目录
OSPF的部署,在AC、三层交换机、R1上配置OSPF,使得全网互通。
实验拓扑
实验步骤:
1.VLAN部署:在交换机以及AC上配置VLAN、Trunk。
2.IP地址部署: AC、R1上配置IP地址。
3.VLAN间路由部署:在AC、三层交换机、R1上配置OSPF,使得全网互通。
4.DHCP服务部署:在AC上部署DHCP服务,为AP和无线终端提供IP地址;在S1上配置DHCP代理。
5.创建AP组:用于将相同配置的AP都加入同一AP组中。
6.AP上线:配置AP认证方式,把AP加入组,AP上电,确认AP找到AC
7.配置WLAN业务参数:配置安全模板、SSID模板、VAP模板
8.配置AP射频的信道和功率:配置2.4G和5G视频信道和功率优化
vlan部署
S1:
vlan batch 10 100 to 102
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 101 to 102
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 100 to 102
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 101 to 102
S2:
vlan batch 10 101 to 102
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 101 to 102
interface GigabitEthernet0/0/2
port link-type trunk
port trunk pvid vlan 10
port trunk allow-pass vlan 10 101 to 102
interface GigabitEthernet0/0/3
port link-type trunk
port trunk pvid vlan 10
port trunk allow-pass vlan 10 101 to 102
AC:
vlan batch 100 to 102
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 100 to 102
检查vlan配置
S1:
S2:
AC:
IP地址的部署
R1:
interface GigabitEthernet0/0/0.101
dot1q termination vid 101
ip address 10.23.101.2 255.255.255.0
arp broadcast enable
interface GigabitEthernet0/0/0.102
dot1q termination vid 102
ip address 10.23.102.2 255.255.255.0
arp broadcast enable
interface LoopBack0
ip address 10.10.10.10 255.255.255.0
S1:
interface Vlanif10
ip address 10.23.10.1 255.255.255.0
interface Vlanif100
ip address 10.23.100.1 255.255.255.0
interface Vlanif101
ip address 10.23.101.1 255.255.255.0
interface Vlanif102
ip address 10.23.102.1 255.255.255.0
AC:
interface Vlanif100
ip address 10.23.100.2 255.255.255.0
检查IP地址的配置
R1:
S1:
AC:
OSPF的部署,在AC、三层交换机、R1上配置OSPF,使得全网互通。
R1:
S1:
AC:
DHCP的配置
在AC上创建3个全局地址池。地址池pool huawei为AP提供地址,这个地址池要设置option 43为AP指明AC的IP地址。地址池pool vlan101为VLAN 101的STA提供地址,地址池pool vlan102为VLAN 102的STA提供地址。
AC:
dhcp enable
ip pool ap
gateway-list 10.23.10.1
network 10.23.10.0 mask 255.255.255.0
option 43 sub-option 3 ascii 10.23.100.2
ip pool vlan101
gateway-list 10.23.101.1
network 10.23.101.0 mask 255.255.255.0
dns-list 10.10.10.10
ip pool vlan102
gateway-list 10.23.102.1
network 10.23.102.0 mask 255.255.255.0
dns-list 10.10.10.10
S1:
dhcp enable
interface Vlanif10
dhcp select relay
dhcp relay server-ip 10.23.100.2
interface Vlanif101
dhcp select relay
dhcp relay server-ip 10.23.100.2
interface Vlanif102
dhcp select relay
dhcp relay server-ip 10.23.100.2
接口应用:
AC:
interface Vlanif100
ip address 10.23.100.2 255.255.255.0
dhcp select global
检查DHCP配置
检查DHCP配置在两个ap上进行测试,查看是都获取到ip地址
AC的配置
[AC]capwap source interface Vlanif 100 //不要忘记
[AC-wlan-view]ssid-profile name ap1 //ap信号的名字
[AC-wlan-ssid-prof-ap1]ssid ap1
[AC-wlan-view]ssid-profile name ap2
[AC-wlan-ssid-prof-ap2]ssid ap2
[AC-wlan-view]security-profile name ap1 // ap信号的密码
[AC-wlan-sec-prof-ap1]security open
[AC-wlan-view]security-profile name ap2
[AC-wlan-sec-prof-ap2]security wpa-wpa2 psk pass-phrase 12345678 aes
[AC-wlan-view]vap-profile name ap1 //ap信号的vap设置
[AC-wlan-vap-prof-ap1]service-vlan vlan-id 101 //关联的业务vlan
[AC-wlan-vap-prof-ap1]ssid-profile ap1 //关联的ssid名称
[AC-wlan-vap-prof-ap1]security-profile ap1 //关联的security
[AC-wlan-view]vap-profile name ap2
[AC-wlan-vap-prof-ap2]service-vlan vlan-id 102
[AC-wlan-vap-prof-ap2] ssid-profile ap2
[AC-wlan-vap-prof-ap2] security-profile ap2
[AC-wlan-view]ap-group name ap //ap组
[AC-wlan-ap-group-ap]vap-profile ap1 wlan 1 radio 0
[AC-wlan-ap-group-ap]vap-profile ap1 wlan 1 radio 1
[AC-wlan-ap-group-ap]vap-profile ap2 wlan 2 radio 0
[AC-wlan-ap-group-ap]vap-profile ap2 wlan 2 radio 1
[AC-wlan-view]ap-id 0 ap-mac 00e0-fcc3-1670 //mac地址,可在ap上进行dis arp查看
[AC-wlan-ap-0]ap-name a //上线ap的名称
[AC-wlan-ap-0]ap-group ap //上线ap所属组
[AC-wlan-view]ap-id 1 ap-mac 00e0-fc8c-5670
[AC-wlan-ap-1]ap-name b
[AC-wlan-ap-1]ap-group ap
创建AP组,用于将相同配置的AP都加入同一AP组中,ap1发射的信号是vlan101的,ap2发射的信号是vlan102的,