基于华为WAC双机VRRP热备份下旁挂三层组网隧道转发模式解决方案
组网拓扑
方案思路
(1)
本案例是旁挂三层组网,隧道转发模式,AP与WAC之间是CAPWAP隧道,业务数据流量通过CAPWAP隧道转发;
其中ap管理vlan为10,业务vlan为500;
(2)
Master WAC和Backup WAC之间起VRRP双机热备份,VLAN为100,其中:
Master VRRP IP:192.168.1.11/24
Backup VRRP IP:192.168.1.21/24
VRRP Virtual-IP:192.168.1.1/24
WAC上capwap隧道的source ip add为vrrp virtual-ip 192.168.1.1;
(3)
Master WAC和Backup WAC之间互联的链路为心跳线,起HSB,同步AP组、用户接入、DHCP等信息,HSB vlan为200,其中:
Master HSB IP:192.168.2.11/24
Backup HSB IP:192.168.2.21/24
(4)
Master WAC和Backup WAC之间还需要配置同步配置来同步无线公有配置,后续Master AC上的任意公有配置操作,会自动同步给Backup Master AC;
(5)
Core Switch作为AP和业务vlan的DHCP Pool,并且也是作为AP以及业务流量的网关,其中:
AP vlan:10,gateway:10.251.1.254/24
STA vlan:500,gatwway:10.250.1.254/24
并且Core Switch上配置vlanif100:192.168.1.254/24作为VRRP的gateway;
(6)
Core Switch连接Access Switch以下的链路为2层链路,g0/0/3只需放通ap管理vlan 10;
Core Switch连接WAC的链路为3层链路,g0/0/1以及g0/0/2放通vrrp vlan 100,以及业务vlan500,不需要放通vlan10,并disable stp;
WAC的g0/0/1口放通vrrp vlan 100,以及业务vlan500,并disable stp;g0/0/2口只需要放通hsb vlan 200;
Access Switch的接口g0/0/1-g0/0/3放通ap管理vlan10,并且连接ap的接口g0/0/2-g0/0/3 pvid为vlan 10;
AP上线配置流程图
设备详细配置
Acc Switch
#
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 10
#
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk pvid vlan 10
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 10
#
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk pvid vlan 10
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 10
#
Core Switch
#
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow