jjzjj

华为ENSP中AP与AC的配置

mogexiuluo 2023-07-21 原文

配置企业无线网络阶段一:让AP获得IP地址

1、配置交换机
[sw1]vlan 100
[sw1]port-group group-member g0/0/1 to g0/0/5
[sw1-port-group]port link-type trunk 
[sw1-port-group]port trunk pvid vlan 100
[sw1-port-group]port trunk allow-pass vlan all

2、配置核心交换机
[sw2]vlan batch 100 210
[sw2]int g0/0/1    
[sw2-GigabitEthernet0/0/1]port link-type trunk     
[sw2-GigabitEthernet0/0/1]port trunk pvid vlan 100    
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[sw2-GigabitEthernet0/0/1]int g0/0/2    
[sw2-GigabitEthernet0/0/2]port link-type access     
[sw2-GigabitEthernet0/0/2]port default vlan 210
[sw2]int Vlanif 100    
[sw2-Vlanif100]ip address 192.168.100.1 24
[sw2-Vlanif100]int vlanif 201
[sw2-Vlanif201]ip address 192.168.210.254 24

3、配置DHCP服务器
[dhcp]dhcp enable 

[dhcp]ip pool vlan100
[dhcp-ip-pool-vlan100]network 192.168.100.0 mask 24    
[dhcp-ip-pool-vlan100]gateway-list 192.168.100.1

[dhcp]int g0/0/0    
[dhcp-GigabitEthernet0/0/0]ip address 192.168.210.1 24    
[dhcp-GigabitEthernet0/0/0]dhcp select global 

4、启动ap1,查看是否能获得IP地址;
<Huawei>display ip int brief 

5、配置DHCP中继代理
[sw2]dhcp enable
[sw2]int Vlanif 100    
[sw2-Vlanif100]dhcp select relay 
[sw2-Vlanif100]dhcp relay server-ip 192.168.210.1

6、重启ap,查看是否能够获得IP地址;
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]shutdown     
[Huawei-GigabitEthernet0/0/0]undo shutdown 
<Huawei>reboot

7、为DHCP服务器设置默认路由
[dhcp]ip route-static 0.0.0.0 0 192.168.210.254

--------------------------------------------------    
*********所有的设备综合配置**************************
SW1配置:
    undo terminal monitor 
    system-view 
    sysname SW1
    vlan 100
    q

    port-group group-member g0/0/1 to g0/0/5
    port link-type trunk
    port trunk pvid vlan 100
    port trunk allow-pass vlan all

SW2配置:
    undo terminal monitor 
    system-view 
    sysname SW2
    vlan batch 100 210
    int vlanif100
    ip add 192.168.100.1 24
    quit 

    int vlanif210
    ip add 192.168.210.254 24
    quit 

    int g0/0/1
     port link-type trunk
     port trunk pvid vlan 100    
     port trunk allow-pass vlan all
    quit 

    int g0/0/2
     port link-type access
     port default vlan 210
    quit 
    
    int vlanif100
        dhcp select relay 
        dhcp relay server-ip 192.168.210.1

DHCP配置:
    undo terminal monitor 
    system-view 
    sysname DHCP
    dhcp enable 
    int g0/0/0
      ip add 192.168.210.1 24
      dhcp select global 
      quit
    ip pool vlan100
       network 192.168.100.0 mask 24
       gateway-list 192.168.100.1
       dns-list 100.100.100.100
    quit 
      ip route-static 0.0.0.0 0 192.168.210.254

配置企业无线网络阶段二:让AP向AC注册


1、配置AC服务器
[AC6605]vlan 200
[AC6605]int g0/0/1
[AC6605-GigabitEthernet0/0/1]port link-type access 
[AC6605-GigabitEthernet0/0/1]port default vlan 200
[AC6605]int Vlanif 200
[AC6605-Vlanif200]ip address 192.168.200.2 24
[AC6605]ip route-static 0.0.0.0 0 192.168.200.1
    
    undo terminal monitor 
    system-view 
    sysname AC
    vlan 200
    quit
    int g0/0/1
        port link-type access 
        port default vlan 200
        quit
    int vlanif200
        ip add 192.168.200.2 24
        quit
    ip route-static 0.0.0.0 0 192.168.200.1
    capwap source interface Vlanif 200    
    
