组网图形
配置项 | 数据 |
---|---|
DHCP服务器 | AC作为DHCP服务器为STA和AP分配IPv4和IPv6地址 |
AP的IP地址池 | IPv4地址池:10.23.100.2~10.23.100.254/24 IPv6地址池:FC01::2~FC01::FFFF:FFFF:FFFF:FFFF/64 |
STA的IP地址池 | IPv4地址池:10.23.101.2~10.23.101.254/24 IPv6地址池:FC02::2~FC01::FFFF:FFFF:FFFF:FFFF/64 |
AC的源接口IP地址 | IPv4源接口,VLANIF100:10.23.100.1/24 IPv6源接口,VLANIF200:FC01::1/64 |
AP组 |
|
域管理模板 |
|
SSID模板 |
|
安全模板 |
|
VAP模板 |
|
建议在与AP直连的设备接口上配置端口隔离,如果不配置端口隔离,尤其是业务数据转发方式采用直接转发时,可能会在VLAN内形成大量不必要的广播报文,导致网络阻塞,影响用户体验。
隧道转发模式下,管理VLAN和业务VLAN不能配置为同一VLAN,且AP和AC之间只能放通管理VLAN,不能放通业务VLAN。
system-view - [HUAWEI] sysname SwitchA
- [SwitchA] vlan batch 100 200
- [SwitchA] interface gigabitethernet 0/0/1
- [SwitchA-GigabitEthernet0/0/1] port link-type trunk
- [SwitchA-GigabitEthernet0/0/1] port trunk pvid vlan 100
- [SwitchA-GigabitEthernet0/0/1] port trunk allow-pass vlan 100
- [SwitchA-GigabitEthernet0/0/1] port-isolate enable
- [SwitchA-GigabitEthernet0/0/1] quit
- [SwitchA] interface gigabitethernet 0/0/2
- [SwitchA-GigabitEthernet0/0/2] port link-type trunk
- [SwitchA-GigabitEthernet0/0/2] port trunk pvid vlan 200
- [SwitchA-GigabitEthernet0/0/2] port trunk allow-pass vlan 200
- [SwitchA-GigabitEthernet0/0/2] port-isolate enable
- [SwitchA-GigabitEthernet0/0/2] quit
- [SwitchA] interface gigabitethernet 0/0/3
- [SwitchA-GigabitEthernet0/0/3] port link-type trunk
- [SwitchA-GigabitEthernet0/0/3] port trunk allow-pass vlan 100 200
- [SwitchA-GigabitEthernet0/0/3] quit
system-view - [Huawei] sysname Router
- [Router] ipv6
- [Router] vlan batch 101
- [Router] interface gigabitethernet 1/0/0
- [Router-GigabitEthernet1/0/0] port link-type trunk
- [Router-GigabitEthernet1/0/0] port trunk allow-pass vlan 101
- [Router-GigabitEthernet1/0/0] quit
- [Router] interface vlanif 101
- [Router-Vlanif101] ip address 10.23.101.2 24
- [Router-Vlanif101] ipv6 enable
- [Router-Vlanif101] ipv6 address fc02::2/64
- [Router-Vlanif101] quit
system-view - [HUAWEI] sysname AC
- [AC] vlan batch 100 101 200
- [AC] interface gigabitethernet 0/0/1
- [AC-GigabitEthernet0/0/1] port link-type trunk
- [AC-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 200
- [AC-GigabitEthernet0/0/1] quit
- [AC] interface gigabitethernet 0/0/2
- [AC-GigabitEthernet0/0/2] port link-type trunk
- [AC-GigabitEthernet0/0/2] port trunk allow-pass vlan 101
- [AC-GigabitEthernet0/0/2] quit
- [AC] dhcp enable
- [AC] interface vlanif 100
- [AC-Vlanif100] ip address 10.23.100.1 24
- [AC-Vlanif100] dhcp select interface
- [AC-Vlanif100] quit
- [AC] ipv6
- [AC] dhcp enable
- [AC] dhcpv6 pool ap_pool
- [AC-dhcpv6-pool-ap_pool] address prefix fc01::/64
- [AC-dhcpv6-pool-ap_pool] quit
- [AC] interface vlanif 200
- [AC-Vlanif200] ipv6 enable
- [AC-Vlanif200] ipv6 address fc01::1/64
- [AC-Vlanif200] undo ipv6 nd ra halt
- [AC-Vlanif200] ipv6 nd autoconfig managed-address-flag
