配置实验:
1.需求
AP1通过DHCP Server获取IP地址;AP2通过LSW1基于接口Vlanif 20获取IP地址
AP1、AP2获取地址后与AC建立三层连接,AC上完成上线配置和业务配置,并下发给AP
STA1连接WIFI信号,自动获取IP地址,可直接访问外网10.10.10.10
2.基础配置
2.1 LSW2配置
vlan batch 10 20 50
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk pvid vlan 10
port trunk allow-pass vlan 10 50
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk pvid vlan 20
port trunk allow-pass vlan 20 50
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 10 20 50
2.2 LSW1配置
#
vlan batch 10 20 30 40 50 60
#
dhcp enable
#
interface Vlanif10
ip address 192.168.1.1 255.255.255.0
dhcp select relay
dhcp relay server-ip 192.168.3.1
#
interface Vlanif20
ip address 192.168.2.1 255.255.255.0
dhcp select interface# 告诉AP AC的位置(3层组网)
dhcp server option 43 sub-option 2 ip-address 192.168.4.1
#
interface Vlanif30
ip address 192.168.3.2 255.255.255.0
#
interface Vlanif40
ip address 192.168.4.2 255.255.255.0
#
interface Vlanif50
ip address 192.168.5.1 255.255.255.0
dhcp select interface
#
interface Vlanif60
ip address 192.168.6.1 255.255.255.0
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 30
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 40
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 10 20 50
#
interface GigabitEthernet0/0/4
port link-type access
port default vlan 60
#
ip route-static 10.10.10.0 24 192.168.6.2
2.3 AR2配置
#
interface GigabitEthernet0/0/0
ip address 192.168.6.2 255.255.255.0
#
interface LoopBack0
ip address 10.10.10.10 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 192.168.6.1
2.4 AR1配置
#
dhcp enable
#
ip pool AP1-pool
network 192.168.1.0 mask 255.255.255.0# 告诉AP AC的位置(3层组网)
option 43 sub-option 2 ip-address 192.168.4.1
#
interface GigabitEthernet0/0/1
ip address 192.168.3.1 255.255.255.0
dhcp select global
#
ip route-static 0.0.0.0 0.0.0.0 192.168.3.2
3. AC1基础配置
[AC1]vlan 40
[AC1]interface Vlanif 40
[AC1-Vlanif40]ip address 192.168.4.1 24
#
[AC1]interface GigabitEthernet 0/0/2
[AC1-GigabitEthernet0/0/2]port link-type trunk
[AC1-GigabitEthernet0/0/2]port trunk allow-pass vlan 40
#
[AC1]ip route-static 0.0.0.0 0 192.168.4.2
4. AC1进行AP上线配置
#
[AC1]capwap source interface Vlanif 40
[AC1]wlan
# 设置AP的射频国家配置模板
[AC1-wlan-view]regulatory-domain-profile name default
[AC1-wlan-regulate-domain-default]country-code cn
# 创建AP组并应用国家射频模板
[AC1-wlan-view]ap-group name Stu
[AC1-wlan-ap-group-Stu]regulatory-domain-profile default
# ap通过mac认证
[AC1-wlan-view]ap auth-mode mac-auth
# 绑定ap的mac和id
[AC1-wlan-view]ap-id 1 ap-mac 00e0-fc01-6260
# 重命名ap
[AC1-wlan-ap-1]ap-name ap1
# 当前ap加入Stu的ap组
[AC1-wlan-ap-1]ap-group Stu
#
[AC1-wlan-view]ap-id 2 ap-mac 00e0-fcf8-38d0
[AC1-wlan-ap-2]ap-name ap2
[AC1-wlan-ap-2]ap-group Stu
5. AC1进行AP业务配置
# 配置安全模板
[AC1-wlan-view]security-profile name Stu-Sec
[AC1-wlan-sec-prof-Stu-Sec]security wpa2 psk pass-phrase huawei@123 aes
# 配置SSID模板
[AC1-wlan-view]ssid-profile name Stu-ssid
[AC1-wlan-ssid-prof-Stu-ssid]ssid Student
# 配置VAP模板
[AC1-wlan-view]vap-profile name Stu-vap
#关联安全模板
[AC1-wlan-vap-prof-Stu-vap]security-profile Stu-sec
#关联ssid模板
[AC1-wlan-vap-prof-Stu-vap]ssid-profile Stu-ssid
#本模板接入的Vlan
[AC1-wlan-vap-prof-Stu-vap]service-vlan vlan-id 50
#本模板转发模式为直接转发
[AC1-wlan-vap-prof-Stu-vap]forward-mode direct-forward
# 进入ap组
[AC1-wlan-view]ap-group name Stu
#关联VAP并设置AP发射2.4G和5G信号
[AC1-wlan-ap-group-Stu]vap-profile Stu-vap wlan 1 radio all
6.访问外网
配置坑点:
1. DHCP中继模式,AP无法获取IP地址,通过抓包有AP发起的DHCP Discover报文,并且成功被中继转发给了DHCP Server,DHCP Server就是没有回包
1.DHCP Server没有中继的回程路由,即:路由不通
2.DHCP Server 与中继互联的接口没有开启dhcp: dhcp select global
3.ip地址池中宣告的网段 与 发起DHCP请求的Client网关 不在同一个网段。或者池中没有相同的,如:ip pool中宣告的192.168.1.0,而发起DHCP请求的client的网关是192.168.2.1
2.AP获取到IP地址后,找不到AC(3层组网),无法上线
1.AP与AC管理地址不通
2.DHCP分配IP信息时,没有告诉AP AC的位置:
option 43 sub-option 2 ip-address 192.168.4.1
3.配置和网络都排查没问题时,AP仍未上线
把AP断电,或者Vlanif 1口shutdown,或者等待几分钟