2、配置核心交换添加vlan200
sw2:
    vlan 200
    int g0/0/3
    port link-type access
    port default vlan 200
    int vlanif 200
    ip address 192.168.200.1 24

3、配置DHCP服务器为客户端分配置AC服务器的地址
    ip pool vlan100
    option 43 sub-option 3 ascii 192.168.200.2
[dhcp]ip pool vlan100
[dhcp-ip-pool-vlan100]option 43 sub-option 3 ascii 192.168.200.2
        option 43:所有其它服务器        
        sub-option 3:代表AC服务器
        ascii:ascii编码
        192.168.200.2 :AC服务器的IP地址

4、重启AP,让AP获得AC服务器地址;

5、配置AC服务器,允许AP注册;
1)指定capwap协议的信令源地址
[AC6605]capwap source interface Vlanif 200        //指定capwap协议的信令源地址

2)指定AC的验证方式为MAC地址验证  最容易出错(忘记配置)
[AC-wlan-view]ap auth-mode mac-auth 

查看ap mac地址:
<Huawei>display int g0/0/0
#创建 AP-group,为的是后期对大量AP进行批量管理
[AC6605-wlan-view]ap-group name guest
[AC6605-wlan-ap-group-guest]quit

[AC6605-wlan-view]ap-group name yuangong
[AC6605-wlan-ap-group-yuangong]quit

#创建 “域配置文件”,指定的是 AP 所使用的是哪个国家的无线频率范围;
[AC6605-wlan-view]regulatory-domain-profile name China    
[AC6605-wlan-regulate-domain-China]country-code CN 
[AC6605-wlan-regulate-domain-China]quit

#将配置好的“域配置文件”关联到每一个 ap-group ; 
[AC6605-wlan-view]ap-group name guest
[AC6605-wlan-ap-group-guest]regulatory-domain-profile China
Warning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continue?[Y/N]:Y
[AC6605-wlan-ap-group-guest]quit

[AC6605-wlan-view]ap-group name yuangong
[AC6605-wlan-ap-group-yuangong]regulatory-domain-profile China
Warning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continue?[Y/N]:Y
[AC6605-wlan-ap-group-yuangong]quit


#在 AC 上手动添加 ap (基于MAC地址进行注册)
[AC6605-wlan-view]ap-id 1 ap-mac 00e0-fcb6-4850  [是要自己查看的]
[AC6605-wlan-ap-1]ap-name guest-1   [为了区分设备上的多个ap,取的名字]
[AC6605-wlan-ap-1]ap-group guest    [为ap指定所加入的 ap-group]
Warning: This operation may cause AP reset. If the country code changes, it willclear channel, power and antenna gain configurations of the radio, Whether to continue? [Y/N]:y
[AC6605-wlan-ap-1]quit

[AC6605-wlan-view]ap-id 2 ap-mac 00e0-fcee-0670
[AC6605-wlan-ap-2]ap-name guest-2
[AC6605-wlan-ap-2]ap-group guest
Warning: This operation may cause AP reset. If the country code changes, it willclear channel, power and antenna gain configurations of the radio, Whether to continue? [Y/N]:y
[AC6605-wlan-ap-2]quit

[AC6605-wlan-view]ap-id 3 ap-mac 00e0-fc44-6910
[AC6605-wlan-ap-3]ap-name yuangong-1
[AC6605-wlan-ap-3]ap-group yuangong
Warning: This operation may cause AP reset. If the country code changes, it willclear channel, power and antenna gain configurations of the radio, Whether to continue? [Y/N]:y
[AC6605-wlan-ap-3]quit

