配置旁掛三層組網(wǎng)隧道轉(zhuǎn)發(fā)示例
組網(wǎng)圖形
業(yè)務(wù)需求
企業(yè)用戶接入WLAN網(wǎng)絡(luò),以滿足移動(dòng)辦公的最基本需求。且在覆蓋區(qū)域內(nèi)移動(dòng)發(fā)生漫游時(shí),不影響用戶的業(yè)務(wù)使用。使用VLAN pool作為業(yè)務(wù)VLAN,可以避免出現(xiàn)IP地址資源不足或者IP地址資源浪費(fèi),減小單個(gè)VLAN下的用戶數(shù)目,縮小廣播域。
組網(wǎng)需求
- AC組網(wǎng)方式:旁掛三層組網(wǎng)。
-
DHCP部署方式:
- AC作為DHCP服務(wù)器為AP分配IP地址。
- 匯聚交換機(jī)SwitchB作為DHCP服務(wù)器為STA分配IP地址。
- 業(yè)務(wù)數(shù)據(jù)轉(zhuǎn)發(fā)方式:隧道轉(zhuǎn)發(fā)。
數(shù)據(jù)規(guī)劃
項(xiàng)目 |
數(shù)據(jù) |
---|---|
AP管理VLAN |
VLAN10、VLAN100 |
STA業(yè)務(wù)VLAN |
VLAN pool |
DHCP服務(wù)器 |
AC作為AP的DHCP服務(wù)器 匯聚交換機(jī)作為STA的DHCP服務(wù)器,STA的默認(rèn)網(wǎng)關(guān)為10.23.101.2和10.23.102.2 |
AP地址池 |
10.23.10.2~10.23.10.254/24 |
STA地址池 |
10.23.101.3~10.23.101.254/24 10.23.102.3~10.23.102.254/24 |
VLAN pool |
|
AC源接口 |
VLANIF100:10.23.100.1/24 |
AP組 |
|
域管理模板 |
|
SSID模板 |
|
安全模板 |
|
VAP模板 |
|
配置思路
- 配置AP、AC和周邊網(wǎng)絡(luò)設(shè)備之間實(shí)現(xiàn)三層互通。
- 配置VLAN pool,用于作為業(yè)務(wù)VLAN。
-
配置AP上線。
- 創(chuàng)建AP組,用于將需要進(jìn)行相同配置的AP都加入到AP組,實(shí)現(xiàn)統(tǒng)一配置。
- 配置AC的系統(tǒng)參數(shù),包括國(guó)家碼、AC與AP之間通信的源接口。
- 配置AP上線的認(rèn)證方式并離線導(dǎo)入AP,實(shí)現(xiàn)AP正常上線。
- 配置WLAN業(yè)務(wù)參數(shù),實(shí)現(xiàn)STA訪問(wèn)WLAN網(wǎng)絡(luò)功能。
配置注意事項(xiàng)
-
純組播報(bào)文由于協(xié)議要求在無(wú)線空口沒有ACK機(jī)制保障,且無(wú)線空口鏈路不穩(wěn)定,為了純組播報(bào)文能夠穩(wěn)定發(fā)送,通常會(huì)以低速報(bào)文形式發(fā)送。如果網(wǎng)絡(luò)側(cè)有大量異常組播流量涌入,則會(huì)造成無(wú)線空口擁堵。為了減小大量低速組播報(bào)文對(duì)無(wú)線網(wǎng)絡(luò)造成的沖擊,建議配置組播報(bào)文抑制功能。配置前請(qǐng)確認(rèn)是否有組播業(yè)務(wù),如果有,請(qǐng)謹(jǐn)慎配置限速值。
- 業(yè)務(wù)數(shù)據(jù)轉(zhuǎn)發(fā)方式采用直接轉(zhuǎn)發(fā)時(shí),建議在直連AP的交換機(jī)接口上配置組播報(bào)文抑制。
- 業(yè)務(wù)數(shù)據(jù)轉(zhuǎn)發(fā)方式采用隧道轉(zhuǎn)發(fā)時(shí),建議在AC的流量模板下配置組播報(bào)文抑制。
-
建議在與AP直連的設(shè)備接口上配置端口隔離,如果不配置端口隔離,尤其是業(yè)務(wù)數(shù)據(jù)轉(zhuǎn)發(fā)方式采用直接轉(zhuǎn)發(fā)時(shí),可能會(huì)在VLAN內(nèi)形成大量不必要的廣播報(bào)文,導(dǎo)致網(wǎng)絡(luò)阻塞,影響用戶體驗(yàn)。
-
隧道轉(zhuǎn)發(fā)模式下,管理VLAN和業(yè)務(wù)VLAN不能配置為同一VLAN,且AP和AC之間只能放通管理VLAN,不能放通業(yè)務(wù)VLAN。
- V200R021C00版本開始,配置CAPWAP源接口或源地址時(shí),會(huì)檢查和安全相關(guān)的配置是否已存在,包括DTLS加密的PSK、AC間DTLS加密的PSK、登錄AP的用戶名和密碼、全局離線管理VAP的登錄密碼,均已存在才能成功配置,否則會(huì)提示用戶先完成相關(guān)的配置。
- V200R021C00版本開始,AC默認(rèn)開啟CAPWAP控制隧道的DTLS加密功能。開啟該功能,添加AP時(shí)AP會(huì)上線失敗,此時(shí)需要先開啟CAPWAP DTLS不認(rèn)證方式(capwap dtls no-auth enable)讓AP上線,以便AP獲取安全憑證,AP上線后應(yīng)及時(shí)關(guān)閉該功能(undo capwap dtls no-auth enable),避免未授權(quán)AP上線。
操作步驟
-
配置周圍設(shè)備
# 配置接入交換機(jī)SwitchA的GE0/0/1和GE0/0/2接口加入VLAN10,GE0/0/1的缺省VLAN為VLAN10。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd"><HUAWEI> <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b1621764312190921">system-view</strong> [HUAWEI] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b1059066761190921">sysname SwitchA</strong> [SwitchA] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b368197346190921">vlan batch 10</strong> [SwitchA] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b549081780190921">interface gigabitethernet 0/0/1</strong> [SwitchA-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b1310967693190921">port link-type trunk</strong> [SwitchA-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b292518998190921">port trunk pvid vlan 10</strong> [SwitchA-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b977182054190921">port trunk allow-pass vlan 10</strong> [SwitchA-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b769506019190921">port-isolate enable</strong> [SwitchA-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b1964230705190921">quit</strong> [SwitchA] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b1539535887190921">interface gigabitethernet 0/0/2</strong> [SwitchA-GigabitEthernet0/0/2] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b2045142050190921">port link-type trunk</strong> [SwitchA-GigabitEthernet0/0/2] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b201778540190921">port trunk allow-pass vlan 10</strong> [SwitchA-GigabitEthernet0/0/2] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912361_b697633435190921">quit</strong></span></span></span>
# 配置匯聚交換機(jī)SwitchB的接口GE0/0/1加入VLAN10,接口GE0/0/2加入VLAN100、VLAN101和VLAN102,接口GE0/0/3加入VLAN101和VLAN102,并創(chuàng)建接口VLANIF100,地址為10.23.100.2/24。