys
sys LSW2
vlan batch 20100int g0/0/1
p l t
p t a v 20100
q
int g0/0/2
p l t
p t a v 100
p t p v 100
q
int g0/0/3
p l a
p d v 20
q
LSW3
sys
sys LSW3
vlan batch 30100int g0/0/1
p l t
p t a v 30100
q
int g0/0/2
p l t
p t a v 100
p t p v 100
q
int g0/0/3
p l a
p d v 30
q
FW2
sys
sys FW2
int g1/0/0
ip ad 11.1.1.224
service-manage ping permit
q
int g1/0/1
ip ad 23.1.1.224
service-manage ping permit
q
firewall zone trust
add interface GigabitEthernet 1/0/0
q
firewall zone untrust
add interface GigabitEthernet 1/0/1
q
security-policy
rule name localtotrust
source-zone local
destination-zone trust
action permit
q
rule name trusttolocal
source-zone trust
destination-zone local
action permit
q
rule name localtountrust
source-zone local
destination-zone untrust
action permit
q
rule name trusttountrust
source-zone trust
destination-zone untrust
action permit
q
rule name untrusttolocal
source-zone untrust
destination-zone local
action deny
q
rule name untrusttotrust
source-zone untrust
destination-zone trust
action deny
q
q
ip route-static0.0.0.0023.1.1.1
ip route-static11.1.1.02411.1.1.1
ip route-static192.168.10.02411.1.1.1
ip route-static192.168.20.02411.1.1.1
ip route-static192.168.30.02411.1.1.1
ip route-static100.1.1.02411.1.1.1
AR1
sys
sys AR1
int g0/0/1
ip ad 23.1.1.124
q
int g0/0/0
ip ad 12.1.1.124
q
ip route-static0.0.0.0012.1.1.2
ip route-static23.1.1.0023.1.1.2
ip route-static11.1.1.02423.1.1.2
ip route-static192.168.10.02423.1.1.2
ip route-static192.168.20.02423.1.1.2
ip route-static192.168.30.02423.1.1.2
ip route-static100.1.1.02423.1.1.2
acl 2000
rule permit source 192.168.0.00.0.255.255
q
nat address-group 012.1.1.312.1.1.3int g0/0/0
nat outbound 2000 address-group 0
q
AR2
sys
sys AR2
int g0/0/0
ip ad 12.1.1.224
q
ip route-static0.0.0.0012.1.1.1