无线组网(VLAN内二层漫游)综合

1、拓扑图

在这里插入图片描述

2、命令(可刷)

AC1

sys 
sys AC1
vlan batch 10 100
dhcp enable
int vlan 10
ip address 192.168.10.1 24
dhcp select interface
q
int vlan 100
ip address 100.1.1.1 24
dhcp select interface
q
int g0/0/1
p l t
p t a v 10 100
q


wlan 
ap auth-mode mac-auth
regulatory-domain-profile name JT
q
ap-group name one
regulatory-domain-profile JT
y
q

ap-id 0 ap-mac 00E0-FC9D-18B0
ap-name AP1
ap-group one
y
q
ap-id 1 ap-mac 00E0-FC2C-3450
ap-name AP2
ap-group one
y
q

capwap source interface vlanif 100

wlan
ssid-profile name JT
ssid huawei
q
security-profile name JT
security wpa-wpa2 psk pass-phrase 123456789 aes
y
q
vap-profile name JT
forward-mode tunnel 
service-vlan vlan-id 10
ssid-profile JT
security-profile JT
q

ap-group name one
vap-profile JT wlan 1 radio 1
q
q
ip route-static 0.0.0.0 0 192.168.10.2








LSW1

sys
sys LSW1
vlan batch 10 20 30 40 100 1000
dhcp enable
int vlan 10
ip ad 192.168.10.2 24
q
int vlan 20
ip ad 192.168.20.1 24
dhcp select interface
q
int vlan 30
ip ad 192.168.30.1 24
dhcp select interface
q
observe-port 1 interface GigabitEthernet 0/0/5
int vlan 40
ip ad 192.168.56.2 24
q
int vlan 1000
ip ad 11.1.1.1 24
q


int g0/0/1
p l a
p d v 1000
port-mirroring to observe-port 1 both 
q
int g0/0/2
p l t
p t a v 10 100
q
int g0/0/3
p l t
p t a v 20 100
q
int g0/0/4
p l t
p t a v 30 100
q
int g0/0/5
p l a
p d v 40
q



ip route-static 0.0.0.0 0 11.1.1.2
ip route-static 192.168.10.0 24 192.168.10.1
ip route-static 100.1.1.0 24 192.168.10.1



LSW2

sys
sys LSW2
vlan batch 20 100
int g0/0/1
p l t
p t a v 20 100
q
int g0/0/2
p l t
p t a v 100
p t p v 100
q
int g0/0/3
p l a
p d v 20
q

LSW3

sys
sys LSW3
vlan batch 30 100
int g0/0/1
p l t
p t a v 30 100
q
int g0/0/2
p l t
p t a v 100
p t p v 100
q
int g0/0/3
p l a
p d v 30
q

FW2

sys 
sys FW2
int g1/0/0
ip ad 11.1.1.2 24
service-manage ping permit
q
int g1/0/1
ip ad 23.1.1.2 24
service-manage ping permit
q

firewall zone trust 
add interface GigabitEthernet 1/0/0
q
firewall zone untrust 
add interface GigabitEthernet 1/0/1
q

security-policy
rule name localtotrust
source-zone local 
destination-zone trust 
action permit 
q
rule name trusttolocal
source-zone trust
destination-zone local
action permit 
q

rule name localtountrust
source-zone local 
destination-zone untrust 
action permit 
q

rule name trusttountrust
source-zone trust
destination-zone untrust
action permit
q

rule name untrusttolocal
source-zone untrust
destination-zone local
action deny
q

rule name untrusttotrust
source-zone untrust 
destination-zone trust 
action deny 
q
q




ip route-static 0.0.0.0 0 23.1.1.1
ip route-static 11.1.1.0 24 11.1.1.1
ip route-static 192.168.10.0 24 11.1.1.1
ip route-static 192.168.20.0 24 11.1.1.1
ip route-static 192.168.30.0 24 11.1.1.1
ip route-static 100.1.1.0 24 11.1.1.1


AR1

sys
sys AR1
int g0/0/1
ip ad 23.1.1.1 24
q
int g0/0/0
ip ad 12.1.1.1 24
q

ip route-static 0.0.0.0 0 12.1.1.2
ip route-static 23.1.1.0 0 23.1.1.2
ip route-static 11.1.1.0 24 23.1.1.2
ip route-static 192.168.10.0 24 23.1.1.2
ip route-static 192.168.20.0 24 23.1.1.2
ip route-static 192.168.30.0 24 23.1.1.2
ip route-static 100.1.1.0 24 23.1.1.2

acl 2000
rule permit source 192.168.0.0 0.0.255.255
q
nat address-group 0 12.1.1.3 12.1.1.3
int g0/0/0
nat outbound 2000 address-group 0 
q

AR2

sys
sys AR2
int g0/0/0
ip ad 12.1.1.2 24
q
ip route-static 0.0.0.0 0 12.1.1.1
  • 1
    点赞
  • 5
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值