当前位置:主页 > 查看内容

华为wlan配置直连二层组网直接转发

发布时间:2021-07-29 00:00| 位朋友查看

简介:配置直连二层组网直接转发 1. 拓扑图 2. 规划 配置项 配置 AP管理VLAN vlan100 地址10.0.100.0//24 STA业务VLAN vlan1001 地址10.0.101.0//24 DHCP服务器 AC作为DHCP服务器为AP和STA分配IP地址 AP的IP地址池 10.0.100.210.0.100.254/24 STA的IP地址池 10.0.1……

配置直连二层组网直接转发

1. 拓扑图:
在这里插入图片描述
2. 规划:

配置项配置
AP管理VLANvlan100 &地址:10.0.100.0//24
STA业务VLANvlan1001 &地址:10.0.101.0//24
DHCP服务AC作为DHCP服务器为AP和STA分配IP地址
AP的IP地址池10.0.100.2~10.0.100.254/24
STA的IP地址池10.0.101.3~10.0.101.254/24
AP组名称:f100-ap &引用模板:VAP模板、域管理模板
域管理模板名称:f100 &国家码:中国
SSID模板名称:f100-ssid &SSID名称:f100-ssid
安全模板名称:f100-security &安全策略:WPA-WPA2+PSK+AES &密码:a1234567
VAP模板名称:f100-vap &转发模式:直接转发 &业务vlan:vlan101 &引用模板:ssid模板,安全模板

3.配置思路

在这里插入图片描述

4. 配置步骤:

1.基础配置:

  • 配置接入交换机Switch的GE0/0/1和GE0/0/2接口加入VLAN100和VLAN101,GE0/0/1的缺省VLAN为VLAN100。
<HUAWEI> system-view
[HUAWEI] sysname Switch
[Switch] vlan batch 100 101
[Switch] interface gigabitethernet 0/0/1
[Switch-GigabitEthernet0/0/1] port link-type trunk
[Switch-GigabitEthernet0/0/1] port trunk pvid vlan 100
[Switch-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 101
[Switch-GigabitEthernet0/0/1] port-isolate enable
[Switch-GigabitEthernet0/0/1] quit
[Switch] interface gigabitethernet 0/0/2
[Switch-GigabitEthernet0/0/2] port link-type trunk
[Switch-GigabitEthernet0/0/2] port trunk allow-pass vlan 100 101
[Switch-GigabitEthernet0/0/2] quit

2.配置AC与Switch设备互通

  • # 配置AC的接口GE0/0/1加入VLAN100和VLAN101。
<AC6605> system-view
[AC6605] sysname AC
[AC] vlan batch 100 101
[AC] interface gigabitethernet 0/0/1
[AC-GigabitEthernet0/0/1] port link-type trunk
[AC-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 101
[AC-GigabitEthernet0/0/1] quit

3.配置DHCP服务器为STA和AP分配IP地址

  • 在AC上配置VLANIF100接口为AP提供IP地址,配置VLANIF101接口为STA提供IP地址。
[AC] dhcp enable
[AC] interface vlanif 100
[AC-Vlanif100] ip address 10.0.100.1 24
[AC-Vlanif100] dhcp select interface
[AC-Vlanif100] quit
[AC] interface vlanif 101
[AC-Vlanif101] ip address 10.0.101.1 24
[AC-Vlanif101] dhcp select interface
[AC-Vlanif101] quit

4.配置AP上线

  • 创建AP组,用于将相同配置的AP都加入同一AP组中。
[AC] wlan
[AC-wlan-view] ap-group name f100-ap
[AC-wlan-ap-group-f100-ap] quit
  • 创建域管理模板,在域管理模板下配置AC的国家码并在AP组下引用域管理模板。
[AC-wlan-view] regulatory-domain-profile name f100
[AC-wlan-regulate-domain-f100] country-code cn
[AC-wlan-regulate-domain-f100] quit
[AC-wlan-view] ap-group name f100-ap
[AC-wlan-ap-group-f100-ap] regulatory-domain-profile f100
Warning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continu
e?[Y/N]:y 
[AC-wlan-ap-group-f100-ap] quit
[AC-wlan-view] quit
  • 配置AC的源接口。
[AC] capwap source interface vlanif 100
  • 在AC上离线导入AP,并将AP加入AP组“f100-ap”中。假设AP的MAC地址为60de-4476-e360,并将此AP命名为AP1。
[AC] wlan
[AC-wlan-view] ap auth-mode mac-auth
[AC-wlan-view] ap-id 0 ap-mac 60de-4476-e360
[AC-wlan-ap-0] ap-name AP1
Warning: This operation may cause AP reset. Continue? [Y/N]:y 
[AC-wlan-ap-0] ap-group f100-ap
Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configuration
s of the radio, Whether to continue? [Y/N]:y 
[AC-wlan-ap-0] quit
  • 将AP上线后,当执行命令display ap all查看到AP的“State”字段为“nor”时,表示AP正常上线。
[AC-wlan-view] display ap all
Total AP information:
nor  : normal          [1]
Extra information:
P  : insufficient power supply
--------------------------------------------------------------------------------------------------
ID   MAC            Name   Group     IP            Type            State STA Uptime      ExtraInfo
--------------------------------------------------------------------------------------------------
0    60de-4476-e360 AP1 f100-ap 10.0.100.254 AP5030DN        nor   0   10S         -
--------------------------------------------------------------------------------------------------
Total: 1

5.配置WLAN业务参数

  • 创建名为“f100-security”的安全模板,并配置安全策略。
[AC-wlan-view] security-profile name f100-security
[AC-wlan-sec-prof-f100-security] security wpa-wpa2 psk pass-phrase a1234567 aes
[AC-wlan-sec-prof-f100-security] quit
  • 创建名为“f100-ssid”的SSID模板,并配置SSID名称为“f100-ssid”。
[AC-wlan-view] ssid-profile name f100-ssid
[AC-wlan-ssid-prof-f100-ssid] ssid f100-ssid
[AC-wlan-ssid-prof-f100-ssid] quit
  • 创建名为“f100-vap”的VAP模板,配置业务数据转发模式、业务VLAN,并且引用安全模板和SSID模板。
[AC-wlan-view] vap-profile name f100-vap
[AC-wlan-vap-prof-f100-vap] forward-mode direct-forward
[AC-wlan-vap-prof-f100-vap] service-vlan vlan-id 101
[AC-wlan-vap-prof-f100-vap] security-profile f100-security
[AC-wlan-vap-prof-f100-vap] ssid-profile f100-ssid
[AC-wlan-vap-prof-f100-vap] quit
  • 配置AP组引用VAP模板,AP上射频0和射频1都使用VAP模板“f100-vap”的配置。
[AC-wlan-view] ap-group name f100-ap
[AC-wlan-ap-group-f100-ap] vap-profile f100-vap wlan 1 radio 0
[AC-wlan-ap-group-f100-ap] vap-profile f100-vap wlan 1 radio 1
[AC-wlan-ap-group-f100-ap] quit
;原文链接:https://blog.csdn.net/m0_46556100/article/details/115787730
本站部分内容转载于网络,版权归原作者所有,转载之目的在于传播更多优秀技术内容,如有侵权请联系QQ/微信:153890879删除,谢谢!
上一篇:关于在Windows上安装Linux系统的一点看法 下一篇:没有了

推荐图文


随机推荐