拓?fù)鋱D
實(shí)驗(yàn)設(shè)備 | 型號(hào) |
---|---|
AC | AC6005 |
S1 | S5700 |
S2 | S3700 |
AP | AP2050DN |
AP4 | AP2050DN |
AR1 | AR200 |
沒有配置好之前,是沒有這個(gè)AP范圍圈的
配置流程
接入交換機(jī)創(chuàng)建VLAN,配置對(duì)應(yīng)端口的鏈路類型,放行vlan,開啟端口隔離
# 與AP連接的接口(0/0/2)
[S2]vlan batch 100 101
[S2]int e0/0/2
[S2-Ethernet0/0/2]port link-type trunk
[S2-Ethernet0/0/2]port trunk pvid vlan 100
[S2-Ethernet0/0/2]port trunk allow-pass vlan 100 101
[S2-Ethernet0/0/2]port-isolate enable
# 與上行匯聚層交換機(jī)連接的接口(0/0/1)
[S2]int e0/0/1
[S2-Ethernet0/0/1]port link-type trunk
[S2-Ethernet0/0/1]port trunk allow-pass vlan 100 101
命令:文章來源:http://www.zghlxwxcb.cn/news/detail-515195.html
- port-isolate enable(開啟端口隔離功能):主要是實(shí)現(xiàn)二層隔離,可以實(shí)現(xiàn)同一個(gè)vlan內(nèi)端口隔離,如果不配置端口隔離,尤其是業(yè)務(wù)數(shù)據(jù)轉(zhuǎn)發(fā)方式采用直接轉(zhuǎn)發(fā)時(shí),可能會(huì)在VLAN內(nèi)形成大量不必要的廣播報(bào)文,導(dǎo)致網(wǎng)絡(luò)阻塞,影響用戶體驗(yàn)。
- port trunk pvid vlan 100 默認(rèn)是vlan 1,就是相當(dāng)于給AP打個(gè)vlan 100的標(biāo)簽,表示AP劃在了vlan 100
匯聚交換機(jī)配置鏈路類型,與AC相連的放行vlan 100,與路由器相連的放行vlan 101
# 與AC相連的接口
[S1]vlan batch 100 101
[S1]int g0/0/1
[S1-GigabitEthernet0/0/1]port link-type trunk
[S1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
#與下行接入交換機(jī)相連的接口
[S1-GigabitEthernet0/0/1]int g0/0/2
[S1-GigabitEthernet0/0/2]port link-type trunk
[S1-GigabitEthernet0/0/2]port trunk allow-pass vlan 100 101
#與路由器相連接口
[S1-GigabitEthernet0/0/2]int g0/0/3
[S1-GigabitEthernet0/0/3]port link-type trunk
[S1-GigabitEthernet0/0/3]port trunk allow-pass vlan 101
路由器配置,配置鏈路類型,放行vlan,設(shè)置vlan 101ip地址
#路由器接口
[AR1]int e0/0/0
[AR1-Ethernet0/0/0]port link-type trunk
[AR1-Ethernet0/0/0]port trunk allow-pass vlan 101
[AR1-Ethernet0/0/0]q
[AR1]int Vlanif 101
[AR1-Vlanif101]ip address 10.10.10.1 24
配置AC,配置管理VLAN為AP下發(fā)IP
[AC]vlan batch 100 101
[AC]int g0/0/1
[AC-GigabitEthernet0/0/1]port link-type trunk
[AC-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
[AC-GigabitEthernet0/0/1]q
[AC] dhcp enable
[AC]interface Vlanif 100
[AC-Vlanif100]ip address 10.10.100.1 24
[AC-Vlanif100]dhcp select interface
命令:
dhcp enable開啟DHCP功能
dhcp select interface開啟接口采用接口地址池的DHCP Server功能文章來源地址http://www.zghlxwxcb.cn/news/detail-515195.html
配置vlan 101為終端分配IP地址
[S1] dhcp enable
[S1]interface Vlanif 101
[S1-Vlanif101]ip address 10.10.10.2 24
[S1-Vlanif101]dhcp select interface
- 這里可以應(yīng)該加一條命令dhcp server gateway-list 10.10.10.1 24就是讓路由器做他的網(wǎng)關(guān),但是不知道為什么在實(shí)驗(yàn)里這個(gè)命令就配置不上去,就只能10.10.10.2做網(wǎng)關(guān)了
配置AP上線
#創(chuàng)建ap組 組名為lnj_group_1
[AC]wlan
[AC-wlan-view]ap-group name lnj_group_1
[AC-wlan-ap-group-lnj_group_1]q
#創(chuàng)建域的管理模板,在域管理的模板下配置AC的國(guó)家碼
[AC-wlan-view]regulatory-domain-profile name default
[AC-wlan-regulate-domain-default]country-code cn
[AC-wlan-regulate-domain-default]q
#在AP組下引用域管理模板。
[AC-wlan-view]ap-group name lnj_group_1
[AC-wlan-ap-group-lnj_group_1]regulatory-domain-profile default
onfigurations of the radio and reset the AP. Continue?[Y/N]:y
[AC-wlan-ap-group-lnj_group_1]q
[AC-wlan-view]q
#配置AC的源接口為vlan 100
[AC] capwap source interface vlanif 100
在AC上可以離線導(dǎo)入AP(00e0-fc13-10b0),并將AP加入AP組“l(fā)nj_group_1”
[AC]wlan
[AC-wlan-view]ap auth-mode mac-auth
#我的AP的MAC:00e0-fc13-10b0
[AC-wlan-view]ap-id 0 ap-mac 00e0-fc13-10b0
[AC-wlan-ap-0]ap-name area_1
[AC-wlan-ap-0]ap-group lnj_group_1
Warning: This operation may cause AP reset. If the country code changes, it will
clear channel, power and antenna gain configurations of the radio, Whether to c
ontinue? [Y/N]:y
Info: This operation may take a few seconds. Please wait for a moment.. done.
