h3c无线控制器加fit-ap配置实例

合集下载

06-H3C WX系列AC+Fit AP AP自动升级版本典型配置举例

06-H3C WX系列AC+Fit AP AP自动升级版本典型配置举例

H3C WX系列AC+Fit AP AP自动升级版本典型配置举例关键词:AP, AC, LWAPP摘要:本配置举例介绍了AP版本的自动升级功能。

缩略语:缩略语英文全名中文解释Point 无线接入点AP AcessControler 无线控制器AC AccessLWAPP Light Weigthed AP Protocol 轻量AP协议无线局域网NetworkLocalWLAN Wireless目录1 特性简介 (1)1.1 特性优点 (1)2 应用场合 (1)3 注意事项 (1)4 配置举例 (1)4.1 组网需求 (1)4.2 配置思路 (2)4.3 使用版本 (2)4.4 操作步骤 (3)4.5 验证结果 (7)5 相关资料 (8)5.1 相关协议和标准 (8)5.2 其它相关资料 (8)1 特性简介AP版本自动升级功能,可以实现,人工升级AC后,AP检测到AC的版本已经更新,会自动从AC 上获取最新的相应版本,更新到最新版本。

1.1 特性优点降低了管理AP的工作量。

2 应用场合这个特性,当有大量AP需要升级版本或者AP布置在比较难于触及的地方时,有极大的方便性。

3 注意事项Bootrom版本要能够兼容新的AP版本。

4 配置举例4.1 组网需求本配置举例中的AC使用的是WX5002无线控制器,AP使用的是WA2100无线局域网接入点。

图4-1AP自动升级版本的典型配置举例组网图4.2 配置思路需要配置以下内容:z版本升级前,AP和AC处于正常工作状态。

z保存AC的配置,并设置默认启动配置;然后从版本服务获取最新的AC和AP的版本到AC 上面来,AP的名称应符合要求,例如Fit AP WA2100的升级版本名称,必须为wa2100.bin。

z重启AC之后,AP将会进行版本检测,自动升级版本;并重新恢复保存的配置。

4.3 使用版本1. AC版本<AC>display versionH3C Comware Platform SoftwareComware Software, Version 5.00, ESS 1102P01Copyright (c) 2004-2007 Hangzhou H3C Tech. Co., Ltd. All rights reserved.H3C WX5002-128 uptime is 0 week, 0 day, 0 hour, 3 minutesCPU type: BCM MIPS 1250 700MHz1024M bytes DDR SDRAM Memory32M bytes Flash MemoryPcb Version: ALogic Version: 1.0Basic BootROM Version: 1.12Extend BootROM Version: 1.13[SLOT 1]CON (Hardware)A, (Driver)1.0, (Cpld)1.0[SLOT 1]GE1/0/1 (Hardware)A, (Driver)1.0, (Cpld)1.0[SLOT 1]GE1/0/2 (Hardware)A, (Driver)1.0, (Cpld)1.0<AC>2. AP版本<AP>_display versionH3C Comware Platform SoftwareComware Software, Version 5.00, ESS 1102P01Comware Platform Software Version COMWAREV500R002B35D004H3C WA2100 Software Version V100R001B05D004Copyright (c) 2004-2007 Hangzhou H3C Tech. Co., Ltd. All rights reserved.Compiled Jun 12 2007 15:52:46, RELEASE SOFTWAREH3C WA2100 uptime is 0 week, 0 day, 0 hour, 0 minuteCPU type: ATHEROS MIPS 2313 180MHz32M bytes SDRAM Memory4M bytes Flash MemoryPcb Version: Ver.BBasic BootROM Version: 1.08Extend BootROM Version: 1.08[SLOT 1]CON (Hardware)Ver.B, (Driver)1.0[SLOT 1]RADIO1/0/1 (Hardware)Ver.B, (Driver)1.0[SLOT 1]ETH1/0/1 (Hardware)Ver.B, (Driver)1.04.4 操作步骤1. 确认网络状况良好需要确认网络状况,AC和AP之间的网络能够通畅,保证AC和AP在没有升级版本时,能够成功连接。

