本案例利用华为eNSP模拟器,实现了AP通过SN认证,在AC上上线。
一、拓扑结构
二、网络规划
1、AC1和APs使用三层组网,APs在VLAN50,AC1在VLAN100
2、AC1做DHCP服务器,为AP1、AP2和工作站分配IP
3、LSW1做DHCP中继代理,为APs和STAs向AC1申请IP
4、管理VLAN 50和100,业务VLAN 10、20和VLAN30,上行VLAN 200
5、AP认证方式:SN认证(AP1离线添加,AP2加入白名单,AP3手工确认)
6、IP地址规划 (1)AC1 vlanif 10:192.168.10.253/24
(2)AC1 vlanif 20:192.168.20.253/24
(3)AC1 vlanif 30:192.168.20.253/24
(4)AC1 vlanif100:192.168.100.253/24
(5)LSW1 vlanif 10: 192.168.10.254/24
(6)LSW1 vlanif 20: 192.168.20.254/24
(7)LSW1 vlanif 30: 192.168.30.254/24
(8)LSW1 vlanif 50: 192.168.50.254/24
(9)LSW1 vlanif100: 192.168.100.254/24
(10)LSW1 vlanif200: 192.168.200.254/24
(11)AR1 G0/0/0: 192.168.200.253/24
(12)APs、STAs都自动获取
三、配置步骤
实验之前:将所有AP关机
3.1 配置AR1
1、设备名、接口地址
配置设备名称为AR
<Huawei>system-view
[Huawei]sysname AR
配置下联端口G0/0/0的IP地址
[AR]interface GigabitEthernet 0/0/0
[AR-GigabitEthernet0/0/0]ip address 192.168.200.253 24
[AR-GigabitEthernet0/0/0]quit
2、到业务VLAN的路由
配置到业务Vlan的静态路由
[AR]ip route-static 192.168.10.0 255.255.255.0 192.168.200.254
[AR]ip route-static 192.168.20.0 255.255.255.0 192.168.200.254
[AR]ip route-static 192.168.30.0 255.255.255.0 192.168.200.254
[AR]quit
<AR>save
3.2 配置LSW1
1、设备名、VLAN、VLAN接口地址
创建Vlan
<Huawei>system-view
[Huawei]sysname SW
[SW]vlan batch 10 20 30 50 100 200
配置Vlanif10的IP地址
[SW]interface Vlanif 10
[SW-Vlanif10]ip address 192.168.10.254 24
[SW-Vlanif10]quit
配置Vlanif20的IP地址
[SW]interface Vlanif 20
[SW-Vlanif20]ip address 192.168.20.254 24
[SW-Vlanif20]quit
配置Vlanif30的IP地址
[SW]interface Vlanif 30
[SW-Vlanif30]ip address 192.168.30.254 24
[SW-Vlanif30]quit
配置Vlanif50的IP地址
[SW]interface Vlanif 50
[SW-Vlanif50]ip address 192.168.50.254 24
[SW-Vlanif50]quit
配置Vlanif100的IP地址
[SW]interface Vlanif 100
[SW-Vlanif100]ip address 192.168.100.254 24
[SW-Vlanif100]quit
配置Vlanif200的IP地址
[SW]interface Vlanif 200
[SW-Vlanif200]ip address 192.168.200.254 24
[SW-Vlanif200]quit
2、端口划分(注意隧道转发方式)
配置G0/0/1端口
[SW]interface GigabitEthernet 0/0/1
[SW-GigabitEthernet0/0/1]port link-type trunk
[SW-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20 30 50 100
[SW-GigabitEthernet0/0/1]quit
配置G0/0/2端口
[SW]interface GigabitEthernet 0/0/2
[SW-GigabitEthernet0/0/2]port link-type trunk
[SW-GigabitEthernet0/0/2]port trunk pvid vlan 50
[SW-GigabitEthernet0/0/2]port trunk allow-pass vlan 50
[SW-GigabitEthernet0/0/2]quit
配置G0/0/3端口
[SW]interface GigabitEthernet 0/0/3
[SW-GigabitEthernet0/0/3]port link-type trunk
[SW-GigabitEthernet0/0/3]port trunk pvid vlan 50
[SW-GigabitEthernet0/0/3]port trunk allow-pass vlan 50
[SW-GigabitEthernet0/0/3]quit
配置G0/0/4端口
[SW]interface GigabitEthernet 0/0/4
[SW-GigabitEthernet0/0/4]port link-type trunk
[SW-GigabitEthernet0/0/4]port trunk pvid vlan 50
[SW-GigabitEthernet0/0/4]port trunk allow-pass vlan 50
[SW-GigabitEthernet0/0/4]quit
配置G0/0/5端口
[SW]interface GigabitEthernet 0/0/5
[SW-GigabitEthernet0/0/5]port link-type access
[SW-GigabitEthernet0/0/5]port default vlan 200
[SW-GigabitEthernet0/0/5]quit
3、配置DHCP中继代理
在Vlanif10接口上启用中继
[SW]interface Vlanif 10
[SW-Vlanif10]dhcp select relay
[SW-Vlanif10]dhcp relay server-ip 192.168.100.253