- [AC-Vlanif200] ipv6 nd autoconfig other-flag
- [AC-Vlanif200] dhcpv6 server ap_pool
- [AC-Vlanif200] quit
- [AC] dhcpv6 pool sta_pool
- [AC-dhcpv6-pool-sta_pool] address prefix fc02::/64
- [AC-dhcpv6-pool-sta_pool] quit
- [AC] interface vlanif 101
- [AC-Vlanif101] ipv6 enable
- [AC-Vlanif101] ip address 10.23.101.1 24
- [AC-Vlanif101] dhcp select interface
- [AC-Vlanif101] ipv6 address fc02::1/64
- [AC-Vlanif101] undo ipv6 nd ra halt
- [AC-Vlanif101] ipv6 nd autoconfig managed-address-flag
- [AC-Vlanif101] ipv6 nd autoconfig other-flag
- [AC-Vlanif101] dhcpv6 server sta_pool
- [AC-Vlanif101] quit
- [AC] wlan
- [AC-wlan-view] ap-group name ap-group_ipv4
- [AC-wlan-ap-group-ap-group_ipv4] ap ip version ipv4
- Warning: This operation may cause AP offline, Whether to continue? [Y/N]:y
- [AC-wlan-ap-group-ap-group_ipv4] quit
- [AC-wlan-view] ap-group name ap-group_ipv6
- [AC-wlan-ap-group-ap-group_ipv6] ap ip version ipv6
- Warning: This operation may cause AP offline, Whether to continue? [Y/N]:y
- [AC-wlan-ap-group-ap-group_ipv6] quit
- [AC-wlan-view] regulatory-domain-profile name default
- [AC-wlan-regulate-domain-default] country-code cn
- [AC-wlan-regulate-domain-default] quit
- [AC-wlan-view] ap-group name ap-group_ipv4
- [AC-wlan-ap-group-ap-group_ipv4] regulatory-domain-profile default
- Warning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continue?[Y/N]:y
- [AC-wlan-ap-group-ap-group_ipv4] quit
- [AC-wlan-view] ap-group name ap-group_ipv6
- [AC-wlan-ap-group-ap-group_ipv6] regulatory-domain-profile default
- Warning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continue?[Y/N]:y
- [AC-wlan-ap-group-ap-group_ipv6] quit
- [AC-wlan-view] quit
- [AC] capwap double-stack enable
- [AC] capwap source interface vlanif 100
- [AC] capwap source interface vlanif 200
ap auth-mode命令缺省情况下为MAC认证,如果之前没有修改其缺省配置,可以不用执行ap auth-mode mac-auth。
举例中使用的AP为AP5030DN,具有射频0和射频1两个射频。AP5030DN的射频0为2.4GHz射频,射频1为5GHz射频。
- [AC] wlan
- [AC-wlan-view] ap auth-mode mac-auth
- [AC-wlan-view] ap-id 0 ap-mac dcd2-fcf6-76a0
- [AC-wlan-ap-0] ap-name ap1
- Warning: This operation may cause AP reset. Continue? [Y/N]:y
- [AC-wlan-ap-0] ap-group ap-group_ipv4
- Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configuration s of the radio, Whether to continue? [Y/N]:y
- [AC-wlan-ap-0] quit
- [AC-wlan-view] ap-id 1 ap-mac 60de-4476-e360
- [AC-wlan-ap-1] ap-name ap2
- Warning: This operation may cause AP reset. Continue? [Y/N]:y
- [AC-wlan-ap-1] ap-group ap-group_ipv6
- Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configuration s of the radio, Whether to continue? [Y/N]:y
- [AC-wlan-ap-1] quit
# 将AP上电后,当执行命令display ap all查看到AP的“State”字段为“nor”时,表示AP正常上线。
- [AC-wlan-view] display ap all
- Total AP information:
- nor : normal [2]
- Extrainfo : Extra information
- P : insufficient power supply
