工作流程
创建两个VLAN,一个控制VLAN(AC管理AP),一个业务VLAN(终端传输数据),避免控制数据和业务数据在同一链路上传输,使控制数据受到干扰。
1.AP上线
AP获取ip阶段
配置dhcp
[AC6005]vlan batch 100 101
[AC6005]int g0/0/1
[AC6005-GigabitEthernet0/0/1]port link-type trunk
[AC6005-GigabitEthernet0/0/1]port trunk allow-pass vlan 100 101
[AC6005]int vlanif101
[AC6005-Vlanif101]ip addr 192.168.101.1 24
[AC6005-Vlanif101]q
[AC6005]dhcp enable
[AC6005]int vlanif101
[AC6005-Vlanif101]dhcp select global
这时可以看到AP中已自动获取到地址
隧道建立阶段
此外,AP还在查找AC(发送CAPWAP)报文。
AC标明想要通过接口vlanif101和AP建立隧道(还没建完,需要配置模板)
[AC6005]capwap source interface vlanif101
ap接入控制阶段
[AC6005]wlan
#创建国家配置模板
[AC6005-wlan-view]regulatory-domain-profile name xiaobai
[AC6005-wlan-regulate-domain-xiaobai]country-code cn
[AC6005-wlan-regulate-domain-xiaobai]q
#创建ap组
[AC6005-wlan-view]ap-group name xiaobai
#将模板加入ap组中
[AC6005-wlan-ap-group-xiaobai]regulatory-domain-profile xiaobai
Warning: Modifying the country code will clear channel, power and antenna gain c
onfigurations of the radio and reset the AP. Continue?[Y/N]:y
#配置ap认证
[AC6005-wlan-view]ap auth-mode mac-auth
[AC6005-wlan-view]ap-id 0 ap-mac 00e0-fcfb-5db0
[AC6005-wlan-view]ap-name xiaobai111
[AC6005-wlan-view]ap-group name xiaobai
完成ap认证之后成功建立隧道
这时可以在AP端看到
在AC中查看AP状态为normal
至此已完成AP上线。
2.WALN业务配置下发
接下来要给ac配置必备模板,其中vap模板中还嵌套ssid模板(wifi名字)和安全模板(wifi密码)
配置业务wlan
#配置安全模板(wifi密码
[AC6005-wlan-view]security-profile name xiaobai
#配置链路认证(采用wpa加密预共享密钥,适用于个人家庭) 采用aes对密码进行加密
[AC6005-wlan-sec-prof-xiaobai]security wpa-wpa2 psk pass-phrase xiaobai123 aes-t
kip
#配置ssid模板(wifi账号
[AC6005-wlan-view]ssid-profile name xiaobai
[AC6005-wlan-ssid-prof-xiaobai]ssid xiaobaiwifi
[AC6005-wlan-ssid-prof-xiaobai]q
#创建vap模板
[AC6005-wlan-view]vap-profile name xiaobai
#将安全模板导入vap模板
[AC6005-wlan-vap-prof-xiaobai]security-profile xiaobai
#将ssid模板导入vap模板
[AC6005-wlan-vap-prof-xiaobai]ssid-profile xiaobai
#配置转发方式
[AC6005-wlan-vap-prof-xiaobai]forward-mode direct-forward
#配置业务VLAN
[AC6005-wlan-vap-prof-xiaobai]service-vlan vlan-id 100
#将vap模板导入ap组中并且设置射频 其中radio代表2.4G,1代表5G
[AC6005-wlan-view]ap-group name xiaobai
[AC6005-wlan-ap-group-xiaobai]vap-profile xiaobai wlan 1 radio 0
[AC6005-wlan-ap-group-xiaobai]vap-profile xiaobai wlan 1 radio 1
配置完成后
连接wifi(发现获取不到地址,是因为还没给终端配地址池
[AC6005]ip pool vlan100
[AC6005-ip-pool-vlan100]network 192.168.100.0 mask 24
[AC6005-ip-pool-vlan100]gateway-list 192.168.100.1
[AC6005-ip-pool-vlan100]q
[AC6005]int vlanif100
[AC6005-Vlanif100]ip addr 192.168.100.1 24
[AC6005-Vlanif100]dhcp select global
补充: