一、拓扑图
二、地址规划
Vlan100:10.23.100.1/24 AP的管理IP地址
Vlan101:10.23.101.1/24 无线用户获取的IP地址
三、基础配置
交换机(SW):
<Huawei>system-view
[Huawei]sysname SW
[SW]vlan batch 100 101
# 创建Vlan
[SW]interface GigabitEthernet0/0/1
[SW-GigabitEthernet0/0/1]description AC
[SW-GigabitEthernet0/0/1]port link-type trunk
[SW-GigabitEthernet0/0/1]port trunk allow-pass vlan 100 to 101
# 设置备注为AC,设置端口为trunk 放行Vlan 100 101
[SW-GigabitEthernet0/0/1]interface GigabitEthernet0/0/2
[SW-GigabitEthernet0/0/2]description AP
[SW-GigabitEthernet0/0/2]port link-type trunk
[SW-GigabitEthernet0/0/2]port trunk pvid vlan 100
[SW-GigabitEthernet0/0/2]port trunk allow-pass vlan 100 to 101
# 设置备注为AP,设置端口为trunk ,给这个端口打标签100,放行Vlan 100 101
AC配置:
<AC6005>system-view
[AC6005]sysname AC
[AC]vlan batch 100 101
# 创建Vlan
[AC]dhcp enable
# 开启DHCP服务
[AC]interface Vlanif 100
# 进入Vlan100
[AC-Vlanif100]description AP_Manage
[AC-Vlanif100]ip add 10.23.100.1 24
# 设置管理vlan ip
[AC-Vlanif100]dhcp select interface
# 为DHCP选择源接口
[AC-Vlanif100]quit
[AC]interface Vlanif 101
# 进入Vlan101
[AC-Vlanif101]description USER
[AC-Vlanif101]ip add 10.23.101.1 24
# 设置用户vlan ip
[AC-Vlanif101]dhcp select interface
# 为DHCP选择源接口
[AC-Vlanif101]capwap source interface Vlanif 100
# 为capwap隧道绑定vlan
[AC]interface GigabitEthernet0/0/1
[AC-GigabitEthernet0/0/1]port link-type trunk
[AC-GigabitEthernet0/0/1]port trunk allow-pass vlan 100 101
# 配置AC接口配置设置trunk口,放行100 101
[AC-GigabitEthernet0/0/1]quit
[AC]wlan
# 进入无线视图
[AC-wlan-view]ap auth-mode no-auth
# 开启AP上线 不需要认证(自动发现)
AP上线:
1、启动AP
2、查看AP上线情况
display ap all
状态为
nor
表示上线成功
五、配置无线模板
[AC]wlan
# 进入无线视图
[AC-wlan-view]regulatory-domain-profile name hadesr
# 创建域管理模板,名称为hadesr
[AC-wlan-regulate-domain-hadesr]country-code CN
# 配置国家代码
[AC-wlan-regulate-domain-hadesr]ssid-profile name hadesr-ssid
# 创建SSID模板,名称为hadesr-ssid
[AC-wlan-ssid-prof-hadesr-ssid]ssid Hadesr
# 配置SSID名称为Hadesr
[AC-wlan-ssid-prof-hadesr-ssid]security-profile name hadesr-security
# 创建安全策略,名称为hadesr-security
[AC-wlan-sec-prof-hadesr-security]security wpa-wpa2 psk pass-phrase 123456789 aes
# SSID密码为123456789
ters a to z, uppercase letters A to Z, digits, and special characters. Continue?[Y/N]:
y
[AC-wlan-sec-prof-hadesr-security]vap-profile name hadesr-vap
# 创建VAP模板
[AC-wlan-vap-prof-hadesr-vap]forward-mode direct-forward
# 配置业务数据转发模式
[AC-wlan-vap-prof-hadesr-vap]security-profile hadesr-security
# 绑定安全策略
[AC-wlan-vap-prof-hadesr-vap]ssid-profile hadesr-ssid
# 绑定SSID模板
[AC-wlan-vap-prof-hadesr-vap]service-vlan vlan-id 101
# 绑定业务VLAN
[AC-wlan-vap-prof-hadesr-vap]ap-group name hadesr-ap-group
# 创建AP组,名称为office-ap-group
[AC-wlan-ap-group-hadesr-ap-group]regulatory-domain-profile hadesr
# 绑定域模板
onfigurations of the radio and reset the AP. Continue?[Y/N]:
y
[AC-wlan-ap-group-hadesr-ap-group]vap-profile hadesr-vap wlan 1 radio 0
# 绑定vap模板到射频卡0上,radio 0表示2.4g信号
[AC-wlan-ap-group-hadesr-ap-group]vap-profile hadesr-vap wlan 1 radio 1
# 绑定vap模板到射频卡1上,radio 1表示5g信号
[AC-wlan-ap-group-hadesr-ap-group]ap-id 0
[AC-wlan-ap-0]ap-name AP-Hadesr
[AC-wlan-ap-0]ap-group hadesr-ap-group
# 将ap放入到ap-group组中,0是AP的ID可以使用display ap all命令查看
clear channel, power and antenna gain configurations of the radio, Whether to continue? [Y/N]:
y
等待
ap
重启,并用笔记本连接wlan
验证:
最后:如果发给别人,设备关闭前记得使用
save命令
保存哦