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd"><HUAWEI> <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b917625514190921">system-view</strong> [HUAWEI] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b344355388190921">sysname SwitchB</strong> [SwitchB] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1931308663190921">vlan batch 10 100 101 102</strong> [SwitchB] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1211554111190921">interface gigabitethernet 0/0/1</strong> [SwitchB-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b375976978190921">port link-type trunk</strong> [SwitchB-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1931953435190921">port trunk allow-pass vlan 10</strong> [SwitchB-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b802945932190921">quit</strong> [SwitchB] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1404564343190921">interface gigabitethernet 0/0/2</strong> [SwitchB-GigabitEthernet0/0/2] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b998551662190921">port link-type trunk</strong> [SwitchB-GigabitEthernet0/0/2] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b809751990190921">port trunk allow-pass vlan 100 101 102</strong> [SwitchB-GigabitEthernet0/0/2] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1506044190190921">quit</strong> [SwitchB] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b912482635190921">interface gigabitethernet 0/0/3</strong> [SwitchB-GigabitEthernet0/0/3] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b785888875190921">port link-type trunk</strong> [SwitchB-GigabitEthernet0/0/3] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1818290682190921">port trunk allow-pass vlan 101 102</strong> [SwitchB-GigabitEthernet0/0/3] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b990911419190921">quit</strong> [SwitchB] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b43449113190921">interface vlanif 100</strong> [SwitchB-Vlanif100] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b58955742190921">ip address 10.23.100.2 24</strong> [SwitchB-Vlanif100] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b921608182190921">quit</strong></span></span></span>
# 配置Router的接口GE1/0/0加入VLAN101和VLAN102,創(chuàng)建接口VLANIF101并配置IP地址為10.23.101.2/24,創(chuàng)建接口VLANIF102并配置IP地址為10.23.102.2/24。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd"><Huawei> <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1660975988190921">system-view</strong> [Huawei] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1226113612190921">sysname Router</strong> [Router] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1810277086190921">vlan batch 101 102</strong> [Router] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1780942278190921">interface gigabitethernet 1/0/0</strong> [Router-GigabitEthernet1/0/0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1672774733190921">port link-type trunk</strong> [Router-GigabitEthernet1/0/0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b189355832190921">port trunk allow-pass vlan 101 102</strong> [Router-GigabitEthernet1/0/0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b961790458190921">quit</strong> [Router] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1935309198190921">interface vlanif 101</strong> [Router-Vlanif101] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b218616744190921">ip address 10.23.101.2 24</strong> [Router-Vlanif101] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b617077487190921">quit</strong> [Router] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b824497200190921">interface vlanif 102</strong> [Router-Vlanif102] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b976896216190921">ip address 10.23.102.2 24</strong> [Router-Vlanif102] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b89740708190921">quit</strong></span></span></span>
-
配置AC與其它網(wǎng)絡(luò)設(shè)備互通