- ----------------------------------------------------------------------------------------------------
- ID MAC Name Group IP Type State STA Uptime ExtraInfo
- ----------------------------------------------------------------------------------------------------
- 0 dcd2-fcf6-76a0 ap1 ap-group_ipv4 10.23.100.138 AP5030DN nor 0 4H:49M:11S P
- 1 60de-4476-e360 ap2 ap-group_ipv6 FC01::9 AP5030DN nor 0 6H:3M:40S -
- ----------------------------------------------------------------------------------------------------
- Total: 2, printed: 2
[AC-wlan-view] sta-ipv6-service enable
举例中以配置WPA-WPA2+PSK+AES的安全策略为例,密码为“a1234567”,实际配置中请根据实际情况,配置符合实际要求的安全策略。
- [AC-wlan-view] security-profile name wlan-net
- [AC-wlan-sec-prof-wlan-net] security wpa-wpa2 psk pass-phrase a1234567 aes
- [AC-wlan-sec-prof-wlan-net] quit
- [AC-wlan-view] ssid-profile name wlan-net
- [AC-wlan-ssid-prof-wlan-net] ssid wlan-net
- [AC-wlan-ssid-prof-wlan-net] quit
- [AC-wlan-view] vap-profile name wlan-net
- [AC-wlan-vap-prof-wlan-net] forward-mode tunnel
- [AC-wlan-vap-prof-wlan-net] service-vlan vlan-id 101
- [AC-wlan-vap-prof-wlan-net] security-profile wlan-net
- [AC-wlan-vap-prof-wlan-net] ssid-profile wlan-net
- [AC-wlan-vap-prof-wlan-net] quit
- [AC-wlan-view] ap-group name ap-group_ipv4
- [AC-wlan-ap-group-ap-group_ipv4] vap-profile wlan-net wlan 1 radio 0
- [AC-wlan-ap-group-ap-group_ipv4] vap-profile wlan-net wlan 1 radio 1
- [AC-wlan-ap-group-ap-group_ipv4] quit
- [AC-wlan-view] ap-group name ap-group_ipv6
- [AC-wlan-ap-group-ap-group_ipv6] vap-profile wlan-net wlan 1 radio 0
- [AC-wlan-ap-group-ap-group_ipv6] vap-profile wlan-net wlan 1 radio 1
- [AC-wlan-ap-group-ap-group_ipv6] quit
WLAN业务配置会自动下发给AP,配置完成后,通过执行命令display vap ssid wlan-net查看如下信息,当“Status”项显示为“ON”时,表示AP对应的射频上的VAP已创建成功。
- [AC-wlan-view] display vap ssid wlan-net
- WID : WLAN ID
- -------------------------------------------------------------------------------------
- AP ID AP name RfID WID BSSID Status Auth type STA SSID
- -------------------------------------------------------------------------------------
- 1 ap1 0 1 DCD2-FCF6-76A0 ON WPA/WPA2-PSK 0 wlan-net
- 1 ap1 1 1 DCD2-FCF6-76B0 ON WPA/WPA2-PSK 0 wlan-net
- 2 ap2 0 1 60DE-4474-E360 ON WPA/WPA2-PSK 0 wlan-net
- 2 ap2 1 1 60DE-4474-E370 ON WPA/WPA2-PSK 0 wlan-net
- -------------------------------------------------------------------------------------
- Total: 4
- [AC-wlan-view] display station ssid wlan-net
- Rf/WLAN: Radio ID/WLAN ID
- Rx/Tx: link receive rate/link transmit rate(Mbps)
- ------------------------------------------------------------------------------------------------------------------------------------------------
- STA MAC AP ID Ap name Rf/WLAN Band Type Rx/Tx RSSI VLAN IPv4 address SSID IPv6 address
