二层组网
项目需求:
VLAN100为管理VLAN
VLAN101为业务VLAN
1.配置AP组
#进入WLAN模版
[AC6005]wlan
#创建AP组
[AC6005-wlan-view]ap-group name dd (AP组名称)
#创建域管理模版
[AC6005-wlan-ap-group-dd]regulatory-domain-profile name dd (域管理模版名称)
#配置AC国家代码(在域管理模版下配置)
[AC6005-wlan-regulate-domain-dd]country-code cn (cn=中国)
[AC6005-wlan-regulate-domain-dd]q
#进入AP组
[AC6005-wlan-view]ap-group name dd (AP组名称)
#将域管理模版与AP组关联
[AC6005-wlan-ap-group-dd]regulatory-domain-profile dd (域管理模版名称)
2.创建与AP建隧道的接口
#配置源接口或源地址与AP建隧道
[AC6005]wlan
[AC6005]capwap source interface Vlanif 100
#AP接入控制,这里是MAC认证
[AC6005-wlan-view]ap auth-mode mac-auth
#配置AP认证模式--离线导入
[AC6005-wlan-view]ap-id 1 ap-mac 00e0-fc20-2f50 (AP接口MAC地址)
#修改AP的名称
[AC6005-wlan-ap-1]ap-name AP1 (AP的名称)
#与前面创建的AP组做绑定
[AC6005-wlan-ap-1]ap-group dd (AP组名称)
[AC6005]wlan
#另外一个AP接入认证
[AC6005-wlan-view]ap-id 2 ap-mac 00e0-fc81-2670
#修改AP的名称
[AC6005-wlan-ap-2]ap-name AP2 (AP的名称)
#与前面创建的AP组做绑定
[AC6005-wlan-ap-2]ap-group dd (AP组名称)
3.安全模版
[AC6005]wlan
#创建安全模版
[AC6005-wlan-view]security-profile name dd (安全模版名称)
#STA认证
[AC6005-wlan-sec-prof-dd]security wpa-wpa2 psk pass-phrase Huawei@123 aes
4.SSID模版
[AC6005]wlan
#创建SSID模版
[AC6005-wlan-view]ssid-profile name sb (SSID模版名称)
#创建无线信号名称
[AC6005-wlan-ssid-prof-sb]ssid sg250 (WLAN的SSID名称)
5.VAP模版
#创建VAP模版
[AC6005-wlan-view]vap-profile name sb (VAP模版名称 )
#配置数据转发方式
[AC6005-wlan-vap-prof-sb]forward-mode tunnel
#配置业务VLAN
[AC6005-wlan-vap-prof-sb]service-vlan vlan-id 101
#VAP模版引用到安全模版
[AC6005-wlan-vap-prof-sb]security-profile dd (安全模版名称)
#VAP模版引用到SSID模版
[AC6005-wlan-vap-prof-sb]ssid-profile sb (SSID模版名称)
6.射频配置
[AC6005]wlan
#进入AP组
[AC6005-wlan-view]ap-group name dd (AP组名称)
#将VAP模版引用到射频模版中
[AC6005-wlan-ap-group-dd]vap-profile sb (VAP模版名称)wlan 1 radio 0
[AC6005-wlan-ap-group-dd]vap-profile sb (VAP模版名称)wlan 1 radio 1
三层组网
项目需求:
VLAN10、VLAN101为管理VLAN
AP1默认VLAN为VLAN10
AP2默认VLAN为VLAN101
STA分配地址为VLAN102
VLAN100为业务VLAN
核心交换机配置
DHCP中继,代理AC为AP、STA分配IP地址
[SW2]dhcp enable
[SW2]interface Vlanif 10
#启用DHCP中继
[SW2-Vlanif10]dhcp select relay
#DHCP中继IP地址
[SW2-Vlanif10] dhcp relay server-ip 10.1.100.1
AC配置
1.设置地址池–为AP提供地址
[AC6605]dhcp enable
[AC6605]ip pool v10
[AC6605-ip-pool-v10]network 10.1.10.0 mask 24
#地址池设置Option 43为AP发现AC
[AC6605-ip-pool-v10]option 43 sub-option 3 ascii 10.1.100.1
2.AP组和域管理模版
[AC6005]wlan
[AC6005-wlan-view]ap-group name dd (AP组名称)
[AC6005-wlan-ap-group-dd]regulatory-domain-profile name dd (域管理模版名称)
[AC6005-wlan-regulate-domain-dd]country-code cn
[AC6005-wlan-regulate-domain-dd]q
[AC6005-wlan-view]ap-group name dd (AP组名称)
[AC6005-wlan-ap-group-dd]regulatory-domain-profile dd (域管理模版名称)
3.创建与AP建隧道的接口
[AC6005]capwap source interface Vlanif 100
[AC6005]wlan
[AC6005-wlan-view]ap auth-mode mac-auth
[AC6005-wlan-view]ap-id 1 ap-mac 00e0-fc20-2f50 (AP接口MAC地址)
[AC6005-wlan-ap-1]ap-name AP1 (AP的名称)
[AC6005-wlan-ap-1]ap-group dd (AP组名称)
[AC6005-wlan-ap-1]q
[AC6005]wlan
[AC6005-wlan-view]ap-id 2 ap-mac 00e0-fc81-2670
[AC6005-wlan-ap-2]ap-name AP2 (AP的名称)
[AC6005-wlan-ap-2]ap-group dd (AP组名称)
[AC6005-wlan-ap-2]q
4.安全模版
[AC6005]wlan
[AC6005-wlan-view]security-profile name dd (安全模版名称)
[AC6005-wlan-sec-prof-dd]security wpa-wpa2 psk pass-phrase Huawei@123 aes
5.SSID模版
[AC6005]wlan
[AC6005-wlan-view]ssid-profile name sb (SSID模版名称)
[AC6005-wlan-ssid-prof-sb]ssid sg250 (WLAN的SSID名称)
[AC6005-wlan-ssid-prof-sb]q
6.VAP模版
[AC6005-wlan-view]vap-profile name sb (VAP模版名称 )
[AC6005-wlan-vap-prof-sb]forward-mode tunnel
[AC6005-wlan-vap-prof-sb]service-vlan vlan-id 101
[AC6005-wlan-vap-prof-sb]security-profile dd (安全模版名称)
[AC6005-wlan-vap-prof-sb]ssid-profile sb (SSID模版名称)
7.射频配置
[AC6005]wlan
[AC6005-wlan-view]ap-group name dd (AP组名称)
[AC6005-wlan-ap-group-dd]vap-profile sb (VAP模版名称)wlan 1 radio 0
[AC6005-wlan-ap-group-dd]vap-profile sb (VAP模版名称)wlan 1 radio 1