# 配置AC的接口GE0/0/1加入VLAN100、VLAN101和VLAN102,并創(chuàng)建接口VLANIF100。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd"><HUAWEI> <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b629993190921">system-view</strong> [HUAWEI] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1353342057190921">sysname AC</strong> [AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b42034894190921">vlan 100</strong> [AC-vlan100] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1340682779190921">quit</strong> [AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b402927046190921">interface vlanif 100</strong> [AC-Vlanif100] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b888892818190921">ip address 10.23.100.1 24</strong> [AC-Vlanif100] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b304386546190921">quit</strong> [AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b348243040190921">interface gigabitethernet 0/0/1</strong> [AC-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b356838640190921">port link-type trunk</strong> [AC-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b933544608190921">port trunk allow-pass vlan 100 101 102</strong> [AC-GigabitEthernet0/0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1729124733190921">quit</strong></span></span></span>
# 配置AC到AP的路由,下一跳為SwitchB的VLANIF100。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b968430929190921">ip route-static 10.23.10.0 24 10.23.100.2</strong></span></span></span>
-
配置DHCP服務(wù)為AP和STA分配IP地址
# 在SwitchB上配置DHCP中繼,代理AC分配IP地址。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[SwitchB] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b709859105190921">dhcp enable</strong> [SwitchB] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1603317566190921">interface vlanif 10</strong> [SwitchB-Vlanif10] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b82434276190921">ip address 10.23.10.1 24</strong> [SwitchB-Vlanif10] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1453619429190921">dhcp select relay</strong> [SwitchB-Vlanif10] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b2144273645190921">dhcp relay server-ip 10.23.100.1</strong> [SwitchB-Vlanif10] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b868750119190921">quit</strong></span></span></span>
# 在SwitchB上創(chuàng)建VLANIF101和VLANIF102接口為STA提供地址,并指定默認(rèn)網(wǎng)關(guān)。DNS服務(wù)器地址請(qǐng)根據(jù)實(shí)際需要配置。常用配置方法如下:- 接口地址池場(chǎng)景,需要在VLANIF接口視圖下執(zhí)行命令dhcp server dns-list?ip-address?&<1-8>。
- 全局地址池場(chǎng)景,需要在IP地址池視圖下執(zhí)行命令dns-list?ip-address?&<1-8>。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[SwitchB] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b873658886190921">interface vlanif 101</strong> [SwitchB-Vlanif101] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b95742990190921">ip address 10.23.101.1 24</strong> [SwitchB-Vlanif101] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1732731206190921">dhcp select interface</strong> [SwitchB-Vlanif101] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b401619151190921">dhcp server gateway-list 10.23.101.2</strong> [SwitchB-Vlanif101] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b2128265174190921">quit</strong> [SwitchB] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1109687378190921">interface vlanif 102</strong> [SwitchB-Vlanif102] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1695334458190921">ip address 10.23.102.1 24</strong> [SwitchB-Vlanif102] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b784759301190921">dhcp select interface</strong> [SwitchB-Vlanif102] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1025754285190921">dhcp server gateway-list 10.23.102.2</strong> [SwitchB-Vlanif102] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b22249946190921">quit</strong></span></span></span>