- ------------------------------------------------------------------------------------------------------------------------------------------------
- 508f-4cfb-0556 1 ap1 1/1 5G - -/- - 101 10.23.101.164 wlan-net FC02::A48F:A256:29D:8841
- c894-bbdc-99ae 2 ap2 1/1 5G - -/- - 101 10.23.101.204 wlan-net FC02::7057:14F:2211:7FA0
- ------------------------------------------------------------------------------------------------------------------------------------------------
- Total: 2 2.4G: 0 5G: 2
- #
- sysname SwitchA
- #
- vlan batch 100 200
- #
- interface GigabitEthernet0/0/1
- port link-type trunk
- port trunk pvid vlan 100
- port trunk allow-pass vlan 100
- port-isolate enable group 1
- #
- interface GigabitEthernet0/0/2
- port link-type trunk
- port trunk pvid vlan 200
- port trunk allow-pass vlan 200
- port-isolate enable group 1
- #
- interface GigabitEthernet0/0/3
- port link-type trunk
- port trunk allow-pass vlan 100 200
- #
- return
- #
- sysname AC
- #
- ipv6
- #
- vlan batch 100 to 101 200
- #
- dhcp enable
- #
- dhcpv6 pool ap_pool
- address prefix FC01::/64
- #
- dhcpv6 pool sta_pool
- address prefix FC02::/64
- #
- interface Vlanif100
- ip address 10.23.100.1 255.255.255.0
- dhcp select interface
- #
- interface Vlanif101
- ipv6 enable
- ip address 10.23.101.1 255.255.255.0
- ipv6 address FC02::1/64
- undo ipv6 nd ra halt
- ipv6 nd autoconfig managed-address-flag
- ipv6 nd autoconfig other-flag
- dhcp select interface
- dhcpv6 server sta_pool
- dhcp server excluded-ip-address 10.23.101.2
- #
- interface Vlanif200
- ipv6 enable
- ipv6 address FC01::1/64
- undo ipv6 nd ra halt
- ipv6 nd autoconfig managed-address-flag
- ipv6 nd autoconfig other-flag
- dhcpv6 server ap_pool
- #
- interface GigabitEthernet0/0/1
- port link-type trunk
- port trunk allow-pass vlan 100 200
- #
- interface GigabitEthernet0/0/2
- port link-type trunk
- port trunk allow-pass vlan 101
- #
- capwap double-stack enable
- capwap source interface vlanif100
- capwap source interface vlanif200
- #
- wlan
- sta-ipv6-service enable
- security-profile name wlan-net
- security wpa-wpa2 psk pass-phrase %^%#m"tz0f>~7.[`^6RWdzwCy16hJj/Mc!,}s`X*B]}A%^%# aes
- ssid-profile name wlan-net
- ssid wlan-net
- vap-profile name wlan-net
- forward-mode tunnel
- service-vlan vlan-id 101
- ssid-profile wlan-net
- security-profile wlan-net
- regulatory-domain-profile name default
- ap-group name ap-group_ipv4
- ap ip version ipv4
- radio 0
- vap-profile wlan-net wlan 1
- radio 1
- vap-profile wlan-net wlan 1
- ap-group name ap-group_ipv6
- ap ip version ipv6
- radio 0
- vap-profile wlan-net wlan 1
- radio 1
- vap-profile wlan-net wlan 1
- ap-id 0 type-id 35 ap-mac dcd2-fcf6-76a0 ap-sn 2102351KDVW0JB015457
- ap-name ap1
- ap-group ap-group_ipv4
- ap-id 1 type-id 35 ap-mac 60de-4476-e360 ap-sn 21500831023GH9001248
- ap-name ap2
- ap-group ap-group_ipv6
- #
- return