WLAN开局配置

配置实验:

1.需求

  1. AP1通过DHCP Server获取IP地址;AP2通过LSW1基于接口Vlanif 20获取IP地址

  2. AP1、AP2获取地址后与AC建立三层连接,AC上完成上线配置和业务配置,并下发给AP

  3. STA1连接WIFI信号,自动获取IP地址,可直接访问外网10.10.10.10

2.基础配置

2.1 LSW2配置

 vlan batch 10 20 50
#
interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk pvid vlan 10
 port trunk allow-pass vlan 10 50
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk pvid vlan 20
 port trunk allow-pass vlan 20 50
#
interface GigabitEthernet0/0/3
 port link-type trunk
 port trunk allow-pass vlan 10 20 50

2.2 LSW1配置

#
vlan batch 10 20 30 40 50 60
#
dhcp enable
#
interface Vlanif10
 ip address 192.168.1.1 255.255.255.0
 dhcp select relay
 dhcp relay server-ip 192.168.3.1
#
interface Vlanif20
 ip address 192.168.2.1 255.255.255.0
 dhcp select interface

# 告诉AP  AC的位置(3层组网)
 dhcp server option 43 sub-option 2 ip-address 192.168.4.1
#
interface Vlanif30
 ip address 192.168.3.2 255.255.255.0
#
interface Vlanif40
 ip address 192.168.4.2 255.255.255.0
#
interface Vlanif50
 ip address 192.168.5.1 255.255.255.0
 dhcp select interface
#
interface Vlanif60
 ip address 192.168.6.1 255.255.255.0
#
interface GigabitEthernet0/0/1
 port link-type access
 port default vlan 30
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 40
#
interface GigabitEthernet0/0/3
 port link-type trunk
 port trunk allow-pass vlan 10 20 50
#
interface GigabitEthernet0/0/4
 port link-type access
 port default vlan 60
#
ip route-static 10.10.10.0 24 192.168.6.2

2.3 AR2配置

#
interface GigabitEthernet0/0/0
 ip address 192.168.6.2 255.255.255.0 
#
interface LoopBack0
 ip address 10.10.10.10 255.255.255.0 
#
ip route-static 0.0.0.0 0.0.0.0 192.168.6.1

2.4 AR1配置

 #
dhcp enable
#
ip pool AP1-pool
 network 192.168.1.0 mask 255.255.255.0 

# 告诉AP  AC的位置(3层组网)
 option 43 sub-option 2 ip-address 192.168.4.1  
#
interface GigabitEthernet0/0/1
 ip address 192.168.3.1 255.255.255.0 
 dhcp select global
#
ip route-static 0.0.0.0 0.0.0.0 192.168.3.2

3. AC1基础配置

 [AC1]vlan 40
[AC1]interface Vlanif 40    
[AC1-Vlanif40]ip address 192.168.4.1 24
#
[AC1]interface GigabitEthernet 0/0/2
[AC1-GigabitEthernet0/0/2]port link-type trunk 
[AC1-GigabitEthernet0/0/2]port trunk allow-pass vlan 40
#
[AC1]ip route-static 0.0.0.0 0 192.168.4.2

4. AC1进行AP上线配置

#
[AC1]capwap source interface Vlanif 40
[AC1]wlan 
# 设置AP的射频国家配置模板
[AC1-wlan-view]regulatory-domain-profile name default
[AC1-wlan-regulate-domain-default]country-code cn
# 创建AP组并应用国家射频模板
[AC1-wlan-view]ap-group name Stu
[AC1-wlan-ap-group-Stu]regulatory-domain-profile default
# ap通过mac认证
[AC1-wlan-view]ap auth-mode mac-auth 
# 绑定ap的mac和id
[AC1-wlan-view]ap-id 1 ap-mac 00e0-fc01-6260
# 重命名ap
[AC1-wlan-ap-1]ap-name ap1
# 当前ap加入Stu的ap组
[AC1-wlan-ap-1]ap-group Stu
#
[AC1-wlan-view]ap-id 2 ap-mac 00e0-fcf8-38d0
[AC1-wlan-ap-2]ap-name ap2
[AC1-wlan-ap-2]ap-group Stu

5. AC1进行AP业务配置

# 配置安全模板
[AC1-wlan-view]security-profile name Stu-Sec
[AC1-wlan-sec-prof-Stu-Sec]security wpa2 psk pass-phrase huawei@123 aes
# 配置SSID模板
[AC1-wlan-view]ssid-profile name Stu-ssid
[AC1-wlan-ssid-prof-Stu-ssid]ssid Student
# 配置VAP模板
[AC1-wlan-view]vap-profile name Stu-vap
    #关联安全模板
[AC1-wlan-vap-prof-Stu-vap]security-profile Stu-sec
    #关联ssid模板
[AC1-wlan-vap-prof-Stu-vap]ssid-profile Stu-ssid
    #本模板接入的Vlan
[AC1-wlan-vap-prof-Stu-vap]service-vlan vlan-id 50
    #本模板转发模式为直接转发
[AC1-wlan-vap-prof-Stu-vap]forward-mode direct-forward 
# 进入ap组
[AC1-wlan-view]ap-group name Stu
    #关联VAP并设置AP发射2.4G和5G信号
[AC1-wlan-ap-group-Stu]vap-profile Stu-vap wlan 1 radio all

6.访问外网

配置坑点:

1. DHCP中继模式,AP无法获取IP地址,通过抓包有AP发起的DHCP Discover报文,并且成功被中继转发给了DHCP Server,DHCP Server就是没有回包

1.DHCP Server没有中继的回程路由,即:路由不通

2.DHCP Server 与中继互联的接口没有开启dhcp: dhcp select global

3.ip地址池中宣告的网段 与 发起DHCP请求的Client网关 不在同一个网段。或者池中没有相同的,如:ip pool中宣告的192.168.1.0,而发起DHCP请求的client的网关是192.168.2.1

2.AP获取到IP地址后,找不到AC(3层组网),无法上线

1.AP与AC管理地址不通

2.DHCP分配IP信息时,没有告诉AP AC的位置:

        option 43 sub-option 2 ip-address 192.168.4.1 

3.配置和网络都排查没问题时,AP仍未上线

        把AP断电,或者Vlanif 1口shutdown,或者等待几分钟

         

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值