topo图
配置代码
1、第1步,先让ap获取到IP地址,需要在交换机上配置dhcp中继
为什么,ap发出dhcp自动获取的报文给sw1,sw1告诉ap,需要获得dhcp地址,你需要去这个地方,也就是AC2
SWA
sy
sys SWA //为交换机命名为SWA
vlan batch 10 101 102
int g0/0/1
port link-type trunk //配置接口方式为trunk口
port trunk allow-pass vlan 10 101 102 //放行vlan 10、101、102
port trunk pvid vlan 10 //并设置其默认VLAN(PVID)为10,不设置的话默认是vlan1
int g0/0/2
port link-type trunk
port trunk allow-pass vlan 10 101 102
汇聚交换机SWB
sy
dhcp enable //开启dhcp功能,配置dhcp地址池,为业务vlan和管理vlan分配地址
vlan batch 10 100 101 102
int vlanif 10
ip add 10.23.10.1 24
dhcp select relay //配置dhcp中继
dhcp relay server-ip 10.23.100.1 //告诉ap,要获取动态IP地址,需要去这个ip地址
int vlanif 100
ip add 10.23.100.2 24 //配置vlan的IP地址
int vlanif 101
ip add 10.23.101.1 24
dhcp select global //配置dhcp获取ip地址的方式为global,也就是地址池吧
int vlanif 102
ip add 10.23.102.1 24
dhcp select global
q
ip pool wlan1 //为vlan101分配地址
network 10.23.101.0 mask 24
gateway-list 10.23.101.1 //网关为这个
ip pool wlan2
network 10.23.102.0 mask 24
gateway-list 10.23.102.1
q
int g0/0/1
port link-type trunk //接口方式为trunk口,似乎交换机之间都是trunk口
port trunk allow-pass vlan 10 101 102 //放行vlan
int g0/0/2
port link-type trunk
port trunk allow-pass vlan 100
int g0/0/3
port link-type trunk
port trunk allow-pass vlan 101 102
q
AC
sy
sys AC1 //命名为AC1
dhcp enable
vlan batch 100 to 102 //创建vlan 100 101 102
int g0/0/1
port link-type trunk
port trunk allow-pass vlan 100 //放行vlan100
int vlanif 100
ip add 10.23.100.1 24
q
ip route-static 10.23.10.0 255.255.255.0 10.23.100.2
ip pool wlan
network 10.23.10.0 mask 24 //为vlan10分配IP地址范围
gateway-list 10.23.10.1 //网关为10.23.10.1
option 43 sub-option 3 ascii 10.23.100.1 //表示设置选项43的子选项3为10.23.100.1
配置完以上部分,ap就应该能够获取IP地址流量,如果没有ip地址,请检查是否配置错误
ap查看IP地址为dis arp
q
int vlanif 100
dhcp select global
q
vlan pool sta-pool
vlan 101
vlan 102
assignment hash
q
wlan
ap-group name ap-group1
q
regulatory-domain-profile name default
country-code cn
q
ap-group name ap-group1
regulatory-domain-profile default
y
q
q
capwap source interface vlan 100
wlan
ap-id 0 ap-mac 00e0-fcbe-5960
ap-group ap-group1
y
security-profile name wlan-security
security wpa-wpa2 psk pass-phrase a1234567 aes
q
ssid-profile name wlan-ssid
ssid wlan-net
q
vap-profile name wlan-vap
forward-mode tunnel
service-vlan vlan-pool sta-pool
security-profile wlan-security
ssid-profile wlan-ssid
q
ap-group name ap-group1
vap-profile wlan-vap wlan 1 radio 0
vap-profile wlan-vap wlan 1 radio 1
AR1
system-view
sysname R1
int g0/0/0
int g0/0/0.1
ip address 10.23.101.2 24
dot1q termination vid 101
int g0/0/0.2
ip address 10.23.102.2 24
dot1q termination vid 102
q
以下是正确配置
1、第1步,先让ap获取到IP地址,需要在交换机上配置dhcp中继
为什么,ap发出dhcp自动获取的报文给sw1,sw1告诉ap,需要获得dhcp地址,你需要去这个地方,也就是AC2
