(1)胖AP配置
#和三层交换机互联地址
interface Vlan-interface1
ip address 192.168.0.50 255.255.255.0
#缺省路由,下一跳指向三层交换机
ip route-static 0.0.0.0 0.0.0.0 192.168.0.1
#
vlan 10
#无线终端业务网关
interface Vlan-interface10
ip address 192.168.10.1 255.255.255.0
#无线终端dhcp地址池,分配192.168.10.0/24网段、网关地址和dns
dhcp server ip-pool vlan10
network 192.168.10.0 mask 255.255.255.0
gateway-list 192.168.10.1
dns-list 114.114.114.114
#dhcp禁止分配网关地址
dhcp server forbidden-ip 192.168.10.1
#使能dhcp
dhcp enable
#使能端口安全
port-security enable
#802.1x认证方式为eap
dot1x authentication-method eap
#配置radius方案,指定认证(授权)、计费服务器地址和密钥
radius scheme yanghaiyan
server-type extended
primary authentication 10.88.142.172
primary accounting 10.88.142.172
key authentication simple 123456
key accounting simple 123456
user-name-format without-domain
nas-ip 192.168.0.50
#配置域,调用radius方案
domain yanghaiyan
authentication lan-access radius-scheme yanghaiyan
authorization lan-access radius-scheme yanghaiyan
accounting lan-access radius-scheme yanghaiyan
#配置无线BSS接口为hybrid口ÿ