组网需求
AC组网方式:旁挂二层组网。
DHCP部署方式:AC作为DHCP服务器为AP和STA分配IP地址。
业务数据转发方式:直接转发。
数据规划
配置项 | 数据 |
AC1的源接口 | VLANIF100:10.23.100.1/24 |
AC2的源接口 | VLANIF100:10.23.100.2/24 |
管理VRRP备份组的虚拟IP地址 | 10.23.100.3/24 |
安全模板 |
|
DHCP服务器 | AC作为DHCP服务器为AP和STA分配IP地址。 |
AP的网关 | VLANIF100:10.23.100.3/24 |
AP的IP地址池 | 10.23.100.4~10.23.100.254/24 |
STA网关 | VLANIF101:10.23.101.3/24 |
STA的IP地址池 | 10.23.101.4~10.23.101.254/24 |
AC1\AC2的主备通道IP地址和端口号 | IP地址:VLANIF102,10.23.102.1/24 端口号:10241 IP地址:VLANIF102,10.23.102.2/24 端口号:10241 |
配置思路
- 配置AP、AC和其他网络设备之间实现网络互通
- 配置WLAN基本业务,保证用户能够通过WLAN网络接入Internet。
- 在AC1和AC2上配置VRRP备份组。AC1配置为主、AC2配置为备。
- 配置双机热备功能,保证业务同步。
配置步骤
配置Switch、AC1和AC2,使AP与AC之间能够传输CAPWAP报文
Switch:
vlan batch 100 101
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100 101
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100 101
interface GigabitEthernet0/0/3
port link-type trunk
port trunk pvid vlan 100
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100 101
AC1:
vlan batch 100 101 102
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 102
stp disable
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100 101
interface GigabitEthernet0/0/3
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100
dhcp enable
interface Vlanif100
ip address 10.23.100.1 24
des Management
dhcp select interface
dhcp server excluded-ip-address 10.23.100.1 10.23.100.3
interface Vlanif101
ip address 10.23.101.1 24
des YeWu
dhcp select interface
dhcp server excluded-ip-address 10.23.101.1 10.23.101.3
interface Vlanif102
des HSB
ip address 10.23.102.1 24
AC2:
vlan batch 100 101 102
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 102
stp disable
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100 101
interface GigabitEthernet0/0/3
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100
dhcp enable
interface Vlanif100
des Management
ip address 10.23.100.2 24
dhcp select interface
dhcp server excluded-ip-address 10.23.100.1 10.23.100.3
interface Vlanif101
ip address 10.23.101.2 24
des YeWu
dhcp select interface
dhcp server excluded-ip-address 10.23.101.1 10.23.101.3
interface Vlanif102
des HSB
ip address 10.23.102.2 24
配置VRRP方式的双机热备份
AC1:
vrrp recover-delay 30 #配置VRRP备份组的状态恢复延迟时间为30秒。
interface vlanif 100 # 管理VRRP,AC1的优先级为120,抢占时间为1800秒。
vrrp vrid 1 virtual-ip 10.23.100.3
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 1800
admin-vrrp vrid 1
interface vlanif 101 # 业务VRRP,抢占时间为1800秒,业务VRRP与管理VRRP绑定(减少VRRP报文数量)
vrrp vrid 2 virtual-ip 10.23.101.3
vrrp vrid 2 preempt-mode timer delay 1800
vrrp vrid 2 track admin-vrrp interface vlanif 100 vrid 1 unflowdown
hsb-service 0# 创建HSB主备服务0,并配置其主备通道IP地址和端口号,配置HSB主备服务报文的重传次数和发送间隔。
service-ip-port local-ip 10.23.102.1 peer-ip 10.23.102.2 local-data-port 10241 peer-data-port 10241
service-keep-alive detect retransmit 3 interval 6 (默认为5次,间隔3秒,可以不修改)
hsb-group 0# 创建HSB备份组0,并配置其绑定HSB主备服务0和管理VRRP备份组。
bind-service 0
track vrrp vrid 1 interface vlanif 100
hsb-service-type access-user hsb-group 0 # 配置NAC业务绑定HSB备份组。
hsb-service-type ap hsb-group 0 # 配置WLAN业务绑定HSB备份组。
hsb-service-type dhcp hsb-group 0 # 配置DHCP业务绑定HSB备份组。
hsb-group 0
hsb enable
AC2:
vrrp recover-delay 30
interface vlanif 100
vrrp vrid 1 virtual-ip 10.23.100.3
admin-vrrp vrid 1
interface vlanif 101
vrrp vrid 2 virtual-ip 10.23.101.3
vrrp vrid 2 track admin-vrrp interface vlanif 100 vrid 1 unflowdown
hsb-service 0
service-ip-port local-ip 10.23.102.2 peer-ip 10.23.102.1 local-data-port 10241 peer-data-port 10241
service-keep-alive detect retransmit 3 interval 6
hsb-group 0
bind-service 0
track vrrp vrid 1 interface vlanif 100
hsb-service-type access-user hsb-group 0
hsb-service-type ap hsb-group 0
hsb-service-type dhcp hsb-group 0
hsb-group 0
hsb enable
查看VRRP状态,AC1的State字段的显示为Master,AC2的State字段的显示为Backup。
display vrrp
查看主备服务的建立情况。可以看到Service State字段的显示为Connected,说明主备服务通道已经成功建立。
display hsb-service 0
查看HSB备份组的运行情况
display hsb-group 0
配置WLAN业务,AC2的配置与之类似。注意AP在主AC上状态为normal时,在AC2上的状态为standby
capwap source interface Vlanif 100
wlan
security-profile name wlan-net
security wpa-wpa2 psk pass-phrase Huawei@123 aes
ssid-profile name wlan-net
ssid wlan-net
vap-profile name wlan-net
service-vlan vlan-id 101
ssid-profile wlan-net
security-profile wlan-net
ap-group name default
vap-profile wlan-net wlan 1 radio all
ap-id 0 type-id 35 ap-mac 00e0-fc76-e360
ap-name AP1
配置AC和AR互联互通
AC1\AC2:
ip route-static 0.0.0.0 0.0.0.0 10.23.100.4
AR:
Vlan 100
interface Vlanif100
ip address 10.23.100.4 255.255.255.0
interface Ethernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100
interface Ethernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 100
ip route-static 10.23.101.0 24 10.23.100.3