企業內部AC旁掛式組網(簡單)

VLAN規划表
| VLAN ID | IP地址段 | 用途 |
|---|---|---|
| VLAN 10 | 172.16.10.0/28 | ISP對接 |
| VLAN 100 | 10.1.100.0/24 | 設備管理 |
| VLAN 101 | 10.1.101.0/24 | 無線 |
| VLAN 200 | 10.1.200.0/24 | AC |
端口規划表
| 本端設備 | 端口號 | 端口類型 | 對端設備 | 對端接口 |
|---|---|---|---|---|
| core_SW | GE0/0/1 | Access | ISP | GE0/0/0 |
| core_SW | GE0/0/2 | Trunk | AC | GE0/0/1 |
| core_SW | GE0/0/3 | Trunk | access_SW | GE0/0/1 |
| core_SW | GE0/0/4 | Trunk | outdoor_AP | GE0/0/0 |
項目實施
一、配置IP地址和所屬VLAN
core_SW的配置
[core_SW]vlan batch 10 100 to 101 200
Info: This operation may take a few seconds. Please wait for a moment...done.
#
[core_SW]interface Vlanif10
[core_SW-Vlanif10]ip address 172.16.10.1 255.255.255.240
#
[core_SW]interface Vlanif100
[core_SW-Vlanif100]ip address 10.1.100.254 255.255.255.0
#
[core_SW]interface Vlanif101
[core_SW-Vlanif101]ip address 10.1.101.254 255.255.255.0
#
[core_SW]nterface Vlanif200
[core_SW-Vlanif200]ip address 10.1.200.2 255.255.255.0
#
[core_SW]port-group group-member g0/0/3 to g0/0/4
[core_SW-port-group]port link-type trunk
[core_SW-GigabitEthernet0/0/3]port link-type trunk
[core_SW-GigabitEthernet0/0/4]port link-type trunk
[core_SW-port-group]port trunk allow-pass vlan all
[core_SW-GigabitEthernet0/0/3]port trunk allow-pass vlan all
[core_SW-GigabitEthernet0/0/4]port trunk allow-pass vlan all
[core_SW-port-group]port trunk pvid vlan 100
[core_SW-GigabitEthernet0/0/3]port trunk pvid vlan 100
[core_SW-GigabitEthernet0/0/4]port trunk pvid vlan 100
[core_SW]interface g0/0/2
[core_SW-GigabitEthernet0/0/2]port link-type trunk
[core_SW-GigabitEthernet0/0/2]port trunk allow-pass vlan all
AC的配置
[AC6005]vlan 200
#
[AC6005]interface Vlanif200
[AC6005-Vlanif200]ip address 10.1.200.1 255.255.255.0
#
[AC6005]interface g0/0/1
[AC6005-GigabitEthernet0/0/2]port link-type trunk
[AC6005-GigabitEthernet0/0/2]port trunk allow-pass vlan all
ISP的配置
[ISP]valn 10
#
[ISP]interface GigabitEthernet0/0/0
[ISP-GigabitEthernet0/0/0]ip address 172.16.10.2 255.255.255.240
[ISP]interface lookback 0
[ISP-LoopBack0]ip address 114.114.114.114 32
二、DHCP服務的配置
[core_SW]ip pool sta
[core_SW-ip-pool-sta]gateway-list 10.1.101.254
[core_SW-ip-pool-sta]network 10.1.101.0 mask 255.255.255.0
[core_SW-ip-pool-sta]dns-list 114.114.114.114
#
[core_SW]ip pool work
[core_SW-ip-pool-work]gateway-list 10.1.100.254
[core_SW-ip-pool-work]network 10.1.100.0 mask 255.255.255.0
[core_SW-ip-pool-work]dns-list 114.114.114.114
[core_SW-ip-pool-work] option 43 sub-option 2 ip-address 10.1.200.1
#
[core_SW]interface Vlanif100
[core_SW-Vlanif100]ip address 10.1.100.254 255.255.255.0
[core_SW-Vlanif100]dhcp select global
#
[core_SW]interface Vlanif101
[core_SW-Vlanif101]ip address 10.1.101.254 255.255.255.0