# 在AC上創(chuàng)建全局地址池為AP提供地址。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b365851844190921">dhcp enable</strong> [AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b990563412190921">ip pool huawei</strong> [AC-ip-pool-huawei] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b169375134190921">network 10.23.10.0 mask 24</strong> [AC-ip-pool-huawei] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1498722238190921">gateway-list 10.23.10.1</strong> [AC-ip-pool-huawei] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1127109521190921">option 43 sub-option 3 ascii 10.23.100.1</strong> [AC-ip-pool-huawei] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1641310089190921">quit</strong> [AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1333165711190921">interface vlanif 100</strong> [AC-Vlanif100] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1287471321190921">dhcp select global</strong> [AC-Vlanif100] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b689492679190921">quit</strong></span></span></span>
-
配置VLAN pool,用于作為業(yè)務(wù)VLAN
# 在AC上新建VLAN pool,并將VLAN101和VLAN102加入其中,配置VLAN pool中的VLAN分配算法為“hash”。
本例VLAN pool中的VLAN分配算法配置為“hash”。分配算法缺省情況下為“hash”,如果之前沒有修改其缺省配置,可以不用執(zhí)行命令assignment hash。
本例VLAN pool僅以加入VLAN101和VLAN102兩個(gè)VLAN為例,實(shí)際可以配置多個(gè)VLAN加入VLAN pool,配置方法與VLAN101和VLAN102一致。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b352911723190921">vlan batch 101 102</strong> [AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b351799307190921">vlan pool sta-pool</strong> [AC-vlan-pool-sta-pool] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1532711495190921">vlan 101 102</strong> [AC-vlan-pool-sta-pool] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b24709074190921">assignment hash</strong> [AC-vlan-pool-sta-pool] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1762892773190921">quit</strong></span></span></span>
-
配置AP上線
# 創(chuàng)建AP組,用于將相同配置的AP都加入同一AP組中。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b1451837292190921">wlan</strong> [AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b1710308668190921">ap-group name ap-group1</strong> [AC-wlan-ap-group-ap-group1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b294415960190921">quit</strong></span></span></span>
# 創(chuàng)建域管理模板,在域管理模板下配置AC的國(guó)家碼并在AP組下引用域管理模板。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b1815954045190921">regulatory-domain-profile name default</strong> [AC-wlan-regulate-domain-default] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b1765454957190921">country-code cn</strong> [AC-wlan-regulate-domain-default] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b464951690190921">quit</strong> [AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b1132959133190921">ap-group name ap-group1</strong> [AC-wlan-ap-group-ap-group1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b4510754102210">regulatory-domain-profile default</strong> Warning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continue?[Y/N]:<strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_zh-cn_task_0175818418_b17491131153716">y</strong> [AC-wlan-ap-group-ap-group1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b101836067190921">quit</strong> [AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b465166413190921">quit</strong></span></span></span>
# 配置AC的源接口。V200R021C00版本開始,配置CAPWAP源接口或源地址時(shí),會(huì)檢查和安全相關(guān)的配置是否已存在,包括DTLS加密的PSK、AC間DTLS加密的PSK、登錄AP的用戶名和密碼、全局離線管理VAP的登錄密碼,均已存在才能成功配置,否則會(huì)提示用戶先完成相關(guān)的配置。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b806281647190921">capwap source interface vlanif 100</strong> Set the DTLS PSK(contains 6-32 plain-text characters, or 48 or 68 cipher-text characters that must be a combination of at least two of the following: lowercase letters a to z, uppercase letters A to Z, digits, and special characters):****** Set the DTLS inter-controller PSK(contains 6-32 plain-text characters, or 48 or 68 cipher-text characters that must be a combination of at least two of the following: lowercase letters a to z, uppercase letters A to Z, digits, and special characters):****** Set the user name for FIT APs(contains 4-31 plain-text characters, which can only include letters, digits and underlines. And the first character must be a letter):admin Set the password for FIT APs(plain-text password of 8-128 characters or cipher-text password of 48-188 characters that must be a combination of at least three of the following: lowercase letters a to z, uppercase letters A to Z, digits, and special characters):******** Set the global temporary-management psk(contains 8-63 plain-text characters, or 48-108 cipher-text characters that must be a combination of at least two of the following: lowercase letters a to z, uppercase letters A to Z, digits, and special characters):********</span></span></span>
# 在AC上離線導(dǎo)入AP,并將AP加入AP組“ap-group1”中。