AC旁挂在核心交换机上,AP的管理地址的DHCP在sw3上,转发模式隧道转发
AC接核心交换机的接口配置为TRUNK并允许对应VLAN通过 ,接入交换机接AP的端口配置为TRUNK并把pvid改为AP的管理VLAN。
在sw4配置AP的管理VLAN的DHCP
interface Vlanif103
ip address 10.1.103.2 255.255.255.0
dhcp select interface
dhcp server option 43 sub-option 3 ascii 10.1.5.1 //关键点, IP为AC的接口IP
因为不在同一网段,ap不知道ap的地址,通过DHCP把ac的地址告诉AP
AC配置
[AC6605-wlan-view] ap auth-mode no-auth //ap认证模式
[AC6605] capwap source interface vlanif5 //capwap隧道建立的IP地址
到了这步ap跟ac通信正常就会建立起capwap隧道
interface Vlanif5 //capwap隧道建立接口
ip address 10.1.5.1 255.255.255.0
interface Vlanif100 //分配给ap下面的PC用
ip address 10.1.100.254 255.255.255.0
dhcp select interface
interface Vlanif101
ip address 10.1.101.254 255.255.255.0
dhcp select interface
interface Vlanif102
ip address 10.1.102.254 255.255.255.0
dhcp select interface
创建安全模板
[AC6605-wlan-view] security-profile name huawei1
security wpa-wpa2 psk pass-phrase huawei aes
SSID模板
[AC6605-wlan-view]ssid-profile name huawei1
ssid huawei1
创建VAP模板
[AC6605-wlan-view]vap-profile name huawei1
forward-mode tunnel
service-vlan vlan-id 100
ssid-profile huawei1
security-profile huawei1
[AC6605-wlan-view] ap-group name default //在AP组下调用VAP模板
radio 0
vap-profile huawei1 wlan 1