SWA
sy
sys SWA //为交换机命名为SWA
vlan batch 10 101 102
int g0/0/1
port link-type trunk //配置接口方式为trunk口
port trunk allow-pass vlan 10 //放行vlan 10
port trunk pvid vlan 10 //并设置其默认VLAN(PVID)为10,不设置的话默认是vlan1
int g0/0/2
port link-type trunk
port trunk allow-pass vlan 10 101 102
汇聚交换机SWB
sy
dhcp enable //开启dhcp功能,配置dhcp地址池,为业务vlan和管理vlan分配地址
vlan batch 10 100 101 102
int vlanif 10
ip add 10.23.10.1 24
dhcp select relay //配置dhcp中继
dhcp relay server-ip 10.23.100.1 //告诉ap,要获取动态IP地址,需要去这个ip地址
int vlanif 100
ip add 10.23.100.2 24 //配置vlan的IP地址
int vlanif 101
ip add 10.23.101.1 24
dhcp select global //配置dhcp获取ip地址的方式为global,也就是地址池吧
int vlanif 102
ip add 10.23.102.1 24
dhcp select global
q
ip pool wlan1 //为vlan101分配地址
network 10.23.101.0 mask 24
gateway-list 10.23.101.1 //网关为这个
ip pool wlan2
network 10.23.102.0 mask 24
gateway-list 10.23.102.1
q
int g0/0/1
port link-type trunk //接口方式为trunk口,似乎交换机之间都是trunk口
port trunk allow-pass vlan 10 101 102 //放行vlan
int g0/0/2
port link-type trunk
port trunk allow-pass vlan 100 101 102
int g0/0/3
port link-type trunk
port trunk allow-pass vlan 101 102
q
AC
sy
sys AC1 //命名为AC1
dhcp enable
vlan batch 100 to 102 //创建vlan 100 101 102
int g0/0/1
port link-type trunk
port trunk allow-pass vlan 100 //放行vlan100
int vlanif 100
ip add 10.23.100.1 24
q
ip route-static 10.23.10.0 255.255.255.0 10.23.100.2
ip pool wlan
network 10.23.10.0 mask 24 //为vlan10分配IP地址范围
gateway-list 10.23.10.1 //网关为10.23.10.1
option 43 sub-option 3 ascii 10.23.100.1 //表示设置选项43的子选项3为10.23.100.1
配置完以上部分,ap就应该能够获取IP地址流量,如果没有ip地址,请检查是否配置错误
ap查看IP地址为dis arp
q
int vlanif 100
dhcp select global
q
vlan pool sta-pool
vlan 101
vlan 102
assignment hash
q
wlan
ap-group name ap-group1
q
regulatory-domain-profile name default
country-code cn
q
ap-group name ap-group1
regulatory-domain-profile default
y
q
q
capwap source interface vlan 100
wlan
ap-id 0 ap-mac 00e0-fcbe-5960
ap-group ap-group1
y
security-profile name wlan-security
security wpa-wpa2 psk pass-phrase a1234567 aes
q
ssid-profile name wlan-ssid
ssid wlan-net
q
vap-profile name wlan-vap
forward-mode tunnel
service-vlan vlan-pool sta-pool
security-profile wlan-security
ssid-profile wlan-ssid
q
ap-group name ap-group1
vap-profile wlan-vap wlan 1 radio 0
vap-profile wlan-vap wlan 1 radio 1
AR1
system-view
sysname R1
int g0/0/0
int g0/0/0.1
ip address 10.23.101.2 24
dot1q termination vid 101
int g0/0/0.2
ip address 10.23.102.2 24
dot1q termination vid 102
q
总结,可能部分代码有错误,但是这个网络连通性没问题,测试没问题
我用的wpa-wpa2,在pc上显示的无认证方式,配置wpa2显示有wpa2认证
对于隧道模式,ap需要将vlan交给ac处理,所以在核心交换机上,需要对ac通行业务vlan 101 102,直接转发是在ap上直接处理
验证
参考文章
无线接入控制器(AC和FIT AP) V200R019C00 配置指南(命令行) - 华为 (huawei.com)
这个好