需求
1.
1) 公司内部有无线用户可以实现上网
2) 无线组网方式AC为二层旁挂组网,直接转发
3) 无线VLAN规划,VLAN101,为业务VLAN,网段10.23.101.0/24
VLAN100,为管理VLAN,用于管理ap
4)DHCP Server: - AC作为AP的DHCP服务器
- SW1作为业务网段的DHCP服务器
5)无线终端可以自动获取IP地址,访问AR1
拓扑
配置步骤
1) SW2配置交换机二层接口,vlan,trunk,access
2) SW1配置业务网关,配置DHCP服务器,配置与AR1互联接口
3) 配置AC
- 配置建立CAPWAP隧道的地址,创建vlan
- 配置ap上线
- 配置业务模板,绑定ap组
配置命令
SW2配置
sysname SW2
#
vlan batch 100 to 101
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100 to 101
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100 to 101
SW1配置:
sysname sw1
#
dhcp enable
#
vlan batch 100 to 101 200
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 200
#
interface Vlanif101
ip address 10.23.101.254 255.255.255.0
dhcp select interface
#
interface Vlanif200
ip address 10.1.13.1 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.1.13.254 (本拓扑可以不需要缺省路由,如果要访问互联网的话,需要配置缺省路由)
AR1配置:
sysname ar1
#
interface GigabitEthernet0/0/0
ip address 10.1.13.254 255.255.255.0
#
ip route-static 10.23.101.0 255.255.255.0 10.1.13.1
AC配置:
vlan batch 100 to 101
#
interface Vlanif100
ip address 10.23.100.254 255.255.255.0
dhcp select interface
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
capwap source interface vlanif100
#
wlan
security-profile name neibu
security wpa-wpa2 psk pass-phrase Huawei12#$ aes
ssid-profile name neibu
ssid neibu
vap-profile name neibu
service-vlan vlan-id 101
ssid-profile neibu
security-profile neibu
ap-id 1 ap-mac 00e0-fcd7-1870
radio 0
vap-profile neibu wlan 1
radio 1
vap-profile neibu wlan 1
ap-id 2 ap-mac 00e0-fcbe-7c80
radio 0
vap-profile neibu wlan 1
radio 1
vap-profile neibu wlan 1
验证测试