WX3024H3C无线控制二层注册配置

WX3024H3C无线控制二层注册配置

●组网说明→FIT AP与WX3024直接连接→WX3024管理地址192.168.1.99/24→AP属于VLAN 1(192.168.1.0/24网段)→无线客户端属于VLAN 2(192.168.2.0/24网段)→交换机与WX3024连接的接口地址为192.168.2.254,为无线客户端网关地址WX3024无线控制模块的主要配置●步骤一:添加相应的VLAN(vlan 2),并在vlan 1下配置设备管理ip 192.168.1.99→[WX3024] vlan 2→[WX3024 ]interface vlan 1→[WX3024-Vlan-interface1] ip address 192.168.1.99 24●步骤二:使能DHCP Server功能,配置vlan 1网段的地址池,为AP动态分配地址→[WX3024] dhcp enable→[WX3024 ] dhcp server ip-pool pool1→[WX3024-dhcp-pool-pool1] network 192.168.1.0 24●步骤三:将无线控制模块的内部接口GigabitEthernet1/0/1设置为Trunk类型→[WX3024] interface GigabitEthernet 1/0/1→[WX3024-GigabitEthernet1/0/1] port link-type trunk→[WX3024-GigabitEthernet1/0/1] port trunk permit vlan all●步骤四:配置无线接口WLAN-ESS 1,并指定其属于vlan 2(无线客户端属于vlan 2)→[WX3024] interface WLAN-ESS 1→[WX3024-WLAN-ESS1] port access vlan 2→[WX3024] wlan service-template 1 clear→[WX3024-wlan-st-1] ssid H3C→[WX3024-wlan-st-1] authentication-method open-system→[WX3024-wlan-st-1] bind WLAN-ESS 1→[WX3024-wlan-st-1] service-template enable●步骤五:手动添加AP WA2110,并在射频卡radio 1上绑定已创建的服务模板service-template 1→[WX3024] wlan ap ap1 model WA2100→[WX3024-wlan-ap-ap1] serial-id 210235A22W0074000123→[WX3024-wlan-ap-ap1] radio 1→[WX3024-wlan-ap-ap1-radio-1] service-template 1→[WX3024-wlan-ap-ap1-radio-1] radio enable●步骤六:配置静态路由→[WX3024]ip route-static 0.0.0.0 0 192.168.2.254●步骤七:查看AP运行情况→[WX3024]display wlan ap allWX3024交换模块的主要配置●步骤一:添加相应的VLAN(vlan 2)→[WX3024] vlan 2●步骤二:将WX3024连接三层交换机的接口设置为vlan 2→[WX3024] interface GigabitEthernet 1/0/24→[WX3024-GigabitEthernet1/0/24] port access vlan 2●步骤三:将交换模块的内部接口GigabitEthernet1/0/29设置为Trunk类型→[WX3024] interface GigabitEthernet 1/0/29→[WX3024-GigabitEthernet1/0/29] port link-type trunk→[WX3024-GigabitEthernet1/0/29] port trunk permit vlan all。

h3c无线控制器加fit ap配置实例

h3c无线控制器加fit ap配置实例

一栋大楼内部组建公共无线网络,考虑到客户端数量可能众多,而客户端频繁移动可能性不大,规划将无线客户端划分到不同的vlan内,无线ap及接入层交换机划在一个vlan内。

