1、五、 配置思路1.配置AP、AC和周边网络设备之间实现网络互通。2.配置AP上线。a) 创建AP组,用于将需要进行相同配置的AP都加入到AP组,实现统一配置。b) 配置AC的系统参数,包括国家码、AC与AP之间通信的源接口。c) 配置AP上线的认证方式并离线导入AP,实现AP正常上线。3.配置WLAN业务参数,实现STA访问WLAN网络功能。六、 实验过程:1. 二层交换机配置 system-viewHUAWEI sysname SwitchSwitch vlan batch 100 101Switch interface Ethernet0/0/1Switch-Ethernet0/0/1 p
2、ort link-type trunkSwitch-Ethernet0/0/1 port trunk pvid vlan 100Switch-Ethernet0/0/1 port trunk allow-pass vlan 100 101Switch-Ethernet0/0/1 port-isolate enableSwitch-Ethernet0/0/1 quitSwitch interface gigabitethernet 0/0/2Switch-Ethernet0/0/2 port link-type trunkSwitch-Ethernet0/0/2 port trunk allow
3、-pass vlan 100 101Switch-Ethernet0/0/2 quit2. 三层交换机配置HuaweiHuawei sysname RouterRouter vlan batch 101Router interface gigabitethernet 0/0/1Router-GigabitEthernet0/0/1 port link-type trunkRouter-GigabitEthernet0/0/1 port trunk allow-pass vlan 101Router-GigabitEthernet0/0/1 quitRouter interface vlanif
4、 101Router-Vlanif101 ip address 10.23.101.2 24Router-Vlanif101 quit3. 配置AC与其它网络设备互通AC6605AC6605 sysname ACAC vlan batch 100 101AC interface gigabitethernet 0/0/1AC-GigabitEthernet0/0/1 port link-type trunkAC-GigabitEthernet0/0/1 port trunk allow-pass vlan 100 101AC-GigabitEthernet0/0/1 quitAC interf
5、ace gigabitethernet 0/0/2AC-GigabitEthernet0/0/2 port link-type trunkAC-GigabitEthernet0/0/2 port trunk allow-pass vlan 101AC-GigabitEthernet0/0/2 quit4. 在AC上配置DHCP服务器为STA和AP分配IP地址AC dhcp enableAC interface vlanif 100AC-Vlanif100 ip address 10.23.100.1 24AC-Vlanif100 dhcp select interfaceAC-Vlanif10
6、0 quitAC interface vlanif 101AC-Vlanif101 ip address 10.23.101.1 24AC-Vlanif101 dhcp select interfaceAC-Vlanif101 quit5. 在AC上配置AP上线# 创建AP组,用于将相同配置的AP都加入同一AP组中。AC wlanAC-wlan-view ap-group name ap-group1AC-wlan-ap-group-ap-group1 quit# 创建域管理模板,在域管理模板下配置AC的国家码并在AP组下引用域管理模板。AC-wlan-view regulatory-doma
7、in-profile name defaultAC-wlan-regulate-domain-default country-code cnAC-wlan-regulate-domain-default quitAC-wlan-ap-group-ap-group1 regulatory-domain-profile defaultWarning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continue?
8、Y/N:y AC-wlan-view quit# 配置AC的源接口。AC capwap source interface vlanif 1006. 查看ap的mac地址做好记录以备用,并为ap设置部署名称例如area_17. AP具有射频0和射频1两个射频。例如AP5030DN的射频0为2.4GHz射频,射频1为5GHz射频。AC-wlan-view ap auth-mode mac-authAC-wlan-view ap-id 0 ap-mac 60de-4476-e360AC-wlan-ap-0 ap-name area_1AC-wlan-ap-0 ap-group ap-group1 T
9、his operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configurations of the radio, Whether to continue? Y/N:AC-wlan-ap-0 quit8. 保证AP上电并与AC连接,当执行命令display ap all查看到AP的“State”字段为“nor”时,表示AP正常上线。AC-wlan-view display ap allTotal AP information:nor :
10、 normal 1-ID MAC Name Group IP Type State STA Uptime0 00e0-fcfe-1e60 area_1 ap-group1 10.23.100.106 AP5030DN nor 0 10STotal: 19. 配置WLAN业务参数,配置WPA-WPA2+PSK+AES的安全策略,密码为“a1234567”AC-wlan-view security-profile name wlan-netAC-wlan-sec-prof-wlan-net security wpa-wpa2 psk pass-phrase a1234567 aesAC-wlan-
11、sec-prof-wlan-net quit# 创建名为“wlan-net”的SSID模板,并配置SSID名称为“wlan-net”。AC-wlan-view ssid-profile name wlan-netAC-wlan-ssid-prof-wlan-net ssid wlan-netAC-wlan-ssid-prof-wlan-net quit# 创建名为“wlan-net”的VAP模板,配置业务数据转发模式、业务VLAN,并且引用安全模板和SSID模板。AC-wlan-view vap-profile name wlan-netAC-wlan-vap-prof-wlan-net fo
12、rward-mode direct-forwardAC-wlan-vap-prof-wlan-net service-vlan vlan-id 101AC-wlan-vap-prof-wlan-net security-profile wlan-netAC-wlan-vap-prof-wlan-net ssid-profile wlan-netAC-wlan-vap-prof-wlan-net quit# 配置AP组引用VAP模板,AP上射频0和射频1都使用VAP模板“wlan-net”的配置。AC-wlan-ap-group-ap-group1 vap-profile wlan-net wl
13、an 1 radio 0AC-wlan-ap-group-ap-group1 vap-profile wlan-net wlan 1 radio 110. 配置AP射频的信道和功率,关闭射频的信道和功率自动调优功能。射频的信道和功率自动调优功能默认开启,如果不关闭此功能则会导致手动配置不生效。AC-wlan-view rrm-profile name defaultAC-wlan-rrm-prof-default calibrate auto-channel-select disableAC-wlan-rrm-prof-default calibrate auto-txpower-select
14、 disableAC-wlan-rrm-prof-default quit# 配置AP射频0的信道和功率。AC-wlan-view ap-id 0AC-wlan-ap-0 radio 0AC-wlan-radio-0/0 channel 20mhz 6 This action may cause service interruption. Continue?Y/NyAC-wlan-radio-0/0 eirp 127AC-wlan-radio-0/0 quit# 配置AP射频1的信道和功率。AC-wlan-ap-0 radio 1AC-wlan-radio-0/1 channel 20mhz 149AC-wlan-radio-0/1 eirp 127AC-wlan-radio-0/1 quit11. 验证配置结果, WLAN业务配置会自动下发给AP,配置完成后,通过执行命令display vap ssid wlan-net查看如下信息,当“Status”项显示为“ON”时,表示AP对应的射频上的VAP已创建成功。12. STA搜索到名为“wlan-net”的无线网络,输入密码“a1234567”并正常关联后,在AC上执行display station ssid wlan-net命令,可以查看到用户已经接入到无线网络“wlan-net”中。在STA3上做如下操作:
copyright@ 2008-2023 冰点文库 网站版权所有
经营许可证编号:鄂ICP备19020893号-2