假設(shè)AP的MAC地址為60de-4476-e360,并且根據(jù)AP的部署位置為AP配置名稱,便于從名稱上就能夠了解AP的部署位置。例如MAC地址為60de-4476-e360的AP部署在1號(hào)區(qū)域,命名此AP為area_1。ap auth-mode命令缺省情況下為MAC認(rèn)證,如果之前沒有修改其缺省配置,可以不用執(zhí)行ap auth-mode mac-auth。
舉例中使用的AP為AP5030DN,具有射頻0和射頻1兩個(gè)射頻。AP5030DN的射頻0為2.4GHz射頻,射頻1為5GHz射頻。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b763711121190921">wlan</strong> [AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b1389711844190921">ap auth-mode mac-auth</strong> [AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b1382708357190921">ap-id 0 ap-mac 60de-4476-e360</strong> [AC-wlan-ap-0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b1272920990190921">ap-name area_1</strong> Warning: This operation may cause AP reset. Continue? [Y/N]:<strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_zh-cn_task_0175818418_b460951517190906">y</strong> [AC-wlan-ap-0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b614746147190921">ap-group ap-group1</strong> Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configuration s of the radio, Whether to continue? [Y/N]:<strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_zh-cn_task_0175818418_b1651706244190906">y</strong> [AC-wlan-ap-0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0176912351_b959850628190921">quit</strong></span></span></span>
# 將AP上電后,當(dāng)執(zhí)行命令display ap all查看到AP的“State”字段為“nor”時(shí),表示AP正常上線。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b614686600190921">display ap all</strong> Total AP information:nor : normal [1] Extra information: P : insufficient power supply -------------------------------------------------------------------------------------------------- ID MAC Name Group IP Type State STA Uptime ExtraInfo -------------------------------------------------------------------------------------------------- 0 60de-4476-e360 area_1 ap-group1 10.23.10.254 AP5030DN nor 0 10S - -------------------------------------------------------------------------------------------------- Total: 1</span></span></span>
-
配置WLAN業(yè)務(wù)
# 創(chuàng)建名為“wlan-net”的安全模板,并配置安全策略。
舉例中以配置WPA-WPA2+PSK+AES的安全策略為例,密碼為“a1234567”,實(shí)際配置中請(qǐng)根據(jù)實(shí)際情況,配置符合實(shí)際要求的安全策略。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b1991067776190921">security-profile name wlan-net</strong> [AC-wlan-sec-prof-wlan-net] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b851752672190921">security wpa-wpa2 psk pass-phrase a1234567 aes</strong> [AC-wlan-sec-prof-wlan-net] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b337241812190921">quit</strong></span></span></span>
# 創(chuàng)建名為“wlan-net”的SSID模板,并配置SSID名稱為“wlan-net”。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b69022931190921">ssid-profile name wlan-net</strong> [AC-wlan-ssid-prof-wlan-net] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b36723145190921">ssid wlan-net</strong> [AC-wlan-ssid-prof-wlan-net] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b1738903244190921">quit</strong></span></span></span>
# 創(chuàng)建名為“wlan-net”的VAP模板,配置業(yè)務(wù)數(shù)據(jù)轉(zhuǎn)發(fā)模式、業(yè)務(wù)VLAN,并且引用安全模板和SSID模板。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1855981251190921">vap-profile name wlan-net</strong> [AC-wlan-vap-prof-wlan-net] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b321684106190921">forward-mode tunnel</strong> [AC-wlan-vap-prof-wlan-net] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b1200768104190921">service-vlan vlan-pool sta-pool</strong> [AC-wlan-vap-prof-wlan-net] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b224281402190921">security-profile wlan-net</strong> [AC-wlan-vap-prof-wlan-net] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b44160359190921">ssid-profile wlan-net</strong> [AC-wlan-vap-prof-wlan-net] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_b623722313190921">quit</strong></span></span></span>
# 配置AP組引用VAP模板,AP上射頻0和射頻1都使用VAP模板“wlan-net”的配置。