网络连接示意图如下:无线控制器配置文件:#version 5.20, Release 2308P10#sysname wx5004#domain default enable system#port-security enable#wlan auto-ap enable#vlan 1#vlan 96description ap-client#vlan 97description ap-client#vlan 98description ap-client#vlan 99description ap-client#vlan 100description ap-client#vlan 101description ap-client#vlan 102description ap-client#vlan 103description managerdevice#domain systemaccess-limit disablestate activeidle-cut disablepublic-key-code beginpublic-key-code endpeer-public-key end#dhcp server ip-pool managerexpired day 7#dhcp server ip-pool pub-wireless-use#dhcp server ip-pool vlan100#dhcp server ip-pool vlan101#dhcp server ip-pool vlan102#dhcp server ip-pool vlan96#dhcp server ip-pool vlan97#dhcp server ip-pool vlan98#dhcp server ip-pool vlan99user-group systemgroup-attribute allow-guest#local-user adminpassword simple xxxxxauthorization-attribute level 3service-type ssh telnet#wlan rrmdot11a mandatory-rate 6 12 24dot11a supported-rate 9 18 36 48 54dot11b mandatory-rate 1 2dot11b supported-rate 5.5 11dot11g mandatory-rate 1 2 5.5 11dot11g supported-rate 6 9 12 18 24 36 48 54 #wlan radio-policy 101#wlan radio-policy 103#wlan service-template 103 clearssid pubwirelessbind WLAN-ESS 103service-template enable#interface NULL0#interface Vlan-interface1#interface Vlan-interface96#interface Vlan-interface97#interface Vlan-interface98#interface Vlan-interface99#interface Vlan-interface100interface Vlan-interface101#interface Vlan-interface102#interface Vlan-interface103#interface GigabitEthernet1/0/1port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103 #interface GigabitEthernet1/0/2port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103 #interface GigabitEthernet1/0/3port access vlan 101#interface GigabitEthernet1/0/4port access vlan 101#interface M-Ethernet1/0/0#interface Ten-GigabitEthernet1/0/5 #interface WLAN-ESS1#interface WLAN-ESS101port access vlan 101#interface WLAN-ESS103port access vlan 103#wlan ap 3c01 model WA2100 id 2radio 1radio-policy 103service-template 103 vlan-id 96 radio enable#wlan ap autoap model WA2100 id 1#wlan ap autoap_0001 model WA2100 id 3radio 1radio-policy 103service-template 103 vlan-id 96radio enable#wlan ap autoap_0002 model WA2100 id 4radio 1radio-policy 103service-template 103 vlan-id 96radio enable#wlan ap autoap_0003 model WA2100 id 5radio 1radio-policy 103service-template 103 vlan-id 96radio enable#wlan ap autoap_0004 model WA2100 id 6radio 1radio-policy 103service-template 103 vlan-id 97radio enable#wlan ap autoap_0005 model WA2100 id 7radio 1radio-policy 103service-template 103 vlan-id 97radio enable#wlan ap autoap_0006 model WA2100 id 8radio 1radio-policy 103service-template 103 vlan-id 97radio enable#wlan ap autoap_0007 model WA2100 id 9radio-policy 103service-template 103 vlan-id 97radio enable#wlan ap autoap_0008 model WA2100 id 10radio 1radio-policy 103service-template 103 vlan-id 97radio enable#wlan ap autoap_0009 model WA2100 id 11radio 1radio-policy 103service-template 103 vlan-id 98radio enable#wlan ap autoap_0010 model WA2100 id 12radio 1radio-policy 103service-template 103 vlan-id 98radio enable#wlan ap autoap_0011 model WA2100 id 13radio 1radio-policy 103service-template 103 vlan-id 98radio enable#wlan ap autoap_0012 model WA2100 id 14radio 1radio-policy 103service-template 103 vlan-id 98radio enable#wlan ap autoap_0013 model WA2100 id 15radio 1radio-policy 103service-template 103 vlan-id 99wlan ap autoap_0014 model WA2100 id 16radio 1radio-policy 103service-template 103 vlan-id 99radio enable#wlan ap autoap_0018 model WA2100 id 17radio 1radio-policy 103service-template 103 vlan-id 99radio enable#wlan ap autoap_0019 model WA2100 id 18radio 1radio-policy 103service-template 103 vlan-id 99radio enable#wlan ap autoap_0020 model WA2100 id 19radio 1radio-policy 103service-template 103 vlan-id 99radio enable#undo info-center logfile enable##dhcp enable#ssh server enable#load xml-configuration#user-interface con 0user-interface vty 0 4authentication-mode schemeuser privilege level 3#return核心交换机配置文件:#version 5.20, Release 2202#sysname wirelessandvideoswitch #irf mac-address persistent timer irf auto-update enableundo irf link-delay#domain default enable system#undo ip ttl-expires#vlan 1#vlan 96description ap-client#vlan 97description ap-client#vlan 98description ap-client#description ap-client#vlan 100description ap-client#vlan 101description ap-client#vlan 102description ap-client#vlan 103description managerdevice#vlan 104description connection FW#radius scheme systemserver-type extendeduser-name-format without-domain #domain systemaccess-limit disablestate activeidle-cut disableself-service-url disable##user-group system#local-user adminpassword simple xxxxxxxxxxauthorization-attribute level 3 service-type ssh telnet#interface NULL0#interface Vlan-interface96#interface Vlan-interface97interface Vlan-interface98#interface Vlan-interface99#interface Vlan-interface100#interface Vlan-interface101#interface Vlan-interface102#interface Vlan-interface103#interface Vlan-interface104description connectionFW#interface GigabitEthernet1/0/1 #interface GigabitEthernet1/0/2 #interface GigabitEthernet1/0/3 #interface GigabitEthernet1/0/4 #interface GigabitEthernet1/0/5 #interface GigabitEthernet1/0/6 #interface GigabitEthernet1/0/7 #interface GigabitEthernet1/0/8 #interface GigabitEthernet1/0/9 #interface GigabitEthernet1/0/10 #interface GigabitEthernet1/0/11 #interface GigabitEthernet1/0/12interface GigabitEthernet1/0/13 port access vlan 103#interface GigabitEthernet1/0/14 port access vlan 103#interface GigabitEthernet1/0/15 port access vlan 103#interface GigabitEthernet1/0/16 port access vlan 103#interface GigabitEthernet1/0/17 port access vlan 103#interface GigabitEthernet1/0/18 port access vlan 103#interface GigabitEthernet1/0/19 shutdown#interface GigabitEthernet1/0/20 shutdown#interface GigabitEthernet1/0/21 #interface GigabitEthernet1/0/22 shutdown#interface GigabitEthernet1/0/23 shutdown#interface GigabitEthernet1/0/24 shutdown#interface GigabitEthernet1/0/25 port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103 shutdown#interface GigabitEthernet1/0/26 port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103 shutdown#interface GigabitEthernet1/0/27port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103#interface GigabitEthernet1/0/28port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103#interface GigabitEthernet1/0/29shutdown#interface GigabitEthernet1/0/30port access vlan 103#interface GigabitEthernet1/0/31#interface GigabitEthernet1/0/32port access vlan 104#ssh server enable#user-interface aux 0 8user-interface vty 0 4authentication-mode schemeuser privilege level 3#return配置要点:无线控制器中:创建服务模板wlan service-template 103 clearssid pubwirelessbind WLAN-ESS 103service-template enable创建无线虚接口,注意此处的vlan号要与无线ap上联的交换机端口的vlan号一致interface WLAN-ESS103port access vlan 103配置fit apwlan ap autoap_0006 model WA2100 id 8radio 1radio-policy 103service-template 103 vlan-id 97radio enable因无线客户端的数据包已经经过封装的,所以AP上联端口不用trunk,而采用access模式。