[AC6605-wlan-view]ap-id  4 ap-mac 00e0-fcc9-22f0
[AC6605-wlan-ap-4]ap-name yuangong-2
[AC6605-wlan-ap-4]ap-group yuangong
Warning: This operation may cause AP reset. If the country code changes, it willclear channel, power and antenna gain configurations of the radio, Whether to continue? [Y/N]:y
[AC6605-wlan-ap-4]quit

6、在ap上验证是否注册成功

===== CAPWAP LINK IS UP!!! =====
ap注册成功后会自动重启
ap注册成功后主机名会自动更改

7、在ac上验证ap是否注册成功
[AC]display ap all
Info: This operation may take a few seconds. Please wait for a moment.done.
Total AP information:
nor  : normal          [4]
--------------------------------------------------------------------------------
-------------------
ID   MAC            Name       Group    IP              Type            State ST
A Uptime
--------------------------------------------------------------------------------
-------------------
1    00e0-fcd4-01b0 guest-1    guest    192.168.100.254 AP4050DN-E      nor   0 
  3M:49S
2    00e0-fc74-3e20 guest-2    guest    192.168.100.251 AP4050DN-E      nor   0 
  3M:50S
3    00e0-fc6d-7d30 yuangong-1 yuangong 192.168.100.253 AP4050DN-E      nor   0 
  4M:1S
4    00e0-fcb2-03f0 yuangong-2 yuangong 192.168.100.252 AP3030DN        nor   0 
  4M:2S
--------------------------------------------------------------------------------
-------------------
Total: 4
 状态应该为 :nor  


************阶段二的:AC此步骤的全部配置************


    wlan
    ap-group name guest
    quit 
    ap-group name yuangong
    quit 

    regulatory-domain-profile  name China
    country-code CN
    quit

ap-group name guest
    regulatory-domain-profile China
    y
    quit

ap-group name yuangong
    regulatory-domain-profile China
       y
       quit
ap auth-mode mac-auth 
        ap-id 1 ap-mac 00e0-fcd4-01b0
        ap-name guest-1
        ap-group guest
         y
         quit

ap-id 2 ap-mac 00e0-fc74-3e20
        ap-name guest-2
        ap-group guest
        y
        quit
ap-id 3 ap-mac 00e0-fc6d-7d30
        ap-name yuangong-1
        ap-group yuangong
        y
        quit
ap-id 4 ap-mac 00e0-fcb2-03f0
        ap-name yuangong-2
        ap-group yuangong
        y
        quit

配置企业无线网络阶段三:让AC为AP分配无线参数


1、创建vlan地址池
[AC]vlan pool sta-pool1 
[AC-vlan-pool-sta-pool1]vlan 101 102
[AC-vlan-pool-sta-pool1]quit
[AC]vlan pool sta-pool2
[AC-vlan-pool-sta-pool2]vlan 103 104
[AC-vlan-pool-sta-pool2]quit

2、设置加密配置文件,为AP分配无线密码;
[AC-wlan-view]security-profile name guest    
[AC-wlan-sec-prof-guest]security wpa2 psk pass-phrase a1234567 aes
[AC-wlan-sec-prof-guest]quit
[AC-wlan-view]security-profile name yuangong    
[AC-wlan-sec-prof-yuangong]security wpa2 psk pass-phrase b1234567 aes
[AC-wlan-sec-prof-yuangong]quit

3、设置ssid名称,为AP分配无线信号的名称;
[AC-wlan-view]ssid-profile name guest    
[AC-wlan-ssid-prof-guest]ssid guest
[AC-wlan-ssid-prof-guest]quit
[AC-wlan-view]ssid-profile name yuangong
[AC-wlan-ssid-prof-yuangong]ssid yuangong
[AC-wlan-ssid-prof-yuangong]quit

4、创建无线客户端访问模板,关联以上三个参数;
[AC-wlan-view]vap-profile name guest    
[AC-wlan-vap-prof-guest]service-vlan vlan-pool sta-pool1
[AC-wlan-vap-prof-guest]security-profile guest
[AC-wlan-vap-prof-guest]ssid-profile  guest
[AC-wlan-vap-prof-guest]quit
[AC-wlan-view]vap-profile name yuangong
[AC-wlan-vap-prof-yuangong]service-vlan vlan-pool sta-pool2
[AC-wlan-vap-prof-yuangong]security-profile yuangong
[AC-wlan-vap-prof-yuangong]ssid-profile yuangong
[AC-wlan-vap-prof-guest]quit

