

图1 配置直连二层组网直接转发示例组网图

企业用户通过 WLAN 接入网络,以满足移动办公的基本需求,并且在覆盖区域内发生漫游时,不影响用户业务使用。
配置项 | 数据 |
|---|---|
AP管理VLAN | VLAN100 |
STA业务VLAN | VLAN101 |
DHCP服务器 | AC |
AP地址池 | 10.23.100.2~10.23.100.254/24 |
STA地址池 | 10.23.101.3~10.23.101.254/24 |
AC接口IP | VLANIF100:10.23.100.1/24 |
capwap dtls no-auth enable
undo capwap dtls no-auth enable
system-view
sysname Switch
vlan batch 100 101
interface GigabitEthernet0/0/1
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100 101
port-isolate enable
quit
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 100 101
quit
system-view
sysname Router
vlan batch 101
interface GigabitEthernet1/0/0
port link-type trunk
port trunk allow-pass vlan 101
quit
interface Vlanif101
ip address 10.23.101.2 24
quit
system-view
sysname AC
vlan batch 100 101
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 100 101
quit
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 101
quit
dhcp enable
interface Vlanif100
ip address 10.23.100.1 24
dhcp select interface
quit
interface Vlanif101
ip address 10.23.101.1 24
dhcp select interface
dhcp server excluded-ip-address 10.23.101.2
quit
ip route-static 0.0.0.0 0.0.0.0 10.23.101.2
wlan
ap-group name ap-group1
regulatory-domain-profile name default
country-code cn
ap-group name ap-group1
regulatory-domain-profile default
capwap source interface vlanif 100
capwap dtls no-auth enable
wlan
ap auth-mode mac-auth
ap-id 0 ap-mac 60de-4476-e360
ap-name area_1
ap-group ap-group1
security-profile name wlan-net
security wpa-wpa2 psk pass-phrase a1234567 aes
ssid-profile name wlan-net
ssid wlan-net
vap-profile name wlan-net
forward-mode direct-forward
service-vlan vlan-id 101
security-profile wlan-net
ssid-profile wlan-net
ap-group name ap-group1
vap-profile wlan-net wlan 1 radio 0
vap-profile wlan-net wlan 1 radio 1
ap-id 0
radio 0
calibrate auto-channel-select disable
calibrate auto-txpower-select disable
channel 20mhz 6
eirp 127
radio 1
calibrate auto-channel-select disable
calibrate auto-txpower-select disable
channel 20mhz 149
eirp 127
display vap ssid wlan-net
display station ssid wlan-net
示例:
IP地址:10.23.101.254
VLAN:101
信号:-68
sysname Switch
vlan batch 100 to 101
interface GigabitEthernet0/0/1
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100 to 101
port-isolate enable group 1
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 100 to 101
sysname Router
vlan batch 101
interface Vlanif101
ip address 10.23.101.2 255.255.255.0
interface GigabitEthernet1/0/0
port link-type trunk
port trunk allow-pass vlan 101
sysname AC
vlan batch 100 to 101
dhcp enable
interface Vlanif100
ip address 10.23.100.1 255.255.255.0
dhcp select interface
interface Vlanif101
ip address 10.23.101.1 255.255.255.0
dhcp select interface
dhcp server excluded-ip-address 10.23.101.2
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 100 to 101
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 101
ip route-static 0.0.0.0 0.0.0.0 10.23.101.2
capwap source interface vlanif100