AC控制器双机热备VRRP模式

组网需求

AC组网方式:旁挂二层组网。

DHCP部署方式:AC作为DHCP服务器为AP和STA分配IP地址。

业务数据转发方式:直接转发。

数据规划

配置项

数据

AC1的源接口

VLANIF100:10.23.100.1/24

AC2的源接口

VLANIF100:10.23.100.2/24

管理VRRP备份组的虚拟IP地址

10.23.100.3/24

安全模板

  • 名称:wlan-net
  • 安全策略:WPA-WPA2+PSK+AES
  • 密码:Huawei@123

DHCP服务器

AC作为DHCP服务器为AP和STA分配IP地址。

AP的网关

VLANIF100:10.23.100.3/24

AP的IP地址池

10.23.100.4~10.23.100.254/24

STA网关

VLANIF101:10.23.101.3/24

STA的IP地址池

10.23.101.4~10.23.101.254/24

AC1\AC2的主备通道IP地址和端口号

IP地址:VLANIF102,10.23.102.1/24  端口号:10241

IP地址:VLANIF102,10.23.102.2/24  端口号:10241

配置思路

  1. 配置AP、AC和其他网络设备之间实现网络互通
  2. 配置WLAN基本业务,保证用户能够通过WLAN网络接入Internet。
  3. 在AC1和AC2上配置VRRP备份组。AC1配置为主、AC2配置为备。
  4. 配置双机热备功能,保证业务同步。

配置步骤

配置Switch、AC1和AC2,使AP与AC之间能够传输CAPWAP报文

Switch:

vlan batch 100 101

interface GigabitEthernet0/0/1

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan 100 101

interface GigabitEthernet0/0/2

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan 100 101

interface GigabitEthernet0/0/3

 port link-type trunk

 port trunk pvid vlan 100

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan 100 101

AC1:

vlan batch 100 101 102

interface GigabitEthernet0/0/1

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan  102

 stp disable

interface GigabitEthernet0/0/2

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan 100 101

interface GigabitEthernet0/0/3

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan 100

dhcp enable

interface Vlanif100

ip address 10.23.100.1 24

des Management

dhcp select interface

dhcp server excluded-ip-address 10.23.100.1 10.23.100.3

interface Vlanif101

ip address 10.23.101.1 24

des YeWu

dhcp select interface

dhcp server excluded-ip-address 10.23.101.1 10.23.101.3

interface Vlanif102

des HSB

ip address 10.23.102.1 24

AC2:

vlan batch 100 101 102

interface GigabitEthernet0/0/1

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan  102

 stp disable

interface GigabitEthernet0/0/2

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan 100 101

interface GigabitEthernet0/0/3

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan 100

dhcp enable

interface Vlanif100

des Management

ip address 10.23.100.2 24

dhcp select interface

dhcp server excluded-ip-address 10.23.100.1 10.23.100.3

interface Vlanif101

ip address 10.23.101.2 24

des YeWu

dhcp select interface

dhcp server excluded-ip-address 10.23.101.1 10.23.101.3

interface Vlanif102

des HSB

ip address 10.23.102.2 24

配置VRRP方式的双机热备份

AC1:

vrrp recover-delay 30 #配置VRRP备份组的状态恢复延迟时间为30秒。

interface vlanif 100 # 管理VRRP,AC1的优先级为120,抢占时间为1800秒。

vrrp vrid 1 virtual-ip 10.23.100.3

vrrp vrid 1 priority 120

vrrp vrid 1 preempt-mode timer delay 1800

admin-vrrp vrid 1

interface vlanif 101  # 业务VRRP,抢占时间为1800秒,业务VRRP与管理VRRP绑定(减少VRRP报文数量)

vrrp vrid 2 virtual-ip 10.23.101.3

vrrp vrid 2 preempt-mode timer delay 1800

vrrp vrid 2 track admin-vrrp interface vlanif 100 vrid 1 unflowdown

hsb-service 0# 创建HSB主备服务0,并配置其主备通道IP地址和端口号,配置HSB主备服务报文的重传次数和发送间隔。

service-ip-port local-ip 10.23.102.1 peer-ip 10.23.102.2 local-data-port 10241 peer-data-port 10241

service-keep-alive detect retransmit 3 interval 6 (默认为5次,间隔3秒,可以不修改)

hsb-group 0# 创建HSB备份组0,并配置其绑定HSB主备服务0和管理VRRP备份组。

bind-service 0

track vrrp vrid 1 interface vlanif 100

hsb-service-type access-user hsb-group 0 # 配置NAC业务绑定HSB备份组。

hsb-service-type ap hsb-group 0 # 配置WLAN业务绑定HSB备份组。

hsb-service-type dhcp hsb-group 0 # 配置DHCP业务绑定HSB备份组。

hsb-group 0

hsb enable

AC2:

vrrp recover-delay 30

interface vlanif 100

vrrp vrid 1 virtual-ip 10.23.100.3

admin-vrrp vrid 1

interface vlanif 101

vrrp vrid 2 virtual-ip 10.23.101.3

vrrp vrid 2 track admin-vrrp interface vlanif 100 vrid 1 unflowdown

hsb-service 0

service-ip-port local-ip 10.23.102.2 peer-ip 10.23.102.1 local-data-port 10241 peer-data-port 10241

service-keep-alive detect retransmit 3 interval 6

hsb-group 0

bind-service 0

track vrrp vrid 1 interface vlanif 100

hsb-service-type access-user hsb-group 0

hsb-service-type ap hsb-group 0

hsb-service-type dhcp hsb-group 0

hsb-group 0

hsb enable

查看VRRP状态,AC1的State字段的显示为Master,AC2的State字段的显示为Backup。

 display vrrp

查看主备服务的建立情况。可以看到Service State字段的显示为Connected,说明主备服务通道已经成功建立。

 display hsb-service 0

查看HSB备份组的运行情况

display hsb-group 0

配置WLAN业务,AC2的配置与之类似。注意AP在主AC上状态为normal时,在AC2上的状态为standby

capwap  source  interface Vlanif  100

wlan

 security-profile name wlan-net

  security wpa-wpa2 psk pass-phrase Huawei@123 aes

 ssid-profile name wlan-net

  ssid wlan-net

 vap-profile name wlan-net

  service-vlan vlan-id 101

  ssid-profile wlan-net

  security-profile wlan-net

 ap-group name default

   vap-profile wlan-net wlan 1 radio all

  ap-id 0 type-id 35 ap-mac 00e0-fc76-e360

  ap-name AP1

配置AC和AR互联互通

AC1\AC2:

ip route-static 0.0.0.0 0.0.0.0 10.23.100.4

AR:

Vlan 100

interface Vlanif100

 ip address 10.23.100.4 255.255.255.0

interface Ethernet0/0/1

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan 100

interface Ethernet0/0/2

 port link-type trunk

 undo port trunk allow-pass vlan 1

 port trunk allow-pass vlan 100

ip route-static 10.23.101.0 24 10.23.100.3

  • 0
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值