5、为ap开启无线信号
[AC-wlan-view]ap-group name guest    
[AC-wlan-ap-group-guest]vap-profile guest wlan 1 radio 0
[AC-wlan-ap-group-guest]vap-profile guest wlan 1 radio 1
[AC-wlan-view]ap-group name yuangong    
[AC-wlan-ap-group-yuangong]vap-profile yuangong wlan 1 radio 0
[AC-wlan-ap-group-yuangong]vap-profile yuangong wlan 1 radio 1

6、创建客户端所在的vlan
[sw1]vlan batch 101 102 103 104
[sw2]vlan batch 101 102 103 104

7、为核心交换机设置vlan虚接口IP地址
[sw2]int Vlanif 101    
[sw2-Vlanif101]ip address 192.168.101.1 24
[sw2]int Vlanif 102    
[sw2-Vlanif101]ip address 192.168.102.1 24
[sw2]int Vlanif 103    
[sw2-Vlanif101]ip address 192.168.103.1 24
[sw2]int Vlanif 104    
[sw2-Vlanif101]ip address 192.168.104.1 24

8、为4个vlan创建dhcp地址池
[dhcp]ip pool vlan101
[dhcp-ip-pool-vlan101]network 192.168.101.0 mask 24    
[dhcp-ip-pool-vlan101]gateway-list 192.168.101.1
[dhcp]ip pool vlan102
[dhcp-ip-pool-vlan102]network 192.168.102.0 mask 24    
[dhcp-ip-pool-vlan102]gateway-list 192.168.102.1
[dhcp]ip pool vlan103
[dhcp-ip-pool-vlan103]network 192.168.103.0 mask 24    
[dhcp-ip-pool-vlan103]gateway-list 192.168.103.1
[dhcp]ip pool vlan104
[dhcp-ip-pool-vlan104]network 192.168.104.0 mask 24    
[dhcp-ip-pool-vlan104]gateway-list 192.168.104.1

9、配置中继代理
[sw2]int Vlanif 101
[sw2-Vlanif101]dhcp select relay 
[sw2-Vlanif101]dhcp relay server-ip 192.168.201.2
[sw2]int Vlanif 102
[sw2-Vlanif102]dhcp select relay 
[sw2-Vlanif102]dhcp relay server-ip 192.168.201.2
[sw2]int Vlanif 103
[sw2-Vlanif103]dhcp select relay 
[sw2-Vlanif103]dhcp relay server-ip 192.168.201.2
[sw2]int Vlanif 104
[sw2-Vlanif104]dhcp select relay 
[sw2-Vlanif104]dhcp relay server-ip 192.168.201.2


************************阶段三:AC的配置*************
vlan pool pool1
    vlan 101 102
    quit 
vlan pool pool2
    vlan 103 104
    quit 
    
wlan
security-profile name guest
security wpa2 psk pass-phrase a1234567 aes
quit

security-profile name yuangong
security wpa2 psk pass-phrase b1234567 aes
quit

ssid-profile name guest
ssid guest
quit

ssid-profile name yuangong
ssid yuangong
quit

vap-profile name guest
    service-vlan vlan-pool pool1
    security-profile guest
    ssid-profile guest
    quit

vap-profile name yuangong
    service-vlan vlan-pool pool2
    security-profile yuangong
    ssid-profile yuangong
    quit 

ap-group name guest
    vap-profile guest wlan 1 radio 0
    vap-profile guest wlan 1 radio 1
    quit
ap-group name yuangong
    vap-profile yuangong wlan 1 radio 0
    vap-profile yuangong wlan 1 radio 1
    quit

