H3C AC WLAN配置本地轉發(V7)


Switch作為DHCP服務器為APClient分配IP地址。現要求:在AC上配置本地轉發功能,使Client的數據流量不經過AC,直接由AP轉發

 

 

 1、配置思路:

為了將APGigabitEthernet1/0/1接口加入本地轉發的VLAN 200,需要AC下發map-configuration文件。

2、配置步驟:

2.1、apcfg.txt的配置:

apcfg.txt的內容,要求為文本文件,按照命令行配置的順序編寫文本文件上傳至AC即可,ACAP關聯后,通過map-configuration命令下發至AP生效。從而完成對AP的配置。

# apcfg.txt配置文件為:
system-view
vlan 200
quit
interface GigabitEthernet 1/0/1
port link-type trunk
port trunk permit vlan 200

 2.2、配置AC

①配置AC的接口:

創建VLAN 100及其對應的VLAN接口,並為該接口配置IP地址。AP將獲取該IP地址與AC建立CAPWAP隧道。

system-view
[AC] vlan 100
[AC-vlan100] quit
[AC] interface vlan-interface 100
[AC-Vlan-interface100] ip address 192.1.1.1 16
[AC-Vlan-interface100] quit

 ②配置無線服務:

創建無線服務模板1,並進入無線服務模板視圖。

[AC] wlan service-template 1

 配置SSIDservice

[AC-wlan-st-1] ssid service

 配置本地轉發模式,開啟VLAN 200的本地轉發功能。

[AC-wlan-st-1] client forwarding-location ap vlan 200

 開啟無線服務模板。

[AC-wlan-st-1] service-template enable
[AC-wlan-st-1] quit

 ③配置AP

創建手工AP,名稱為officeap,型號名稱為WA4320i-ACN

[AC] wlan ap officeap model WA4320i-ACN

 設置AP序列號為219801A0T78159E09083

[AC-wlan-ap-officeap] serial-id 219801A0T78159E09083

 進入APRadio 2視圖,並將無線服務模板1綁定到Radio 2上。

[AC-wlan-ap-officeap] radio 2
[AC-wlan-ap-officeap-radio-2] service-template 1 vlan 200

 開啟Radio 2的射頻功能。

[AC-wlan-ap-officeap-radio-2] radio enable
[AC-wlan-ap-officeap-radio-2] quit

 ④配置AP的配置文件

AC上將配置文件apcfg.txt下發到AP

[AC-wlan-ap-officeap] map-configuration apcfg.txt
[AC-wlan-ap-officeap] quit

 2.3、交換機配置

①配置交換機接口

創建VLAN 100VLAN 200及其對應接口,並為該接口配置IP地址,其中VLAN 100用於轉發ACAPCAPWAP隧道內的流量VLAN 200用於轉發Client無線報文

system-view
[Switch] vlan 100
[Switch-vlan100] quit
[Switch] interface vlan-interface 100
[Switch-Vlan-interface100] ip address 192.1.1.2 16
[Switch-Vlan-interface100] quit
[Switch] vlan 200
[Switch-vlan200] quit
[Switch] interface vlan-interface 200
[Switch-Vlan-interface200] ip address 192.2.1.2 24
[Switch-Vlan-interface200] quit

 配置SwitchAC相連的接口GigabitEthernet1/0/1Trunk類型,禁止VLAN 1報文通過,當前Trunk口的PVID100

[Switch] interface GigabitEthernet 1/0/1
[Switch-GigabitEthernet1/0/1] port link-type trunk
[Switch-GigabitEthernet1/0/1] undo port trunk permit vlan 1
[Switch-GigabitEthernet1/0/1] port trunk pvid vlan 100
[Switch-GigabitEthernet1/0/1] quit

 配置SwitchAP相連的接口GigabitEthernet1/0/2Trunk類型,禁止VLAN 1報文通過,允許VLAN 100VLAN 200通過,當前Trunk口的PVID100

[Switch] interface GigabitEthernet 1/0/2
[Switch-GigabitEthernet1/0/2] port link-type trunk
[Switch-GigabitEthernet1/0/2] undo port trunk permit vlan 1
[Switch-GigabitEthernet1/0/2] port trunk permit vlan 100 200
[Switch-GigabitEthernet1/0/2] port trunk pvid vlan 100

 開啟SwitchAP相連的接口GigabitEthernet1/0/2PoE供電功能。

[Switch-GigabitEthernet1/0/2] poe enable
[Switch-GigabitEthernet1/0/2] quit

 ②配置DHCP服務

開啟DHCP功能。

[Switch] dhcp enable

 創建名為vlan100DHCP地址池,配置地址池動態分配的網段為192.1.0.0/16,網關地址為192.1.1.2,為AP分配IP地址。

[Switch] dhcp server ip-pool vlan100
[Switch-dhcp-pool-vlan100] network 192.1.0.0 mask 255.255.0.0
[Switch-dhcp-pool-vlan100] forbidden-ip 192.1.1.1
[Switch-dhcp-pool-vlan100] gateway-list 192.1.1.2
[Switch-dhcp-pool-vlan100] quit

 創建名為vlan200DHCP地址池,配置地址池動態分配的網段為192.2.1.0/24,網關地址為192.2.1.2,為Client分配IP地址。

[Switch] dhcp server ip-pool vlan200
[Switch-dhcp-pool-vlan200] network 192.2.1.0 mask 255.255.255.0
[Switch-dhcp-pool-vlan200] forbidden-ip 192.2.1.1
[Switch-dhcp-pool-vlan200] gateway-list 192.2.1.2
[Switch-dhcp-pool-vlan200] quit

 2.4、驗證配置

# Client1Client2上線獲取到地址分別是192.2.1.3192.2.1.4,通過抓包可以發現ICMP報文不需要經過ACAP間的隧道封裝,直接轉發。

 附:AC的配置:

#
Vlan 100
#
vlan 200
#
wlan service-template 1
 ssid service
 client forwarding-location ap vlan 200
 service-template enable
#
interface Vlan-interface100
 ip address 192.1.1.1 255.255.0.0
#
wlan ap officeap model WA4320i-ACN
 map-configuration flash:/apcfg.txt
 serial-id 219801A0T78159E09083
 radio 1
 radio 2
  radio enable
  service-template 1 vlan 200
#

 附:交換機配置文件:

#
 dhcp enable
#
vlan 100
#
vlan 200
#
dhcp server ip-pool vlan100
 gateway-list 192.1.1.2
 network 192.1.0.0 mask 255.255.0.0
 forbidden-ip 192.1.1.1
#
dhcp server ip-pool vlan200
gateway-list 192.2.1.2
 network 192.2.1.0 mask 255.255.255.0
 forbidden-ip 192.2.1.1
#
interface Vlan-interface100
 ip address 192.1.1.2 255.255.0.0
#
interface Vlan-interface200
 ip address 192.2.1.2 255.255.255.0
#
interface GigabitEthernet1/0/1
 port link-mode bridge
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk pvid vlan 100
#
interface GigabitEthernet1/0/2
 port link-mode bridge
 port link-type trunk
 undo port trunk permit vlan 1
 port trunk permit vlan 100 200
 port trunk pvid vlan 100
#

注意:

  1. map-configuration文件的命令行后面不要出現Tab或者空格,否則會出現該行配置不成功的情況。
  2. AP的配置需要根據具體AP的型號和序列號進行配置。

本文源自:https://zhiliao.h3c.com/Theme/details/7284


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM