拓扑图如下
设备 | 接口 | IP地址、端口状态 | 备注 |
router | g0/0/0 | 192.168.200.2/30 |
需求
(1)配置隧道转发模式,完成AP上线,内部办公用户只能通过无线上网(vlan101)
(2)访客(vlan102)能通过无线上网
(3)配置vlan100、vlan101和vlan102,vlan100用于AP管理,vlan101为内部用户提供上网服务(ssid:work),vlan102为访客提供上网服务(ssid:fangke)。AP通过AC DHCP自动获取192.168.100.0/24网段的IP地址,内部用户和访客通过SW1DHCP自动分配对应网段的IP地址。
配置过程
R1 :
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.200.2 30
[Huawei-GigabitEthernet0/0/0]quit
<Huawei>ping 192.168.200.1
PING 192.168.200.1: 56 data bytes, press CTRL_C to break
Reply from 192.168.200.1: bytes=56 Sequence=1 ttl=255 time=40 ms
Reply from 192.168.200.1: bytes=56 Sequence=2 ttl=255 time=40 ms
Reply from 192.168.200.1: bytes=56 Sequence=3 ttl=255 time=110 ms
Reply from 192.168.200.1: bytes=56 Sequence=4 ttl=255 time=30 ms
Reply from 192.168.200.1: bytes=56 Sequence=5 ttl=255 time=60 ms
[router]ip route-static 192.168.102.0 24 192.168.200.1
[router]ip route-static 192.168.101.0 24 192.168.200.1
SW1:
<Huawei>sys
[Huawei]sysname sw1
[sw1]vlan batch 100 101 102 200
[sw1]int g0/0/1
[sw1-GigabitEthernet0/0/1]port link-type trunk
[sw1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
[sw1-GigabitEthernet0/0/1]int g0/0/2
[sw1-GigabitEthernet0/0/2]port link-type trunk
[sw1-GigabitEthernet0/0/2]port trunk allow-pass vlan all
[sw1-GigabitEthernet0/0/2]int g0/0/3
[sw1-GigabitEthernet0/0/3]port link-type access
[sw1-GigabitEthernet0/0/3]port default vlan 200
[sw1-GigabitEthernet0/0/3]quit
[sw1]int vlan 101
[sw1-Vlanif101]ip add 192.168.101.254 24
[sw1-Vlanif101]int vlan 102
[sw1-Vlanif102]ip add 192.168.102.254 24
[sw1-Vlanif102]quit
[sw1]int vlan 200
[sw1-Vlanif200]ip add 192.168.200.1 30
[sw1-Vlanif200]quit
[sw1]dhcp enable
[sw1]int vlan 101
[sw1-Vlanif101]dhcp select interface
[sw1-Vlanif101]int vlan 102
[sw1-Vlanif102]dhcp select interface
SW2:
<Huawei>sys
[Huawei]sysname sw2
[sw2]
[sw2]vlan 100
[sw2-vlan100]quit
[sw2]int g0/0/1
[sw2-GigabitEthernet0/0/1]port link-type trunk
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
[sw2-GigabitEthernet0/0/1]port trunk pvid vlan 100
[sw2-GigabitEthernet0/0/1]di th
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100
#
return
[sw2-GigabitEthernet0/0/1]quit
[sw2]int g0/0/2
[sw2-GigabitEthernet0/0/2]port link-type trunk
[sw2-GigabitEthernet0/0/2]port trunk allow-pass vlan 100
[sw2-GigabitEthernet0/0/2]port trunk pvid vlan 100
[sw2-GigabitEthernet0/0/2]dis th
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100
#
return
[sw2-GigabitEthernet0/0/2]quit
[sw2]int g0/0/3
[sw2-GigabitEthernet0/0/3]port link-type trunk
[sw2-GigabitEthernet0/0/3]port trunk allow-pass vlan 100
AC6605:
<AC6605>sys
[AC6605]vlan batch 100 101 102
[AC6605]int g0/0/1
[AC6605-g0/0/1]port link-type trunk
[AC6605-g0/0/1]port trunk allow-pass vlan all
[AC6605-g0/0/1]quit
[AC6605]interface vlan 100
[AC6605-vlanif100]ip add 192.168.100.254 24
#开启DHCP功能,为AP分配IP地址
[AC6605]dhcp enable
[AC6605]int vlan 100
[AC6605-vlanif100]dhcp select interface //为ap分配vlanif100相同网段的管理地址
(3)在AC上配置AP上线
1.创建与管理模板
[AC6605]wlan
[AC6605-wlan-view]regulatory-domain-profile name summer//配置域管理模板,名称为summer,名字可以任意
[AC6605-wlan-regulatory-domain-summer]country-code cn//配置国家代码,cn代表中国
2.创建AP组,并引用特定的与管理参数
[AC6605-wlan-view]ap-group name summer
[AC6605-wlan-ap-group-summer]regulatory-domain-profie summer//引用域管理模板
.......[Y/N]:Y// 表示确认
3.配置CAPWAP隧道源接口或源地址
[AC6605]capwap soure interface vlanif100
4.配置AP设备入网认证
[AC6605]wlan
[AC6605-wlan-view]ap auth-mode mac-auth //配置为mac地址认证
[AC6605-wlan-view]ap-id 1 ap-mac 00e0-fc95-2860//输入要认证色AP1的MAC地址
[AC6605-wlan-ap-1]
[AC6605-wlan-ap-1]ap-group summer//j加入AP组summer
.......[Y/N]:y
#配置AP2上线
[AC6605-wlan-view]ap-group name fangke
Info: This operation may take a few seconds. Please wait for a moment.done.