[SW-Vlanif10]quit
在Vlanif20接口上启用中继
[SW]interface Vlanif 20
[SW-Vlanif20]dhcp select relay
[SW-Vlanif20]dhcp relay server-ip 192.168.100.253
[SW-Vlanif20]quit
在Vlanif30接口上启用中继
[SW]interface Vlanif 30
[SW-Vlanif30]dhcp select relay
[SW-Vlanif30]dhcp relay server-ip 192.168.100.253
[SW-Vlanif30]quit
在Vlanif50接口上启用中继
[SW]interface Vlanif 50
[SW-Vlanif50]dhcp select relay
[SW-Vlanif50]dhcp relay server-ip 192.168.100.253
[SW-Vlanif50]quit
保存配置
[SW]quit
<SW>save
3.3 配置AC1
1、设备名、VLAN
创建Vlan
<AC6605>system-view
[AC6605]sysname AC
[AC]vlan batch 10 20 30 100
2、端口划分
配置G0/0/1端口
[AC]interface GigabitEthernet 0/0/1
[AC-GigabitEthernet0/0/1]port link-type trunk
[AC-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20 30 100
[AC-GigabitEthernet0/0/1]quit
3、DHCP配置
(1)管理vlan地址池(包括option43)
[AC]dhcp enable
[AC]ip pool AP-pool
[AC-ip-pool-AP-pool]network 192.168.50.0 mask 24
[AC-ip-pool-AP-pool]option 43 sub-option 2 ip-address 192.168.100.253
[AC-ip-pool-AP-pool]quit
(2)业务vlan地址池
创建业务Vlan10的地址池
[AC]ip pool vlan10-pool
[AC-ip-pool-vlan10-pool]network 192.168.10.0 mask 24
[AC-ip-pool-vlan10-pool]gateway-list 192.168.10.254
[AC-ip-pool-vlan10-pool]quit
创建业务Vlan20的地址池
[AC]ip pool vlan20-pool
[AC-ip-pool-vlan20-pool]network 192.168.20.0 mask 24
[AC-ip-pool-vlan20-pool]gateway-list 192.168.20.254
[AC-ip-pool-vlan20-pool]quit
创建业务Vlan30的地址池
[AC]ip pool vlan30-pool
[AC-ip-pool-vlan30-pool]network 192.168.30.0 mask 24
[AC-ip-pool-vlan30-pool]gateway-list 192.168.30.254
[AC-ip-pool-vlan30-pool]quit
(3)接口启用DHCP
在Vlanif100接口上启用全局地址池
[AC]interface Vlanif 100
[AC-Vlanif100]ip address 192.168.100.253 24
[AC-Vlanif100]dhcp select global
[AC-Vlanif100]quit
4、配置默认路由
[AC]ip route-static 0.0.0.0 0.0.0.0 192.168.100.254
5、配置AP上线
(1)创建AP组
[AC]wlan
[AC-wlan-view]ap-group name lab09-AG
[AC-wlan-ap-group-lab09-AG]quit
(2)国家码
创建域模板、配置国家码
[AC-wlan-view]regulatory-domain-profile name lab09-domain
[AC-wlan-regulate-domain-lab09-domain]country-code cn
[AC-wlan-regulate-domain-lab09-domain]quit
将域模板绑定在AP组上
[AC-wlan-view]ap-group name lab09-AG
[AC-wlan-ap-group-lab09-AG]regulatory-domain-profile lab09-domain
[AC-wlan-ap-group-lab09-AG]quit
(3)源接口
[AC]capwap source ip-address 192.168.100.253
(4)AP认证方式
[AC]wlan
[AC-wlan-view]ap auth-mode sn-auth
6、离线添加AP1
[AC-wlan-view]ap-id 0 ap-sn 210235448310927D5617
[AC-wlan-ap-0]ap-name ap@vlan10
[AC-wlan-ap-0]ap-group lab09-AG
[AC-wlan-ap-0]quit
此时,将AP1开机,并等待一段时间后,查看AP1是否获取到IP地址,是否上线?
7、白名单列表加入AP2
[AC-wlan-view]ap whitelist sn 210235448310FB3FA239
此时,将AP2开机,并等待一段时间后,查看AP2是否获取到IP地址,是否上线?
离线添加AP2
[AC-wlan-view]ap-id 1
[AC-wlan-ap-1]ap-name ap@wlan10
[AC-wlan-ap-1]ap-group lab09-AG
[AC-wlan-ap-1]quit
8、手工添加AP3
此时,将AP3开机,并等待一段时间后,查看AP3是否获取到IP地址?
继续等待一段时间后,查看AP3是否在未被确认列表内?若在,进行手工确认!
AC-wlan-view]display ap unauthorized record
[AC-wlan-view]ap-confirm sn 21023544831015737779
再等待一段时间后,查看AP3是否上线?
离线添加AP3
[AC-wlan-view]ap-id 2
[AC-wlan-ap-2]ap-name ap@vlan30
[AC-wlan-ap-2]ap-group lab09-AG
[AC-wlan-ap-2]quit
[AC-wlan-view]quit
[AC]quit
<AC>save
四、检查测试
1、AC1上查看AP组display ap-group all
2、AC1上使用display ap all命令查看AP的状态是否为nor