H3C WLAN网络配置与维护第3讲AC&FIT AP基础配置篇(1.0.1)

H3C WLAN网络配置与维护第3讲AC&FIT AP基础配置篇(1.0.1)

H3C WLAN网络配置与维护第三讲AC&FIT AP基础配置篇杭州华三通信技术有限公司版权所有侵权必究All rights reserved目录1 前言 32 课程目标 33 AC&FIT AP的组网方式 34 配置要点 34.1 保证FIT AP上电后可以获得IP地址 34.2 保证FIT AP得到AC的IP地址 44.3 配置AC以便AP进行注册关联 45 配置步骤 55.1 FIT AP 55.1.1 FIT AP安装 55.1.2 通过DHCP Server获得IP地址 55.1.3 得到AC的IP地址 55.2 AC 55.2.1 上传FIT AP的主机软件到AC的flash 55.2.2 配置无线接口和服务模板 55.2.3 配置AP 61 前言构建WLAN网络可以采用两种方式,一种是FAT AP模式,也就是我们常说的胖AP,FAT AP不能集中管理,只能一台一台的配置,对于无线覆盖范围有限,AP数目较少的情况比较合适。

另一种方式是采用无线控制器AC加FIT AP(瘦AP)组网,采用这种方式FIT AP 不需要配置,所有配置和版本都从AC上下载;这种方式非常便于管理和维护,对于AP大规模组网的WLAN项目是非常合适的,在运营商无线热点覆盖项目中是客户首选的方案。

2 课程目标⑴掌握FIT AP开局基本配置方法;⑵掌握FIT AP开局工程实施过程中需要注意的基本问题。

3 AC&FIT AP的组网方式AC&FIT AP的组网方式可以归结为一下三种:直连方式和二层网络连接方式在原理和工作方式上都是一样的,所以我们在配置讲解时,仅仅考虑二层组网方式即可。

而且直连方式在实际组网中应用较少,特别是AP数目较多的情况下,将所有AP和AC直接连起来是不现实的。

第三种方式是三层网络连接,这里需要考虑跨三层时如何让FIT AP得到AC的地址,以便AP向AC发起注册请求。

4 配置要点4.1 保证FIT AP上电后可以获得IP地址网络中要有一台DHCP Server,保证FIT AP上电后通过DHCP Server可以获得IP地址,这是AP向AC发起注册请求的第一个前提条件,如果AP获得地址失败,那么后面的步骤都无法进行下去。

H3C无线控制器配置

H3C无线控制器配置

H3C无线控制器配置1、配置无线空口Wlan enable无线空口的作用:无线用户连接到AP后,相当于“无线客户端”用网线连接到AC的“WLAN-ESS”端口。

配置:interface WLAN-ESS 1port access vlan 100//该VLAN 无线客户端的VLAN2、创建无线服务模板服务模板主要作用:- AP发射信号的SSID名称- 无线加密方式- 关联无线空口配置:wlan service-template 1 crypto//创建无线服务模板1ssid HBB_PXJD//设置SSIDbind WLAN-ESS 1 //绑定到无线空口1cipher-suite wep40 //选择加密方式wep default-key 1 wep40 pass-phrase simple 54321//设置密码service-template enable //启用模板3、服务模板和AP关联配置:wlan ap wa2110_300 model WA2100 //选择具体的AP型号serial-id 210235A22WB09C005077//绑定AP的SN号码radio 1 //绑定射频卡1service-template 1 //绑定服务模板1radio enable //启用射频卡AP版本切换胖切廋先传版本,再命令切换存在AC情况下,可以直接命令切换<H3C> ap-mode fit廋改胖先传版本,再命令切换<H3C> ap-mode fatAP的license添加命令格式:License append License-key activation-key显示添加的license,display license升级之前注意将设备升级的最新的版本,升级后断电重启,在输入新的license 后需要再次断电重启才能生效。

