拓扑图
vlan10,20 用户流量,vlan30 AP管理段,vlan40 AC集连段,AP密码ruijie,enable密码apdebug
集中转发
核心交换机
HX(config)#vlan range 10,20,30,40
HX(config)#int vlan 10 -->用户流量网段
HX(config-VLAN 10)#ip address 192.168.10.254 255.255.255.0
HX(config)#int vlan 20 -->用户流量网段
HX(config-VLAN 20)#ip address 192.168.20.254 255.255.255.0
HX(config)#int vlan 30 -->AP管理网段
HX(config-VLAN 30)#ip address 192.168.30.254 255.255.255.0
HX(config)#int vlan 40 -->与AC集连网段
HX(config-VLAN 40)#ip address 192.168.40.254 255.255.255.0
HX(config)#int fastEthernet 0/23 -->与AP相连
HX(config-FastEthernet 0/23)#switchport access vlan 30
HX(config)#int fastEthernet 0/24 -->与AC相连
HX(config-FastEthernet 0/24)#switchport mode trunk
HX(config)#ip route 1.1.1.1 255.255.255.255 192.168.40.253
HX(config)#service dhcp
HX(config)#ip dhcp pool vlan10
HX(dhcp-config)#network 192.168.10.0 255.255.255.0
HX(dhcp-config)#default-router 192.168.10.254
HX(dhcp-config)#dns-server 114.114.114.114
HX(config)#ip dhcp pool vlan20
HX(dhcp-config)#network 192.168.20.0 255.255.255.0
HX(dhcp-config)#default-router 192.168.20.254
HX(dhcp-config)#dns-server 114.114.114.114
HX(config)#ip dhcp pool vlan30
HX(dhcp-config)#network 192.168.30.0 255.255.255.0
HX(dhcp-config)#dns-server 114.114.114.114
HX(dhcp-config)# default-router 192.168.30.254
HX(dhcp-config)#option 138 ip 1.1.1.1 -->AP利用Option获取的AC地址,与AC建立CAPWAP隧道
AC
AC1(config)#vlan range 10,20,30,40
AC1(config)#int vlan 40 -->与核心集连网段
AC1(config-if-VLAN 40)#ip address 192.168.40.253 255.255.255.0
AC1(config)#int loopback 0 -->配置AC的loopback地址,用于AP发现
AC1(config-if-Loopback 0)#ip address 1.1.1.1 255.255.255.255
AC1(config)#ip route 0.0.0.0 0.0.0.0 192.168.40.254 -->默认路由指向核心
AC1(config)#int gigabitEthernet 0/1 -->配置与核心的二层集联口
AC1(config-if-GigabitEthernet 0/1)#switchport mode trunk
AC1(config)#wlan-config 10 ruijie_1010 -->创建AP信号ruijie_1010(STA可以接收的无线名字)
AC1(config)#wlan-config 20 ruijie_2020 -->创建AP信号ruijie_2020
AC1(config)#int vlan 10 -->必配置,打开AC用户vlan的接口up状态
AC1(config)#int vlan 20 -->必配置,打开AC用户vlan的接口up状态
AC1(config)#int vlan 30 -->必配置,打开AC用户vlan的接口up状态
AC1(config)#ap-group ruijie -->创建AP设备组ruijie
AC1(config-group)#interface-mapping 10 10 radio 1 -->关联wlan组10 与vlan 10 与射频1
AC1(config-group)#interface-mapping 20 20 radio 2 -->关联wlan组20 与vlan 20 与射频2
AC1(config)#sh ap-config summary
========= show ap status =========
Radio: Radio ID or Band: 2.4G = 1#, 5G = 2#
E = enabled, D = disabled, N = Not exist
Current Sta number
Channel: * = Global
Power Level = Percent
Online AP number: 1
Offline AP number: 0
AP Name IP Address Mac Address Radio Radio Up/Off time State
---------------------------------------- --------------- -------------- ------------------- ------------------- ------------- -----
5869.6c2f.cea2 192.168.30.1 5869.6c2f.cea2 1 E 0 1* 100 2 E 0 149* 100 0:00:01:29 Run
AC1(config)#ap-config 5869.6c2f.cea2 -->进入AP配置模式
AC1(config-ap)#ap-name 1#JXL_1F -->重新命名为1#JXL_1F
AC1(config-ap)#ap-group ruijie -->加入到AP设备组ruijie
AC1(config-ap)#channel 3 radio 1 -->2.4G射频信道改为3
AC1(config-ap)#channel 153 radio 2 -->5G射频信道改为153
AC1(config-ap)#power local 40 radio 1 -->2.4G射频信号功率改为40%
AC1(config-ap)#power local 60 radio 2 -->5G射频信号功率改为60%
AC1(config)#sh ap-config summary
========= show ap status =========
Radio: Radio ID or Band: 2.4G = 1#, 5G = 2#
E = enabled, D = disabled, N = Not exist
Current Sta number
Channel: * = Global
Power Level = Percent
Online AP number: 1
Offline AP number: 0
AP Name IP Address Mac Address Radio Radio Up/Off time State
---------------------------------------- --------------- -------------- ------------------- ------------------- ------------- -----
1#JXL_1F 192.168.30.1 5869.6c2f.cea2 1 E 3 3 40 2 E 0 153 60 0:00:30:58 Run
AC1(config)#wlansec 10 -->配置wlan 10加密
AC1(config-wlansec)#security rsn enable -->开启无线WPA2加密功能
AC1(config-wlansec)#security rsn ciphers aes enable -->启用AES加密算法
AC1(config-wlansec)#security rsn akm psk enable -->启用共享密钥认证方式
AC1(config-wlansec)#security rsn akm psk set-key ascii 123456789 -->配置该无线wlan的SSID密码
AC1(config)#wlansec 20
AC1(config-wlansec)#security rsn enable
AC1(config-wlansec)#security rsn ciphers aes enable
AC1(config-wlansec)#security rsn akm psk enable
AC1(config-wlansec)#security rsn akm psk set-key ascii 123456789
AP
Ruijie#sh ap-mode
current mode: fit
本地转发
核心交换机
HX(config)#int fastEthernet 0/23 -->与AP相连
HX(config-FastEthernet 0/23)#switchport mode trunk
HX(config-FastEthernet 0/23)#switchport trunk native vlan 30
AC
AC1(config)#wlan-config 10 ruijie_1010
AC1(config-wlan)#tunnel local -->开启本地转发
AC1(config)#wlan-config 20 ruijie_2020
AC1(config-wlan)#tunnel local -->开启本地转发
AP
Ruijie#sh ap-mode
current mode: fit