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b2051092768190921">ap-group name ap-group1</strong> [AC-wlan-ap-group-ap-group1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b1753511747190921">vap-profile wlan-net wlan 1 radio 0</strong> [AC-wlan-ap-group-ap-group1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b1212706755190921">vap-profile wlan-net wlan 1 radio 1</strong> [AC-wlan-ap-group-ap-group1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b729861449190921">quit</strong></span></span></span>
-
配置AP射頻的信道和功率
射頻的信道和功率自動(dòng)調(diào)優(yōu)功能默認(rèn)開啟,如果不關(guān)閉此功能則會(huì)導(dǎo)致手動(dòng)配置不生效。舉例中AP射頻的信道和功率僅為示例,實(shí)際配置中請(qǐng)根據(jù)AP的國(guó)家碼和網(wǎng)規(guī)結(jié)果進(jìn)行配置。
# 關(guān)閉AP射頻0的信道和功率自動(dòng)調(diào)優(yōu)功能,并配置AP射頻0的信道和功率。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1423607009190921">ap-id 0</strong> [AC-wlan-ap-0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1534489953190921">radio 0</strong> [AC-wlan-radio-0/0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b733594144190921">calibrate auto-channel-select disable</strong> [AC-wlan-radio-0/0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1154293079190921">calibrate auto-txpower-select disable</strong> [AC-wlan-radio-0/0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1858200296190921">channel 20mhz 6</strong> Warning: This action may cause service interruption. Continue?[Y/N]<strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0175818418_b1384307436190906">y</strong> [AC-wlan-radio-0/0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b554899294190921">eirp 127</strong> [AC-wlan-radio-0/0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1779547689190921">quit</strong></span></span></span>
# 關(guān)閉AP射頻1的信道和功率自動(dòng)調(diào)優(yōu)功能,并配置AP射頻1的信道和功率。<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-ap-0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b33229250190921">radio 1</strong> [AC-wlan-radio-0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b327597144190921">calibrate auto-channel-select disable</strong> [AC-wlan-radio-0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1164564697190921">calibrate auto-txpower-select disable</strong> [AC-wlan-radio-0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b201103780190921">channel 20mhz 149</strong> Warning: This action may cause service interruption. Continue?[Y/N]<strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_zh-cn_task_0175818418_b1384307436190906_1">y</strong> [AC-wlan-radio-0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b652286665190921">eirp 127</strong> [AC-wlan-radio-0/1] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b1440636620190921">quit</strong> [AC-wlan-ap-0] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912356_b904227301190921">quit</strong></span></span></span>
-
驗(yàn)證配置結(jié)果
WLAN業(yè)務(wù)配置會(huì)自動(dòng)下發(fā)給AP,配置完成后,通過(guò)執(zhí)行命令display vap ssid wlan-net查看如下信息,當(dāng)“Status”項(xiàng)顯示為“ON”時(shí),表示AP對(duì)應(yīng)的射頻上的VAP已創(chuàng)建成功。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b367333496190921">display vap ssid wlan-net</strong> WID : WLAN ID -------------------------------------------------------------------------------- AP ID AP name RfID WID BSSID Status Auth type STA SSID -------------------------------------------------------------------------------- 0 area_1 0 1 60DE-4476-E360 <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b1874482883190921">ON</strong> WPA/WPA2-PSK 0 wlan-net 0 area_1 1 1 60DE-4476-E370 <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b1628414885190921">ON</strong> WPA/WPA2-PSK 0 wlan-net ------------------------------------------------------------------------------- Total: 2</span></span></span>