16-H3C WX系列AC+Fit AP 二层IPv4网络连接典型配置举例

16-H3C WX系列AC+Fit AP 二层IPv4网络连接典型配置举例

H3C WX系列AC+Fit AP二层IPv4网络连接典型配置举例关键词:AP,AC,二层网络摘要:AP和AC间的连接最常用的情况就是通过IPv4二层网络连接,这种连接方式易于维护,是用户最常用的组网方案,本配置举例对这类二层IPv4网络连接应用给出基本配置指导。

缩略语:缩略语英文全名中文解释无线控制器Control AC AccessPoint无线接入点AP AccessESS Extended Service Set 扩展服务集WLAN Wireless Local Area Network 无线局域网SSID Service Set Identifier 服务集识别码目录1 特性简介 (1)2 应用场合 (1)3 配置举例 (1)3.1 组网需求 (1)3.2 配置思路 (2)3.3 使用版本 (2)3.3.1 AC使用版本 (2)3.3.2 交换机使用版本 (3)3.4 配置步骤 (3)3.4.1 配置AC (3)3.4.2 配置交换机 (6)3.4.3 配置用户 (7)3.5 验证结果 (8)4 相关资料 (10)4.1 相关协议和标准 (10)4.2 其它相关资料 (10)1 特性简介AP和AC间的连接最常用的情况就是进行IPv4二层网络连接,这种连接方式易于维护,是用户最常用的组网方案。

二层网络设备间的连接无需路由设备,一般仅需要在AP和AC间使用带PoE供电功能的二层交换机。

2 应用场合用于无线局域网络组网,此时的AP和AC间不需要路由,只需要用IPv4进行二层网络连接来组网。

3 配置举例3.1 组网需求本配置举例中的AC使用的是WX5002无线控制器,AP使用的是WA2100无线局域网接入点。

z无线用户Client、有线用户PC之间通过二层互通。

z无线用户Client可以通过AP接入到AC,AP使用PoE方式由交换机供电。

z有线用户PC通过二层网络直接连接到AC。

z有线和无线用户都需要经过DHCP client的方式自动获取IP地址。

H3C AC+Fit AP典型配置案例集-6W108-AP本地转发典型配置举例

H3C AC+Fit AP典型配置案例集-6W108-AP本地转发典型配置举例
3.1 组网需求 ··············································································································································· 1 3.2 配置思路 ··············································································································································· 1 3.3 配置注意事项········································································································································ 1 3.4 配置步骤 ··············································································································································· 2
(4) 配置 WLAN-ESS 接口 # 创建 WLAN-ESS1 接口,并进入该视图。
[AC] interface wlan-ess 1
# 配置端口的链路类型为 Hybrid。
[AC-WLAN-ESS1] port link-type hybrid
# 配置 WLAN-ESS1 接口的缺省 VLAN 为 VLAN 200,禁止 VLAN 1 报文通过,并允许 VLAN 200 报文不带 VLAN tag。

H3C v7无线二层网络注册配置举例

H3C v7无线二层网络注册配置举例

二层网络注册配置举例1 组网需求如图1所示,集中式转发架构下,无线客户端Client、有线客户端Host通过L2 switch 和AC相连,L2 switch通过PoE方式给AP供电,AC做为DHCP server为AP、Client和Host分配IP地址。

需要实现无线客户端Client通过AP连接到AC上,并能与有线客户端Host互相访问。

图1 Fit AP通过二层网络注册到AC配置举例组网图2 配置关键点2.1 配置AC(1)在AC上配置相关VLAN,并放通对应接口,开启DHCP server功能,AP、无线客户端Client和有线客户端Host都能通过DHCP server自动获取IP地址。

(2)配置无线服务[AC] wlan service-template 1[AC-wlan-st-1] ssid service[AC-wlan-st-1] service-template enable(3)配置AP[AC]wlan ap ap1 model WA4320i-ACN[AC-wlan-ap-ap1] serial-id 210235A1Q2C159000018[AC-wlan-ap-ap1] radio 1[AC-wlan-ap-ap1-radio-1] service-template 1 vlan 200[AC-wlan-ap-ap1-radio-1] radio enable2.2 配置L2 switch# 创建相关VLAN,配置L2 switch和AP相连的接口为Trunk类型,PVID为AP管理VLAN,并开启PoE供电功能。

