AC-AP
验证:验证AP是否能够获取IP地址
<Huawei>dis system-information //在AP中验证是否获取IP地址
System Information
===============================================
Serial Number : 21023544831070413239 :SN码
System Name : Huawei :系统名字(华为的设备)
Country Code : US :国家代码:US (美国)
MAC Address : 00:e0:fc:80:62:20 :MAC地址
Radio 0 MAC Address : 00:00:00:00:00:00 :射频信号频段 2.4GHz
Radio 1 MAC Address : 00:00:00:00:00:10 : 射频信号频段 5GHz
IP Address : 192.168.100.252 :成功从dhcp 获取IP地址
Subnet Mask : 255.255.255.0
Default Gateway : 192.168.100.254
<Huawei>display ip int brief //查看vlanif 的接口IP地址
interface GigabitEthernet0/0/1
port link-type access
port default vlan 200
dhcp enable
interface Vlanif200
ip address 192.168.200.1 255.255.255.0
dhcp select global
ip pool vlan200
gateway-list 192.168.200.1
network 192.168.200.0 mask 255.255.255.0
excluded-ip-address 192.168.200.200 192.168.200.253
dns-list 114.114.114.114
4) 在AC中配置capwap 隧道 --在AC和AP之间建立隧道
[AC6605] capwap source ip-address 192.168.200.1
备注:创建capwap 隧道,指定隧道的源地址为AC的管理IP:192.168.200.1
=========================================
备注:可以定义源接口,也可以定义源IP地址 :两条命令
capwap source ip-address 192.168.200.1
capwap source interface vlanif 200
=========================================
5)在AC中填写AP的MAC地址,让AC知道AP的存在
[AC6605]wlan
[AC6605-wlan-view]ap-id 1 ap-mac 00e0-fcb2-13f0
[AC6605-wlan-ap-1]quit
验证:
1)AP和AC网络要互联互通
[AC6605]ping 192.168.100.199
[AC6605] dis ap all //AC上查看ap注册信息
=========================================================================
排错方法:
1.检查AP是否获取IP地址了
2.检查AC能否ping通AP1 ---检查网络是否通
3.检查option参数 ---去dhcp服务器中ip pool 100中检查 option 是否配置正确
4.检查capwap隧道地址 --在AC中,检查capwap 隧道是否配置
5.重启ap --等待3分钟,看是否上线,如果不上线,重启ap
[AC6605]dis ap all
Info: This operation may take a few seconds. Please wait for a moment.done.
Total AP information:
nor : normal [4]
--------------------------------------------------------------------------------
ID MAC Name Group IP Type State
--------------------------------------------------------------------------------
1 00e0-fcb2-13f0 00e0-fcb2-13f0 default 192.168.100.253 AP6050DN nor
2 00e0-fcdd-4060 00e0-fcdd-4060 default 192.168.100.251 AP6050DN nor
3 00e0-fcd6-4110 00e0-fcd6-4110 default 192.168.100.250 AP6050DN nor
4 00e0-fc69-7790 00e0-fc69-7790 default 192.168.100.252 AP6050DN nor
--------------------------------------------------------------------------------
第二步:AC下发配置给AP
1)创建域管理配置文件-绑定国家码
[AC6605]wlan
[AC6605-wlan-view]regulatory-domain-profile name employee
[AC6605-wlan-regulate-domain-employee]country-code cn
[AC6605-wlan-regulate-domain-employee]quit
[AC6605-wlan-view]quit
2)创建AP组-绑定域管理配置文件
[AC6605]wlan
[AC6605-wlan-view]ap-group name employee
[AC6605-wlan-ap-group-employee]regulatory-domain-profile employee
[AC6605-wlan-ap-group-employee]quit
3)创建AP组,在AP组里添加物理AP设备
[AC6605]wlan
[AC6605-wlan-view]ap-id 1 //配置ap 1
[AC6605-wlan-ap-1]ap-name ap1 //给ap1 命名为 ap1
[AC6605-wlan-ap-1]ap-group employee //把ap1 加入ntd2312 组
[AC6605-wlan-ap-1]quit
4)验证AP设备是否加入AP组
[AC6605] dis ap all
Total AP information:
nor : normal [4]
--------------------------------------------------------------------------------
ID MAC Name Group IP Type State
ptime
--------------------------------------------------------------------------------
1 00e0-fcb2-13f0 bangong1 bangong 192.168.100.253 AP6050DN nor
2 00e0-fcdd-4060 bangong2 bangong 192.168.100.251 AP6050DN nor
3 00e0-fcd6-4110 xuexi1 xuexi 192.168.100.250 AP6050DN nor
4 00e0-fc69-7790 xuexi2 xuexi 192.168.100.252 AP6050DN nor
--------------------------------------------------------------------------------
Total: 4
[AC6605] dis ap-group all
--------------------------------------------------------------------------------
Name APs
--------------------------------------------------------------------------------
bangong 2
default 0
xuexi 2
--------------------------------------------------------------------------------
Total: 3
5)创建SSID配置文件-定义无线网名
[AC6605]wlan
[AC6605-wlan-view]ssid-profile name employee //创建ssid模版,命名为ntd2312
[AC6605-wlan-ssid-prof-employee]ssid employee //定义ssid的名字(无线网名)
[AC6605-wlan-ssid-prof-employee]quit
6)创建安全配置文件-定义无线网安全策略 预共享密钥,加密方式
[AC6605]wlan
[AC6605-wlan-view]security-profile name employee //创建安全模版,命名为employee
[AC6605-wlan-sec-prof-employee]security wpa-wpa2 psk pass-phrase NTD-HCIE aes
[AC6605-wlan-sec-prof-employee]quit
//定义安全策略,定义预共享密钥,定义加密方式
备注:
wpa-wap2 :是一种新的加密方式
psk :预共享密钥
pass-phrase : 口令短语
a12345678 :设置的密钥值
aes: 高级加密算法(美国国家标准加密算法)
11)在AC设备中,创建VLAN池-绑定多个VLAN: 给STA(电脑和手机)用的VLAN
[AC6605]vlan pool employee //创建vlan池,命名为bangong
[AC6605-vlan-pool-employee]vlan 200 //将vlan 200 加入ntd2312池
[AC6605-vlan-pool-employee]quit
12)创建VAP模板--绑定VLAN池子, 绑定SSID模板, 绑定安全模板
[AC6605]wlan
[AC6605-wlan-view]vap-profile name employee //创建vap模版,命名为bangong
[AC6605-wlan-vap-prof-employee]ssid-profile employee //绑定ssid模版
[AC6605-wlan-vap-prof-employee]security-profile employee //绑定安全模版
[AC6605-wlan-vap-prof-employee]service-vlan vlan-pool employee //绑定vlan池
[AC6605-wlan-vap-prof-employee]quit
13)将VAP配置文件绑定到AP组,把配置下发给AP组的物理设备
[AC6605]wlan
[AC6605-wlan-view]ap-group name employee //进入ap组
[AC6605-wlan-ap-group-employee]vap-profile employee wlan 1 radio 0
[AC6605-wlan-ap-group-employee]vap-profile employee wlan 1 radio 1
[AC6605-wlan-ap-group-employee]quit
//在ap设备组里绑定vap模版,并且定义射频频段
-指定AP组的射频频段: 2.4GHz 5.0GHz