组网要求:AC为核心交换机中的板卡,双方通过内部端口互联。AP通过POE交换机连接。现在要求无线客户端通过连接AP可以获得不同的Vlan。其中vlan 31是用于AP,42-44是客户端使用,100是核心交换机的管理地址(192.168.100.1)
一、核心交换机主要配置(192.168.100.1)
interface Vlan-interface42
ip address 192.168.42.1 255.255.255.0
interface Vlan-interface43
ip address 192.168.43.1 255.255.255.0
interface Vlan-interface44
ip address 192.168.44.1 255.255.255.0
//配置DHCP服务,使Client端自动获取IP地址
dhcp server ip-pool vlan42
gateway-list 192.168.40.1
network 192.168.40.0 mask 255.255.255.0
dns-list 114.114.114.114
dhcp server ip-pool vlan43
gateway-list 192.168.43.1
network 192.168.43.0 mask 255.255.255.0
dns-list 114.114.114.114
dhcp server ip-pool vlan44
gateway-list 192.168.44.1
network 192.168.44.0 mask 255.255.255.0
dns-list 114.114.114.114
//配置vlan 31,使AP自动获取IP地址。(备注:在AC上配置vlan31的DHCP)
interface Vlan-interface31
ip address dhcp-alloc
//配置静态路由指向AC管理地址
ip route-static 192.168.31.0 24 192.168.100.5
//针对与AC直接互联的2个端口做端口聚合。
interface Bridge-Aggregation1
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 2 to 4094
interface Ten-GigabitEthernet2/0/1
port link-mode bridge
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 2 to 4094
port link-aggregation group 1
interface Ten-GigabitEthernet2/0/2
port link-mode bridge
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 2 to 4094
port link-aggregation group 1
二、AC上配置(192.168.100.5)
备注:vlan 31是AP获取的本身地址,vlan 42-44是客户端获取的IP地址,vlan 46是WLAN-ESS4的缺省地址,vlan 100是核心交换机的管理地址。
//配置AP获取的IP地址
Vlan 31
interface Vlan-interface31
ip address 192.168.31.1 255.255.255.0
dhcp server ip-pool vlan31
network 192.168.31.0 mask 255.255.255.0
gateway-list 192.168.31.1
//配置无线获取的vlan地址池
wlan vlan-pool ceshi
vlan-id 42 to 44
interface WLAN-ESS1
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 46 untagged
port hybrid pvid vlan 46
mac-vlan enable //允许同一SSID中不同vlan用户漫游
port-security port-mode psk //创建秘钥
port-security tx-key-type 11key //使能11key类型的密钥协商功能
port-security preshared-key pass-phrase simple ceshi //无线密码:ceshi
wlan service-template 1 crypto // 配置服务模板为crypto类型(无线服务模板为加密方式)
ssid ceshi //无线名称:ceshi
bind WLAN-ESS 1 // 将WLAN-ESS1接口绑定到服务模板
cipher-suite ccmp //启用ccmp加密套件
security-ie rsn //启用rsn加密套件
service-template enable //开启服务模版,需要最后使用
//针对与核心交换机直接互联的2个端口做了端口聚合。
interface Bridge-Aggregation1
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 31 42 to 44 46 100
interface Ten-GigabitEthernet1/0/1
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 31 42 to 44 46 100
port link-aggregation group 1
interface Ten-GigabitEthernet1/0/2
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 31 42 to 44 46 100
port link-aggregation group 1
//配置一个AP
wlan ap ceshi model xxxxxxxxxxx //添加型号
serial-id xxxxxxxxxxxxxxxxxxxx //输入序列号
radio 1
channel 149
service-template 1 vlan-pool ceshi
radio enable
radio 2
channel 11
service-template 1 vlan-pool ceshi
radio enable