3 验证配置(1)在AC上查看AP注册信息# 在AC上使用命令display wlan ap all查看AP,可以看到AP的状态是R/M,表明AP已经成功注册到AC。

<AC> display wlan ap allTotal number of APs: 1Total number of connected APs: 1Total number of connected manual APs: 1Total number of connected auto APs: 0Total number of connected anchor APs: 0Maximum supported APs: 3072Remaining APs: 3071Fit APs activated by license: 512Remaining fit APs: 511WTUs activated by license: 2500Remaining WTUs: 2500AP informationState : I = Idle, J = Join, JA = JoinAck, IL = ImageLoadC = Config, DC = DataCheck, R = Run, M = Master, B = Backup AP name AP ID State Model Serial ID--------------------------------------------------------------------------------ap1 1 R/M WA4320i-ACN 210235A1Q2C159000018(2)在AC上查看Client信息# 在AC上使用命令display wlan client查看在线Client,可以看到Client已经连接到AP的radio1。

  1. 1、下载文档前请自行甄别文档内容的完整性,平台不提供额外的编辑、内容补充、找答案等附加服务。
  2. 2、"仅部分预览"的文档,不可在线预览部分如存在完整性等问题,可反馈申请退款(可完整预览的文档不适用该条件!)。
  3. 3、如文档侵犯您的权益,请联系客服反馈,我们会尽快为您处理(人工客服工作时间:9:00-18:30)。