[AC6605-wlan-ap-group-fangke]regu
[AC6605-wlan-ap-group-fangke]regulatory-domain-profile summer
Warning: Modifying the country code will clear channel, power and antenna gain c
onfigurations of the radio and reset the AP. Continue?[Y/N]:y
[AC6605-wlan-ap-group-fangke]quit
[AC6605-wlan-view]ap-id 2 ap-mac 00e0-fc45-2790
[AC6605-wlan-ap-2]
[AC6605-wlan-ap-2]ap-gr
[AC6605-wlan-ap-2]ap-group fangke
Warning: This operation may cause AP reset. If the country code changes, it will
clear channel, power and antenna gain configurations of the radio, Whether to c
ontinue? [Y/N]:y
5.检查AP上线结果
无线控制器wlan业务配置,配置完成后会自动下发到对应的AP
1.配置用户认证方式
[AC6605-wlan】wlan
[AC6605-wlan-view]security-profile name summer//安全模板,名字为summer
[AC6605-wlan-security-profile-summer]security wpa-wpa2 psk pass-phrase a1234567 aes//采用WPA-WPA2方式认证,PSK表示预共享密码,简单理解就是通过密码方式认证
2.配置SSID模板
[AC6605-wlan-view]ssid-profile name summer
[AC6605-wlan-ssid-profile-summer]ssid work//ssid名称为work
3.配置VAP模板,设置为隧道模式,配置用户vlan101,并绑定安全模板、SSID模板
[AC6605-wlan-view】vap-profile name work
[AC6605-wlan-vap-prof-work]forward-mode tunnel//配置转发模式为隧道模式
[AC6605-wlan-vap-prof-work]service-vlan vlan-id 101 //为用户服务vlan是101,所有连接这个vap的用户被划分到vlan101
[AC6605-wlan-vap-prof-work]security-profile summer
[AC6605-wlan-vap-prof-work]ssid-profile summer
[AC6605-wlan-vap-prof-work]quit
4.在ap组中绑定VAP模板
[AC6605-wlan-view]ap-group name summer
[AC6605-wlan-ap-group-summer]vap-profile work wlan 1 radio 0 //在ap组中,指定的VAP模板引用到射
[AC6605-wlan-view]ap-group name fangke
[AC6605-wlan-ap-group-fangke]vap-pro
[AC6605-wlan-ap-group-fangke]vap-profile famgke wlan 2 ra
[AC6605-wlan-ap-group-fangke]vap-profile famgke wlan 2 radio 0
Error: The VAP profile does not exist.
[AC6605-wlan-ap-group-fangke]vap-pro
[AC6605-wlan-ap-group-fangke]vap-profile fangke wlan 2 ra
[AC6605-wlan-ap-group-fangke]vap-profile fangke wlan 2 radio 0
Info: This operation may take a few seconds, please wait...done.
[AC6605-wlan-ap-group-fangke]
配置完成后。STA1可以正常连接,如图
测试STA1ping路由器地址192.168.200.2 vlanif200接口地址192.168.200.1都可以通
STA1去pingSTA2也可以通