[core_SW-Vlanif101]dhcp select global
三、靜態路由配置
core_SW
[core_SW]ip route-static 0.0.0.0 0.0.0.0 172.16.10.2
ISP
[ISP]ip route-static 0.0.0.0 0.0.0.0 172.16.10.1
AC
[AC6005]ip route-static 10.1.100.0 255.255.255.0 10.1.200.2
四、配置AC無線控制器,上線AP無線接入點
配置ap-group組
[AC6005]wlan
[AC6005-wlan-view]ap-group NAME FLOW #配置AP組,將AP集中管理
[AC6005-wlan-view]regulatory-domain-profile name CN #配置監管提議
[AC6005-wlan-regulate-domain-CN] country-code CN #配置國家代碼,限制AP信號發射強度符合設定國家標准
[AC6005-wlan-regulate-domain-CN]q
[AC6005-wlan-view]ap-group NAME FLOW
[AC6005-wlan-ap-group-FLOW]regulatory-domain-profile CN #應用監管提議
AP上線
[AC6005]capwap source interface vlanif200 #配置CAPWAP,用於與AP相連的接口
[AC6005-wlan-view]ap auth-mode mac-auth #配置ap認證方式,默認是MAC
#
[AC6005-wlan-view]ap-id 1 ap-mac HHHH-HHHH-HHHH
[AC6005-wlan-ap-1]ap-name indoor_AP #配置ap的名字
[AC6005-wlan-ap-1]ap-group FLOW #配置ap的組
#
[AC6005-wlan-view]ap-id 2 ap-mac HHHH-HHHH-HHHH
[AC6005-wlan-ap-2]ap-name outdoor_AP #配置ap的名字
[AC6005-wlan-ap-2]ap-group FLOW #配置ap的組
配置無線網提議
[AC6005-wlan-view]ssid-profile name 406-WLAN #配置無線策略
[AC6005-wlan-ssid-prof-406-WLAN]ssid 406 #配置無線名稱
#
[AC6005-wlan-view]security-profile name 406-WLAN #配置無線密碼策略
[AC6005-wlan-sec-prof-VS-wlan]security wpa-wpa2 psk pass-phrase huawei@406 aes
#
[AC6005-wlan-view]vap-profile name 406-WLAN #配置綜合策略
[AC6005-wlan-vap-prof-406-WLAN]forward-mode direct-forward
[AC6005-wlan-vap-prof-406-WLAN]service-vlan vlan-id 101
[AC6005-wlan-vap-prof-406-WLAN]ssid-profile 406-WLAN
[AC6005-wlan-vap-prof-406-WLAN]security-profile 406-WLAN
效果
1、AP-上線效果
[AC6005-wlan-view]di ap all
Info: This operation may take a few seconds. Please wait for a moment.done.
Total AP information:
nor : normal [2]
--------------------------------------------------------------------------------
----------------
ID MAC Name Group IP Type State STA Upti
me
--------------------------------------------------------------------------------
----------------
1 00e0-fcf8-70e0 indoor_AP FLOW 10.1.100.252 AP4050DN-E nor 0 1H:7
M:7S
2 00e0-fc80-0800 outdoor_AP FLOW 10.1.100.251 AP5030DN nor 1 1H:7
M:11S
--------------------------------------------------------------------------------
----------------
Total: 2
2、wlan網絡的效果


該實驗為2021網絡工程師下半年試題一,參照於該視頻學習
學習中使用的鏈接:
- [1] :https://support.huawei.com/enterprise/zh/doc/EDOC1100201714
- [2] :https://support.huawei.com/enterprise/zh/doc/EDOC1100096314/f1bce588
- [3] :https://support.huawei.com/enterprise/zh/doc/EDOC1100096314/3746f875
- [4] :https://support.huawei.com/enterprise/zh/doc/EDOC1100096306/92dc0646
- [5] :https://support.huawei.com/enterprise/zh/doc/EDOC1100096315/604a0c9c
- [6] :https://max.book118.com/html/2017/0524/108870416.shtm
