模拟一个有线和无线共存的场景
目标:网络互通
1.配置vlan
在sw1上配置vlan
在g0/0/1接口:
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20 100
在g0/0/2接口:
[Huawei-GigabitEthernet0/0/2]port link-type trunk
[Huawei-GigabitEthernet0/0/2]port trunk allow-pass vlan 10 100
[Huawei-GigabitEthernet0/0/2]port trunk pvid vlan 100
因为AP1不允许配置vlan,只能接收不带标签的流量,因此AC1要想管理AP1,需要在g0/0/2接口上将PVID改为100,这样流量才能顺利通过。
在g0/0/3接口:
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port default vlan 20
在AC1上配置VLAN
在g0/0/2接口:
[AC6605-GigabitEthernet0/0/2]port link-type trunk
[AC6605-GigabitEthernet0/0/2]port trunk allow-pass vlan 10 20 100
创建一个管理vlan并配置IP地址:
[AC6605]int Vlanif 100
[AC6605-Vlanif100]ip add 100.0.0.1 24
在AC上配置DHCP地址池
[AC6605]dhcp enable
[AC6605]ip pool vlan100
[AC6605-ip-pool-vlan100]network 100.0.0.0 mask 24
[AC6605-ip-pool-vlan100]gateway-list 100.0.0.1
[AC6605]ip pool vlan10
[AC6605]int Vlanif 10
[AC6605-Vlanif10]ip add 192.168.10.1 24
[AC6605-ip-pool-vlan10]network 192.168.10.0 mask 24
[AC6605-ip-pool-vlan10]gateway-list 192.168.10.1
[AC6605-ip-pool-vlan10]dns-list 8.8.8.8
[AC6605-Vlanif10]dhcp select global
进入管理vlan调用DHCP服务
[AC6605]int Vlanif 100
[AC6605-Vlanif100]dhcp select global
配置AC
与管理vlan建立隧道
[AC6605]capwap source interface Vlanif 100
进入wlan视图
[AC6605]wlan
配置模版并起名
[AC6605-wlan-view]regulatory-domain-profile name domain
创建城市代码
[AC6605-wlan-regulate-domain-domain]country-code CN
创建AP组并起名
[AC6605-wlan-view]ap-group name group-1
调用模版
[AC6605-wlan-ap-group-group-1]regulatory-domain-profile domain
配置AP认证方式(这里选择mac认证)
[AC6605-wlan-view]ap auth-mode mac-auth
创建APID,绑定认证方式
[AC6605-wlan-view]ap-id 0 ap-mac 00e0-fcb5-6520
绑定AP组
[AC6605-wlan-ap-0]ap-group group-1
当状态是nor时表明ap已成功上线
配置ssid模版
[AC6605-wlan-view]ssid-profile name test-1
为ssid取名(wifi名称)
[AC6605-wlan-ssid-prof-test-1]ssid aaa
配置安全模版
[AC6605-wlan-view]security-profile name test-1
选择安全认证方式,配置密码
[AC6605-wlan-sec-prof-test-1]security wpa-wpa2 psk pass-phrase huawei123 aes
配置vap模版
[AC6605-wlan-view]vap-profile name test-1
关联ssid模版和安全模版
[AC6605-wlan-vap-prof-test-1]ssid-profile test-1
[AC6605-wlan-vap-prof-test-1]security-profile test-1
创建AP转发模式
[AC6605-wlan-vap-prof-test-1]forward-mode direct-forward
关联vlan
[AC6605-wlan-vap-prof-test-1]service-vlan vlan-id 10
在AP组中关联vap模版,设置射频信号
[AC6605-wlan-ap-group-group-1]vap-profile test-1 wlan 1 radio all
在STA1上输入密码
显示已连接
查看ip