STA搜索到名為“wlan-net”的無(wú)線網(wǎng)絡(luò),輸入密碼“a1234567”并正常關(guān)聯(lián)后,在AC上執(zhí)行display station ssid wlan-net命令,可以查看到用戶已經(jīng)接入到無(wú)線網(wǎng)絡(luò)“wlan-net”中。
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd">[AC-wlan-view] <strong id="ZH-CN_TASK_0180383111__zh-cn_task_0176912352_zh-cn_task_0176912351_b1120837202190921">display station ssid wlan-net</strong> Rf/WLAN: Radio ID/WLAN ID Rx/Tx: link receive rate/link transmit rate(Mbps) --------------------------------------------------------------------------------- STA MAC AP ID Ap name Rf/WLAN Band Type Rx/Tx RSSI VLAN IP address --------------------------------------------------------------------------------- e019-1dc7-1e08 0 area_1 1/1 5G 11n 46/59 -68 101 10.23.101.254 --------------------------------------------------------------------------------- Total: 1 2.4G: 0 5G: 1</span></span></span>
配置文件
-
SwitchA的配置文件
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd"># sysname SwitchA # vlan batch 10 # interface GigabitEthernet0/0/1 port link-type trunk port trunk pvid vlan 10 port trunk allow-pass vlan 10 port-isolate enable group 1 # interface GigabitEthernet0/0/2 port link-type trunk port trunk allow-pass vlan 10 # return</span></span></span>
-
SwitchB的配置文件
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd"># sysname SwitchB # vlan batch 10 100 to 102 # dhcp enable # interface Vlanif10 ip address 10.23.10.1 255.255.255.0 dhcp select relay dhcp relay server-ip 10.23.100.1 # interface Vlanif100 ip address 10.23.100.2 255.255.255.0 # interface Vlanif101 ip address 10.23.101.1 255.255.255.0 dhcp select interface dhcp server gateway-list 10.23.101.2 # interface Vlanif102 ip address 10.23.102.1 255.255.255.0 dhcp select interface dhcp server gateway-list 10.23.102.2 # interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 10 # interface GigabitEthernet0/0/2 port link-type trunk port trunk allow-pass vlan 100 to 102 # interface GigabitEthernet0/0/3 port link-type trunk port trunk allow-pass vlan 101 to 102 # return</span></span></span>
-
Router的配置文件文章來(lái)源:http://www.zghlxwxcb.cn/news/detail-836644.html
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd"># sysname Router # vlan batch 101 to 102 # interface Vlanif101 ip address 10.23.101.2 255.255.255.0 # interface Vlanif102 ip address 10.23.102.2 255.255.255.0 # interface GigabitEthernet1/0/0 port link-type trunk port trunk allow-pass vlan 101 to 102 # return </span></span></span>
-
AC的配置文件文章來(lái)源地址http://www.zghlxwxcb.cn/news/detail-836644.html
<span style="color:#333333"><span style="background-color:#ffffff"><span style="background-color:#dddddd"># sysname AC # vlan batch 100 to 102 # vlan pool sta-pool vlan 101 to 102 # dhcp enable # ip pool huawei gateway-list 10.23.10.1 network 10.23.10.0 mask 255.255.255.0 option 43 sub-option 3 ascii 10.23.100.1 # interface Vlanif100 ip address 10.23.100.1 255.255.255.0 dhcp select global # interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 100 to 102 # ip route-static 10.23.10.0 24 10.23.100.2 # capwap source interface vlanif100 # wlan security-profile name wlan-net security wpa-wpa2 psk pass-phrase %^%#m"tz0f>~7.[`^6RWdzwCy16hJj/Mc!,}s`X*B]}A%^%# aes ssid-profile name wlan-net ssid wlan-net vap-profile name wlan-net forward-mode tunnel service-vlan vlan-pool sta-pool ssid-profile wlan-net security-profile wlan-net regulatory-domain-profile name default ap-group name ap-group1 radio 0 vap-profile wlan-net wlan 1 radio 1 vap-profile wlan-net wlan 1 ap-id 0 type-id 35 ap-mac 60de-4476-e360 ap-sn 210235554710CB000042 ap-name area_1 ap-group ap-group1 radio 0 channel 20mhz 6 eirp 127 calibrate auto-channel-select disable calibrate auto-txpower-select disable radio 1 channel 20mhz 149 eirp 127 calibrate auto-channel-select disable calibrate auto-txpower-select disable # return</span></span></span>
到了這里,關(guān)于華為配置旁掛三層組網(wǎng)隧道轉(zhuǎn)發(fā)示例的文章就介紹完了。如果您還想了解更多內(nèi)容,請(qǐng)?jiān)谟疑辖撬阉鱐OY模板網(wǎng)以前的文章或繼續(xù)瀏覽下面的相關(guān)文章,希望大家以后多多支持TOY模板網(wǎng)!