*****************SW2地址创建及DHCP中继配置**************
 vlan batch 101 102 103 104 
int vlanif 101
    ip add 192.168.101.1 24
    dhcp select relay 
    dhcp relay server-ip 192.168.210.1
    quit
int vlanif 102
    ip add 192.168.102.1 24
    dhcp select relay 
    dhcp relay server-ip 192.168.210.1
    quit
int vlanif 103
    ip add 192.168.103.1 24
    dhcp select relay 
    dhcp relay server-ip 192.168.210.1
    quit
int vlanif 104
    ip add 192.168.104.1 24
    dhcp select relay 
    dhcp relay server-ip 192.168.210.1
    quit
*****************DHCP地址池配置**************
ip pool vlan101
    network 192.168.101.0 mask 24
    gateway-list 192.168.101.1    
    dns-list 101.101.101.101
    quit    
ip pool vlan102
    network 192.168.102.0 mask 24
    gateway-list 192.168.102.1    
    dns-list 102.102.102.102
    quit
ip pool vlan103
    network 192.168.103.0 mask 24
    gateway-list 192.168.103.1    
    dns-list 103.103.103.103
    quit
ip pool vlan104
    network 192.168.104.0 mask 24
    gateway-list 192.168.104.1    
    dns-list 104.104.104.104
    quit    
    
    测试结果:
    
    
    
    
    
    
    
    
    
    
    

 按照上面的步骤即可完成此项目

            
    
        


 

有关华为ENSP中AP与AC的配置的更多相关文章

  1. ruby-on-rails - 独立 ruby​​ 脚本的配置文件 - 2

    我有一个在Linux服务器上运行的ruby​​脚本。它不使用rails或任何东西。它基本上是一个命令行ruby​​脚本,可以像这样传递参数:./ruby_script.rbarg1arg2如何将参数抽象到配置文件(例如yaml文件或其他文件)中?您能否举例说明如何做到这一点?提前谢谢你。 最佳答案 首先,您可以运行一个写入YAML配置文件的独立脚本:require"yaml"File.write("path_to_yaml_file",[arg1,arg2].to_yaml)然后,在您的应用中阅读它:require"yaml"arg

  2. Ruby Sinatra 配置用于生产和开发 - 2

    我已经在Sinatra上创建了应用程序,它代表了一个简单的API。我想在生产和开发上进行部署。我想在部署时选择,是开发还是生产,一些方法的逻辑应该改变,这取决于部署类型。是否有任何想法,如何完成以及解决此问题的一些示例。例子:我有代码get'/api/test'doreturn"Itisdev"end但是在部署到生产环境之后我想在运行/api/test之后看到ItisPROD如何实现? 最佳答案 根据SinatraDocumentation:EnvironmentscanbesetthroughtheRACK_ENVenvironm

  3. 华为OD机试用Python实现 -【明明的随机数】 2023Q1A - 2

    华为OD机试题本篇题目:明明的随机数题目输入描述输出描述:示例1输入输出说明代码编写思路最近更新的博客华为od2023|什么是华为od,od薪资待遇,od机试题清单华为OD机试真题大全,用Python解华为机试题|机试宝典【华为OD机试】全流程解析+经验分享,题型分享,防作弊指南华为o

  4. 华为常用命令 - 2

    system-view进入系统视图quit退到系统视图sysname交换机命名vlan20创建vlan(进入vlan20)displayvlan显示vlanundovlan20删除vlan20displayvlan20显示vlan里的端口20Interfacee1/0/24进入端口24portlink-typeaccessvlan20把当前端口放入vlan20undoporte1/0/10删除当前VLAN端口10displaycurrent-configuration显示当前配置02配置交换机支持TELNETinterfacevlan1进入VLAN1ipaddress192.168.3.100