一栋大楼内部组建公共无线网络,考虑到客户端数量可能众多,而客户端频繁及接入层交无线ap移动可能性不大,规划将无线客户端划分到不同的vlan内,vlan内。

网络连接示意图如下:换机划在一个无线控制器配置文件:#version 5.20, Release 2308P10#sysname wx5004#domain default enable system#port-security enable#wlan auto-ap enable#vlan 1#vlan 96description ap-client#vlan 97description ap-client#vlan 98description ap-client#vlan 99description ap-client#vlan 100description ap-client#vlan 101description ap-client#vlan 102description ap-client#vlan 103description managerdevice#domain systemaccess-limit disablestate activeidle-cut disableself-service-url disable#public-key peer 192.168.103.254public-key-code begin30819F300D06092A864886F70D3818D00308C2171D5A373DAB7E0E2B1B202AA91185612713CB3BC6CAD3557BB740D5F9CF3CA1935F20EB05B823B1CAC A18E0CC401FE26B61DDE098EE75610ACF51084980E2FCD305EE3CF30F6D5E8885F0D3BA5AD E913BCD672E038FEACBD4B3CDB9809B2E1D57B660CDCF7F50282DF5EF8D973B264191552DE 82E5C3EC3B7C9F11D54357D020*******public-key-code endpeer-public-key end#dhcp server ip-pool managernetwork 192.168.103.0 mask 255.255.255.0gateway-list 192.168.103.254expired day 7#dhcp server ip-pool pub-wireless-usenetwork 192.168.96.0 mask 255.255.248.0dns-list 211.95.193.97 211.94.33.193 8.8.8.8#.dhcp server ip-pool vlan100network 192.168.100.0 mask 255.255.255.0gateway-list 192.168.100.254#dhcp server ip-pool vlan101network 192.168.101.0 mask 255.255.255.0gateway-list 192.168.101.254#dhcp server ip-pool vlan102network 192.168.102.0 mask 255.255.255.0gateway-list 192.168.102.254#dhcp server ip-pool vlan96network 192.168.96.0 mask 255.255.255.0gateway-list 192.168.96.254#dhcp server ip-pool vlan97network 192.168.97.0 mask 255.255.255.0gateway-list 192.168.97.254#dhcp server ip-pool vlan98network 192.168.98.0 mask 255.255.255.0gateway-list 192.168.98.254#dhcp server ip-pool vlan99network 192.168.99.0 mask 255.255.255.0gateway-list 192.168.99.254#user-group systemgroup-attribute allow-guest#local-user adminpassword simple xxxxxauthorization-attribute level 3service-type ssh telnet#wlan rrmdot11a mandatory-rate 6 12 24dot11a supported-rate 9 18 36 48 54dot11b mandatory-rate 1 2dot11b supported-rate 5.5 11dot11g mandatory-rate 1 2 5.5 11dot11g supported-rate 6 9 12 18 24 36 48 54 #.wlan radio-policy 101#wlan radio-policy 103#wlan service-template 103 clearssid pubwirelessbind WLAN-ESS 103service-template enable#interface NULL0#interface Vlan-interface1#interface Vlan-interface96ip address 192.168.96.253 255.255.255.0 #interface Vlan-interface97ip address 192.168.97.253 255.255.255.0 #interface Vlan-interface98ip address 192.168.98.253 255.255.255.0 #interface Vlan-interface99ip address 192.168.99.253 255.255.255.0 #interface Vlan-interface100ip address 192.168.100.253 255.255.255.0 #interface Vlan-interface101ip address 192.168.101.253 255.255.255.0 #interface Vlan-interface102ip address 192.168.102.253 255.255.255.0 #interface Vlan-interface103ip address 192.168.103.253 255.255.255.0 #interface GigabitEthernet1/0/1port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103#interface GigabitEthernet1/0/2port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103#interface GigabitEthernet1/0/3port access vlan 101#interface GigabitEthernet1/0/4port access vlan 101#interface M-Ethernet1/0/0#interface Ten-GigabitEthernet1/0/5#interface WLAN-ESS1#interface WLAN-ESS101port access vlan 101#interface WLAN-ESS103port access vlan 103#wlan ap 3c01 model WA2100 id 2serial-id 210235A22WB095002382radio 1radio-policy 103service-template 103 vlan-id 96radio enable#wlan ap autoap model WA2100 id 1serial-id autoradio 1#wlan ap autoap_0001 model WA2100 id 3 serial-id 210235A22WB095001936radio 1radio-policy 103service-template 103 vlan-id 96radio enable#wlan ap autoap_0002 model WA2100 id 4 serial-id 210235A22WB095002528radio 1radio-policy 103service-template 103 vlan-id 96. radio enable#wlan ap autoap_0003 model WA2100 id 5 serial-id 210235A22WB095000642radio 1radio-policy 103service-template 103 vlan-id 96radio enable#wlan ap autoap_0004 model WA2100 id 6 serial-id 210235A22WB095001850radio 1radio-policy 103service-template 103 vlan-id 97radio enable#wlan ap autoap_0005 model WA2100 id 7 serial-id 210235A22WB095000518radio 1radio-policy 103service-template 103 vlan-id 97radio enable#wlan ap autoap_0006 model WA2100 id 8 serial-id 210235A22WB095001905radio 1radio-policy 103service-template 103 vlan-id 97radio enable#wlan ap autoap_0007 model WA2100 id 9 serial-id 210235A22WB095000643radio 1radio-policy 103service-template 103 vlan-id 97radio enable#wlan ap autoap_0008 model WA2100 id 10 serial-id 210235A22WB095001943radio 1radio-policy 103service-template 103 vlan-id 97radio enable#.wlan ap autoap_0009 model WA2100 id 11 serial-id 210235A22WB095000543radio 1radio-policy 103service-template 103 vlan-id 98radio enable#wlan ap autoap_0010 model WA2100 id 12 serial-id 210235A22WB095001939radio 1radio-policy 103service-template 103 vlan-id 98radio enable#wlan ap autoap_0011 model WA2100 id 13 serial-id 210235A22WB095002305radio 1radio-policy 103service-template 103 vlan-id 98radio enable#wlan ap autoap_0012 model WA2100 id 14 serial-id 210235A22WB095002496radio 1radio-policy 103service-template 103 vlan-id 98radio enable#wlan ap autoap_0013 model WA2100 id 15 serial-id 210235A22WB095002598radio 1radio-policy 103service-template 103 vlan-id 99radio enable#wlan ap autoap_0014 