WLAN基础配置之AP上线
配置WLAN无线网络的第一阶段,AP上线技术:
实验目标:使得AP能够获得来自AC的DHCP地址服务的地址,且是该网段地址池中的IP。
实验步骤:
1.把AC当作三层交换机配置虚拟网关
sys
Enter system view, return user view with Ctrl+Z.
[AC6605]undo in e
Info: Information center is disabled.
[AC6605]vlan 100
Info: This operation may take a few seconds. Please wait for a moment...done.
[AC6605-vlan100]int vlan 100
[AC6605-Vlanif100]ip add 172.16.100.1 24
[AC6605-Vlanif100]int g0/0/1
[AC6605-GigabitEthernet0/0/1]p l a
[AC6605-GigabitEthernet0/0/1]p d v 100
[AC6605-GigabitEthernet0/0/1]
2.配置核心交换机S-CORE
[S-CORE]vlan 100
[S-CORE-vlan100]q
[S-CORE]int g0/0/5 把与AC相连的接口加入互联vlan100
[S-CORE-GigabitEthernet0/0/5]p l a
[S-CORE-GigabitEthernet0/0/5]p d v 100
[S-CORE-GigabitEthernet0/0/5]q
[S-CORE]int g0/0/1 与下联链路配置trunk并放行VLAN10 VLAN 100的流量
[S-CORE-GigabitEthernet0/0/1]p l t
[S-CORE-GigabitEthernet0/0/1]p t a v 10 100
3.配置接入层交换机
[S]vlan b 10 100
Info: This operation may take a few seconds. Please wait for a moment...done.
[S]int e0/0/1
[S-Ethernet0/0/1]p l a
[S-Ethernet0/0/1]p d v 10
[S-Ethernet0/0/1]int e0/0/2
[S-Ethernet0/0/2]p l a
[S-Ethernet0/0/2]p d v 10
[S-Ethernet0/0/2]int e0/0/4
[S-Ethernet0/0/4]p l a
[S-Ethernet0/0/4]p d v 100
[S-Ethernet0/0/4]q
[S]dis vlan
[S]int e0/0/3
[S-Ethernet0/0/3]p l t
[S-Ethernet0/0/3]p t a v 10 100
[S-Ethernet0/0/3]
- 在AC上配置DHCP服务
[AC6605]dhcp en
Info: The operation may take a few seconds. Please wait for a moment.done.
[AC6605]int vlan 100
[AC6605-Vlanif100]dhcp se
[AC6605-Vlanif100]dhcp select in
[AC6605-Vlanif100]dhcp select interface
[AC6605-Vlanif100]
5.将AP加入到AC,
在AP上查看其MAC地址
【ap】dis int vlan 1
复制AP的MAC地址到剪切板上
[AC6605-wlan-view]ap-mac 00e0-fc96-2a70 在AC的WLAN视图下把AP的MAC地址粘贴进去,就是为了把AP加入到AC.
5.配置CAPWAP隧道(该隧道是AC和AP联动管理的一个重要唯一的通道)
[AC6605]capwap source interface vlanif 100 隧道的源端口是vlanif 100
然后使用dis ap all查看AP是否上线,且状态state 是否是nor 【nor---normal正常】
小贴士:如果看到的AP的MAC地址不方便记忆或直观认识,是可以改名的。
[AC6605]wlan
[AC6605-wlan-view]ap-mac 00e0-fc96-2a70
[AC6605-wlan-ap-0]ap-name 1-001
[AC6605-wlan-ap-0]
再次查看AC上的AP上线信息
-----------------以上就是完成了AP上线的工作,下面是重点内容:AC给AP下发WIFI配置-------------
AC给AP下发配置:
1.)基础配置:想让AP放出什么样的WIFI名称?要配置SSID模板
需要输入怎样的密码?配置安全模板
2.)进阶配置:想让无线用户加入什么VLAN?service-vlan vlan-id
想集中转发(有AC处理)还是本地转发(由AP处理)?forward-mode tunnel
3.)想让AP放出几个信号?VAP
4.)如何集中下发配置? AP组
都在AC上做的配置:
1.)基础配置
[AC6605]wlan
[AC6605-wlan-view]ssid-profile name office 进入SSID模板并命名为office
[AC6605-wlan-view]security-profile name office 进入安全模板并命名还是office
[AC6605-wlan-sec-prof-office]security wpa-wpa2 psk pass-phrase huawei@123 aes
使用wpa-wpa2认证方式,且给密码采用aes加密模式放置黑客截获密码。
2).如果不做进阶配置就是默认的vlan1
3).配置VAP (需要几个配置几个,例如老板一个,员工一个,财务一个,就可以配三个,本案例中只配置1个)
[AC6605-wlan-view]vap-profile name office
[AC6605-wlan-vap-prof-office]ssid-profile office
[AC6605-wlan-vap-prof-office]security-profile office
[AC6605-wlan-vap-prof-office]quit
[AC6605]wlan
[AC6605-wlan-view]ap-group name office
[AC6605-wlan-ap-group-office]vap-profile office wlan 1 radio all
[AC6605-wlan-view]ap-name 1-001
[AC6605-wlan-ap-0]ap-group office
测试移动终端可以获得无线信号了