  5. Vscode+Cmake配置并运行opencv环境(Windows和Ubuntu大同小异) - 2

    之前在培训新生的时候,windows环境下配置opencv环境一直教的都是网上主流的vsstudio配置属性表,但是这个似乎对新生来说难度略高(虽然个人觉得完全是他们自己的问题),加之暑假之后对cmake实在是爱不释手,且这样配置确实十分简单(其实都不需要配置),故斗胆妄言vscode下配置CV之法。其实极为简单,图比较多所以很长。如果你看此文还配不好,你应该思考一下是不是自己的问题。闲话少说,直接开始。0.CMkae简介有的人到大二了都不知道cmake是什么,我不说是谁。CMake是一个开源免费并且跨平台的构建工具,可以用简单的语句来描述所有平台的编译过程。它能够根据当前所在平台输出对应的m

  6. 神州数码无线产品(AC+AP)配置 - 2

    注意:本文主要掌握DCN自研无线产品的基本配置方法和注意事项,能够进行一般的项目实施、调试与运维AP基本配置命令AP登录用户名和密码均为:adminAP默认IP地址为:192.168.1.10AP默认情况下DHCP开启AP静态地址配置:setmanagementstatic-ip192.168.10.1AP开启/关闭DHCP功能:setmanagementdhcp-statusup/downAP设置默认网关:setstatic-ip-routegeteway192.168.10.254查看AP基本信息:getsystemgetmanagementgetmanaged-apgetrouteAP配

  7. hadoop安装之保姆级教程(二)之YARN的配置 - 2

    1.1.1 YARN的介绍 为克服Hadoop1.0中HDFS和MapReduce存在的各种问题⽽提出的,针对Hadoop1.0中的MapReduce在扩展性和多框架⽀持⽅⾯的不⾜,提出了全新的资源管理框架YARN. ApacheYARN(YetanotherResourceNegotiator的缩写)是Hadoop集群的资源管理系统,负责为计算程序提供服务器计算资源,相当于⼀个分布式的操作系统平台,⽽MapReduce等计算程序则相当于运⾏于操作系统之上的应⽤程序。 YARN被引⼊Hadoop2,最初是为了改善MapReduce的实现,但是因为具有⾜够的通⽤性,同样可以⽀持其他的分布式计算模

  8. Ruby 默认将 IRB 配置为 Pretty_Inspect - 2

    我是ruby​​的新手,正在配置IRB。我喜欢pretty-print(需要'pp'),但总是输入pp来漂亮地打印它似乎很麻烦。我想做的是默认情况下让它漂亮地打印出来,所以如果我有一个var,比如说,'myvar',然后键入myvar,它会自动调用pretty_inspect而不是常规检查。我从哪里开始?理想情况下,我将能够向我的.irbrc文件添加一个自动调用的方法。有什么想法吗?谢谢! 最佳答案 irb中默认pretty-print对象正是hirb被迫去做。Theseposts解释hirb如何将几乎所有内容转换为ascii表。虽

  9. ruby - 是否可以将 IRB 提示配置为动态更改? - 2

    我想在IRB中浏览文件系统并让提示更改以反射(reflect)当前工作目录,但我不知道如何在每个命令后进行提示更新。最终,我想在日常工作中更多地使用IRB,让bash溜走。我在我的.irbrc中试过这个:require'fileutils'includeFileUtilsIRB.conf[:PROMPT][:CUSTOM]={:PROMPT_N=>"\e[1m:\e[m",:PROMPT_I=>"\e[1m#{pwd}>\e[m",:PROMPT_S=>"FOO",:PROMPT_C=>"\e[1m#{pwd}>\e[m",:RETURN=>""}IRB.conf[:PROMPT_MO

  10. ruby - 如何配置 Ruby Mechanize 代理以通过 Charles Web 代理工作? - 2

    我正在使用Ruby/Mechanize编写一个“自动填写表格”应用程序。它几乎可以工作。我可以使用精彩CharlesWeb代理以查看服务器和我的Firefox浏览器之间的交换。现在我想使用Charles查看服务器和我的应用程序之间的交换。Charles在端口8888上代理。假设服务器位于https://my.host.com。.一件不起作用的事情是:@agent||=Mechanize.newdo|agent|agent.set_proxy("my.host.com",8888)end这会导致Net::HTTP::Persistent::Error:...lib/net/http/pe

随机推荐