[AC-wlan-ap-0]q
上面這一步完成,給AP通電,查看配置結(jié)果,State的值為nor表示AP正常
[AC-wlan-view]display ap all
配置WLAN參數(shù)
#創(chuàng)建名為lnj的安全模板,配置WPA-WPA2+PSK+AES的安全策略
[AC-wlan-view]security-profile name lnj
[AC-wlan-sec-prof-lnj]security wpa-wpa2 psk pass-phrase ax123456 aes
[AC-wlan-sec-prof-lnj]q
#配置wifi名稱為lnj
[AC-wlan-view]ssid-profile name lnj
[AC-wlan-ssid-prof-lnj]ssid lnj
[AC-wlan-ssid-prof-lnj]q
創(chuàng)建名為“l(fā)nj”的VAP模板,配置業(yè)務(wù)數(shù)據(jù)轉(zhuǎn)發(fā)模式為tunnel(隧道轉(zhuǎn)發(fā))
[AC-wlan-view]vap-profile name lnj
[AC-wlan-vap-prof-lnj]forward-mode tunnel
#業(yè)務(wù)vlan為101
[AC-wlan-vap-prof-lnj]service-vlan vlan-id 101
#引用安全模板和ssid模板
[AC-wlan-vap-prof-lnj]security-profile lnj
[AC-wlan-vap-prof-lnj]ssid-profile lnj
[AC-wlan-vap-prof-lnj]q
配置AP組引用VAP模板,指定射頻為 0和1都使用lnj模板
[AC-wlan-view]ap-group name lnj_group_1
[AC-wlan-ap-group-lnj_group_1]vap-profile lnj wlan 1 radio 0
[AC-wlan-ap-group-lnj_group_1]vap-profile lnj wlan 1 radio 1
[AC-wlan-ap-group-lnj_group_1]q
配置讓射頻的信道和功率自動(dòng)調(diào)優(yōu)功能
[AC-wlan-view]regulatory-domain-profile name default
[AC-wlan-regulate-domain-default]dca-channel 2.4g channel-set 1,6,11
[AC-wlan-regulate-domain-default]dca-channel 5g bandwidth 20mhz
[AC-wlan-regulate-domain-default]dca-channel 5g channel-set 149,153,157,161
創(chuàng)建掃描模板“wlan-air”,指定空口掃描信道集合為調(diào)優(yōu)信道集合,指定空口掃描持續(xù)時(shí)間為60毫秒,指定空口掃描間隔時(shí)間為60000毫秒,間隔應(yīng)該設(shè)置高一點(diǎn),低了會(huì)占用較多資源,影響業(yè)務(wù)
[AC-wlan-view]air-scan-profile name wlan-air
[AC-wlan-air-scan-prof-wlan-air]scan-channel-set dca-channel
[AC-wlan-air-scan-prof-wlan-air]scan-period 60
[AC-wlan-air-scan-prof-wlan-air]scan-interval 60000
創(chuàng)建2G射頻模板lnj_radio2g,并引用剛剛配置的空口掃描模板wlan-air,5G射頻模板lnj_radio5g,引用模板wlan-air
[AC-wlan-view]radio-2g-profile name lnj_radio2g
[AC-wlan-radio-2g-prof-lnj_radio2g]air-scan-profile wlan-air
[AC-wlan-view]radio-5g-profile name lnj_radio5g
[AC-wlan-radio-5g-prof-lnj_radio5g]air-scan-profile wlan-air
在名為AP組下引用5G射頻模板lnj_radio5g 和2G射頻模板lnj-radio2g
[AC-wlan-view]ap-group name lnj_group_1
[AC-wlan-ap-group-lnj_group_1]radio-5g-profile lnj_radio5g radio 1
Warning: This action may cause service interruption. Continue?[Y/N]y
[AC-wlan-ap-group-lnj_group_1]radio-2g-profile lnj_radio2g radio 0
Warning: This action may cause service interruption. Continue?[Y/N]y
[AC-wlan-ap-group-lnj_group_1]q
配置射頻調(diào)優(yōu)模式為手動(dòng)調(diào)優(yōu),并手動(dòng)觸發(fā)射頻調(diào)優(yōu)
[AC-wlan-view]calibrate enable manual
[AC-wlan-view]calibrate manual startup
調(diào)優(yōu)結(jié)束后。開始定時(shí)調(diào)優(yōu),并將調(diào)優(yōu)時(shí)間定為用戶業(yè)務(wù)空閑時(shí)段(如當(dāng)?shù)貢r(shí)間凌晨00:00-06:00時(shí)段)。
[AC-wlan-view]calibrate enable schedule time 02:30:00
沒有提前做好規(guī)劃表,配起來挺麻煩的
到了這里,關(guān)于華為FIT痩AP旁掛式隧道組網(wǎng)實(shí)驗(yàn)(一)的文章就介紹完了。如果您還想了解更多內(nèi)容,請(qǐng)?jiān)谟疑辖撬阉鱐OY模板網(wǎng)以前的文章或繼續(xù)瀏覽下面的相關(guān)文章,希望大家以后多多支持TOY模板網(wǎng)!