组网要求:AC为核心交换机中的板卡,双方通过内部端口互联。AP通过POE交换机连接。现在用户需要使用用户名和密码才能登录。WIFI用户名:ceshi 密码:ceshi 。其中vlan 31是用于AP,40是客户端使用,100是核心交换机的管理地址(192.168.100.1)
一、核心交换机配置(192.168.100.1)
Vlan 31、40、100
//配置vlan 31,使AP自动获取IP地址。(备注:在AC上配置vlan31的DHCP)
interface Vlan-interface31
ip address dhcp-alloc //使用动态的方式从DHCP服务器获得IP地址
//客户端获得的IP地址
int vlan 40
ip address 192.168.40.1 24
dhcp server ip-pool vlan40
gateway-list 192.168.40.1
network 192.168.40.0 mask 255.255.255.0
dns-list 114.114.114.114
//配置静态路由指向AC管理地址
ip route-static 192.168.31.0 24 192.168.100.5
//针对与AC直接互联的2个端口做端口聚合。
interface Bridge-Aggregation1
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 2 to 4094
interface Ten-GigabitEthernet2/0/1
port link-mode bridge
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 2 to 4094
port link-aggregation group 1
interface Ten-GigabitEthernet2/0/2
port link-mode bridge
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 2 to 4094
port link-aggregation group 1
二、AC上配置(192.168.100.5)
备注:vlan 31是AP使用,vlan 40 是客户端使用,vlan 46是缺省vlan,vlan 100是核心交换机的管理地址。
//配置AP获取的IP地址
Vlan 31 40
interface Vlan-interface31
ip address 192.168.31.1 255.255.255.0
dhcp server ip-pool vlan31
network 192.168.31.0 mask 255.255.255.0
gateway-list 192.168.31.1
interface WLAN-ESS1
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 46 untagged
port hybrid pvid vlan 46
mac-vlan enable //允许同一SSID中不同vlan用户漫游
port-security port-mode psk //创建秘钥
port-security tx-key-type 11key //使能11key类型的密钥协商功能
port-security preshared-key pass-phras simple ceshi //配置密码:ceshi
wlan service-template 1 crypto //crypto,说明此无线服务模板为加密方式
ssid cehsi //无线名称:ceshi
bind WLAN-ESS 1 // 将WLAN-ESS1接口绑定到服务模板
cipher-suite ccmp //启用ccmp加密套件
security-ie rsn //启用rsn加密套件
service-template enable //开启服务模版,需要最后使用
//针对与核心交换机直接互联的2个端口做了端口聚合。
interface Bridge-Aggregation1
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 31 40 100
interface Ten-GigabitEthernet1/0/1
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 31 40 100
port link-aggregation group 1
interface Ten-GigabitEthernet1/0/2
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 31 40 100
port link-aggregation group 1
//加一个AP测试
wlan ap ceshi model xxxxxxxxxxxx //添加型号
serial-id xxxxxxxxxxxxxxx //输入序列号
radio 1
channel 149
service-template 1 //在射频口绑定服务模板
radio enable //使能射频口
radio 2
channel 1
service-template 1
radio enable