model WA2100 id 16 serial-id 210235A22WB095002499radio 1radio-policy 103service-template 103 vlan-id 99radio enable#wlan ap autoap_0018 model WA2100 id 17 serial-id 210235A22WB095000641.radio 1radio-policy 103service-template 103 vlan-id 99radio enable#wlan ap autoap_0019 model WA2100 id 18 serial-id 210235A22WB095001945radio 1radio-policy 103service-template 103 vlan-id 99radio enable#wlan ap autoap_0020 model WA2100 id 19serial-id 210235A22WB095001932radio 1radio-policy 103service-template 103 vlan-id 99radio enable#undo info-center log#dhcp server forbidden-ip 192.168.101.1 192.168.101.20dhcp server forbidden-ip 192.168.101.240 192.168.101.254dhcp server forbidden-ip 192.168.96.1 192.168.96.20dhcp server forbidden-ip 192.168.96.240 192.168.96.254dhcp server forbidden-ip 192.168.97.1 192.168.97.20dhcp server forbidden-ip 192.168.97.240 192.168.97.254dhcp server forbidden-ip 192.168.98.1 192.168.98.20dhcp server forbidden-ip 192.168.98.240 192.168.98.254dhcp server forbidden-ip 192.168.99.1 192.168.99.20dhcp server forbidden-ip 192.168.99.240 192.168.99.254dhcp server forbidden-ip 192.168.100.1 192.168.100.20dhcp server forbidden-ip 192.168.100.240 192.168.100.254dhcp server forbidden-ip 192.168.102.1 192.168.102.20dhcp server forbidden-ip 192.168.102.240 192.168.102.254dhcp server forbidden-ip 192.168.103.1 192.168.103.20dhcp server forbidden-ip 192.168.103.240 192.168.103.254#dhcp enable#ssh server enablessh client authentication server 192.168.103.254 assign publickey 192.168.103.254#.load xml-configuration#user-interface con 0user-interface vty 0 4 authentication-mode scheme user privilege level 3#return核心交换机配置文件:#version 5.20, Release 2202#sysname wirelessandvideoswitch#irf mac-address persistent timerirf auto-update enableundo irf link-delay#domain default enable system#undo ip ttl-expires#vlan 1#vlan 96description ap-client#vlan 97description ap-client#vlan 98description ap-client#vlan 99description ap-client#vlan 100description ap-client#.vlan 101 description ap-client#vlan 102 description ap-client#vlan 103 description managerdevice#vlan 104 description connection FW# radius scheme system server-type extended primary authentication 127.0.0.1 1645primary accounting 127.0.0.1 1646user-name-format without-domain#domain systemaccess-limit disablestate activeidle-cut disableself-service-url disable##user-group system#local-user adminpassword simple xxxxxxxxxxauthorization-attribute level 3service-type ssh telnet#interface NULL0#interface Vlan-interface96ip address 192.168.96.254 255.255.255.0#interface Vlan-interface97ip address 192.168.97.254 255.255.255.0#interface Vlan-interface98ip address 192.168.98.254 255.255.255.0 #.interface Vlan-interface99ip address 192.168.99.254 255.255.255.0#interface Vlan-interface100ip address 192.168.100.254 255.255.255.0 #interface Vlan-interface101ip address 192.168.101.254 255.255.255.0 #interface Vlan-interface102ip address 192.168.102.254 255.255.255.0 #interface Vlan-interface103ip address 192.168.103.254 255.255.255.0 #interface Vlan-interface104description connectionFWip address 192.168.255.221 255.255.255.252 #interface GigabitEthernet1/0/1#interface GigabitEthernet1/0/2#interface GigabitEthernet1/0/3#interface GigabitEthernet1/0/4#interface GigabitEthernet1/0/5#interface GigabitEthernet1/0/6#interface GigabitEthernet1/0/7#interface GigabitEthernet1/0/8#interface GigabitEthernet1/0/9#interface GigabitEthernet1/0/10#interface GigabitEthernet1/0/11#interface GigabitEthernet1/0/12#interface GigabitEthernet1/0/13. port access vlan 103#interface GigabitEthernet1/0/14port access vlan 103#interface GigabitEthernet1/0/15port access vlan 103#interface GigabitEthernet1/0/16port access vlan 103#interface GigabitEthernet1/0/17port access vlan 103#interface GigabitEthernet1/0/18port access vlan 103#interface GigabitEthernet1/0/19shutdown#interface GigabitEthernet1/0/20shutdown#interface GigabitEthernet1/0/21#interface GigabitEthernet1/0/22shutdown#interface GigabitEthernet1/0/23shutdown#interface GigabitEthernet1/0/24shutdown#interface GigabitEthernet1/0/25port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103shutdown#interface GigabitEthernet1/0/26port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103.shutdown#interface GigabitEthernet1/0/27 port link-type trunk undo port trunk permit vlan 1 port trunk permit vlan 96 to 103# interface GigabitEthernet1/0/28port link-type trunkundo port trunk permit vlan 1port trunk permit vlan 96 to 103#interface GigabitEthernet1/0/29shutdown#interface GigabitEthernet1/0/30port access vlan 103#interface GigabitEthernet1/0/31#interface GigabitEthernet1/0/32port access vlan 104#ssh server enablessh client authentication server assign publickey 192.168.103.253 192.168.103.253192.168.103.254 publickey ssh client authentication server assign192.168.103.254#user-interface aux 0 8user-interface vty 0 4 authentication-mode schemeuser privilege level 3#return配置要点:无线控制器中:创建服务模板wlan service-template 103 clear ssid pubwireless bind WLAN-ESS 103 service-template enable号vlanvlan号要与无线ap上联的交换机端口的创建无线虚接口,注意此处的一致interface WLAN-ESS103 port access vlan 103fit ap配置wlan ap autoap_0006 model WA2100 id 8 serial-id210235A22WB095001905 radio 1 radio-policy 103 service-template 103 vlan-id 97 radio enable,而采用trunkAP上联端口不用因无线客户端的数据包已经经过封装的,所以模式。

相关文档
最新文档