实验规划:
AC旁挂,三层组网。用户和AP网关在SW1,员工用户使用隧道转发,访客用户使用直接转发。
拓扑图
第一步设置二层网络
SW1:
[SW1]vlan batch 20 30 40 50 60
[SW1]interface GigabitEthernet0/0/1
[SW1] port link-type access
[SW1]port default vlan 60
[SW1]interface GigabitEthernet0/0/2
[SW1] port link-type trunk
[SW1]port trunk allow-pass vlan 20 50
[SW1]interface GigabitEthernet0/0/3
[SW1]port link-type trunk
[SW1]port trunk allow-pass vlan 30 40
SW2:
[SW2]vlan batch 30 40
[SW2]interface GigabitEthernet0/0/1
[SW2]port link-type trunk
[SW2]port trunk allow-pass vlan 30 40
[SW2]interface GigabitEthernet0/0/2
[SW2]port link-type trunk
[SW2]port trunk pvid vlan 40
[SW2]port trunk allow-pass vlan 30 40
[SW2]interface GigabitEthernet0/0/3
[SW2]port link-type trunk
[SW2] port trunk pvid vlan 40
[SW2]port trunk allow-pass vlan 30 40
AC:
[AC]vlan batch 20 50
[AC]interface GigabitEthernet0/0/1
[AC]port link-type trunk
[AC] port trunk allow-pass vlan 20 50
第二步设置IP,保证网络互通
SW1:
[SW1]interface Vlanif20
[SW1]ip address 192.168.20.254 255.255.255.0
[SW1]dhcp select global
[SW1]interface Vlanif30
[SW1] ip address 192.168.30.254 255.255.255.0
[SW1]dhcp select global
[SW1]interface Vlanif40
[SW1]ip address 192.168.40.254 255.255.255.0
[SW1]dhcp select global
[SW1]interface Vlanif50
[SW1] ip address 192.168.50.254 255.255.255.0
[SW1]interface Vlanif60
[SW1]ip address 192.168.60.254 255.255.255.0
设置到AC的静态路由
[SW1]ip route-static 10.10.10.10 255.255.255.255 192.168.50.1
AC:
[AC]interface Vlanif50
[AC] ip address 192.168.50.1 255.255.255.0
[AC]interface LoopBack0
[AC]ip address 10.10.10.10 255.255.255.255
第三步配置AP上线
SW1开启DHCP服务,配置AP地址池
[SW1]dhcp enable
[SW1]ip pool ap
[SW1]gateway-list 192.168.40.254
[SW1]network 192.168.40.0 mask 255.255.255.0
[SW1]option 43 sub-option 3 ascii 10.10.10.10
配置员工用户地址池
[SW1]ip pool emp
[SW1]gateway-list 192.168.20.254
[SW1]network 192.168.20.0 mask 255.255.255.0
配置访客用户地址池
[SW1]ip pool guest
[SW1]gateway-list 192.168.30.254
[SW1]network 192.168.30.0 mask 255.255.255.0
在接口下启用全局地址池功能
[SW1]interface Vlanif20
[SW1]dhcp select global
[SW1] interface Vlanif30
[SW1] dhcp select global
[SW1]interface Vlanif40
[SW1] dhcp select global
配置AC源接口地址
[AC]capwap source interface loopback0
设置AP组和认证方式
[AC]wlan
[AC-WLAN-VIEW]ap-group name emp
[AC-WLAN-VIEW]ap auth-mode no auth
[AC-WLAN-VIEW]dis ap all
显示AP已经上线
第四步配置WLAN业务
\创建SSID模板
[AC-wlan-view]ssid-profile name emp
[AC-wlan-ssid-prof-emp] ssid emp
[AC-wlan-ssid-prof-emp] q
[AC-wlan-view]ssid-profile name guest
[AC-wlan-ssid-prof-guest] ssid guest
[AC-wlan-ssid-prof-guest]q
\创建安全模板
[AC-wlan-view]security-profile name emp
[AC-wlan-sec-prof-emp] security wpa-wpa2 psk pass-phrase 12345678 aes
[AC-wlan-sec-prof-emp] q
[AC-wlan-view]security-profile name guest
[AC-wlan-sec-prof-guest] security open
\创建VAP模板
vap-profile name emp
forward-mode tunnel
service-vlan vlan-id 20
ssid-profile emp
security-profile emp
vap-profile name guest
[AC-wlan-vap-prof-guest]forward-mode direct-forward
service-vlan vlan-id 30
ssid-profile guest
security-profile guest
[AC]wlan
[AC-wlan-view]regulatory-domain-profile name emp \设置域模板
[AC-wlan-regulate-domain-emp]country-code CN \国家码
[AC-wlan-regulate-domain-emp]q
[AC-wlan-view]ap-group name emp \进入AP组
[AC-wlan-ap-group-emp] regulatory-domain-profile emp \绑定域模板
[AC-wlan-ap-group-emp]vap-profile emp wlan 1 radio all \绑定VAP 员工模板
[AC-wlan-ap-group-emp]vap-profile guest wlan 2 radio all \绑定VAP 访客模板
[AC]wlan
[AC-wlan-view]dis vap ssid emp \查询员工SSID信息
[AC-wlan-view]dis vap ssid guest \查询访客SSID信息
STA连接员工和访客信号,确保获取地址正确
ping路由器AR测试连通性