导图社区 本地三层旁挂无线网络搭建
本地三层旁挂无线网络搭建的思维导图,注意事项: 配置时确认设备是否支持所配置的命令; 删除vlanif:undo interface vlanif x; 管理vlan不为1时要修改本征VLAN: port trunk pvid vlan x; 隧道转发配置核心就行,接入无需配置,本地转发降低了ac压力但是接入层交换机都需要配置相同的trunk,配置较多。
编辑于2023-08-02 11:40:15 江苏省本地三层旁挂 无线网络搭建
确认设备是否齐全
路由器
无线控制器
无线AP
交换机(核心与接入)
AC授权
规划网络地址
出口路由器地址
上行0口:192.168.33.1/24
下行1口:172.16.10.1/24
核心交换机地址
24口access上联地址:vlanif10 172.16.10.2/24
23口trunk下联业务dhcp地址
vlanif 2 172.16.2.1/23
vlanif 4 172.16.4.1/23
vlanif 6 172.16.6.1/23
22口access核心与无线控制器互联
21口trunk口用于业务互通与管理ap
划分2468口对应业务vlan用于网络测试
无线控制器地址
8口互联地址:172.16.10.3/24
1口capwap源接口:172.16.8.1/24
规划vlan
互联vlan 10
业务vlan 2 4 6
管理vlan 8
配置
路由器
配置接口地址
int g0/0/0 ip add 192.168.33.100 24 int g0/0/1 ip add 172.16.10.1 24
配置往返路由
ip route-static 0.0.0.0 0.0.0.0 192.168.33.1 ip route-static 172.16.2.0 23 172.16.10.2 ip route-static 172.16.4.0 23 172.16.10.2 ip route-static 172.16.6.0 23 172.16.10.2
配置dns
dns server 114.114.114.114
配置nat地址转换
acl number 2000 rule 0 permit source 172.16.2.0 0.0.0.255 rule 1 permit source 172.16.3.0 0.0.0.255 rule 2 permit source 172.16.4.0 0.0.0.255 rule 3 permit source 172.16.5.0 0.0.0.255 rule 4 permit source 172.16.6.0 0.0.0.255 rule 5 permit source 172.16.7.0 0.0.0.255 int g0/0/0 nat bound 2000
配置console口密码
user-interface con 0 authentication-mode password set authentication password cipher 18752548229zy@# idle-timeout 30
核心交换机
配置vlan
vlan batch 2 4 6 8 10 int vlanif 2 ip add 172.16.2.1/23 int vlanif 4 ip add 172.16.4.1/23 int vlanif 6 ip add 172.16.6.1/23 int vlanif 10 ip add 172.16.10.2/24
配置接口
int g0/0/24 port link-type access port default vlan 10 int g0/0/23 port link-type trunk port trunk allow-pass vlan 2 4 6 8 port trunk pvid vlan 8 int g0/0/22 port link-type access port default vlan 10 int g0/0/21 port link-type trunk port trunk allow-pass vlan 2 4 6 8 port trunk pvid vlan 8
配置路由
ip route-static 0.0.0.0 0.0.0.0 172.16.10.1
配置DHCP(地址与dns)
dhcp enable int vlanif 2 dhcp select interface dhcp server dns-list 114.114.114.114 int vlanif 4 dhcp select interface dhcp server dns-list 114.114.114.114 int vlanif 6 dhcp select interface dhcp server dns-list 114.114.114.114
配置测试端口
int g0/0/2 port link-type access port default vlan 2 int g0/0/2 port link-type access port default vlan 4 int g0/0/2 port link-type access port default vlan 6 int g0/0/2 port link-type access port default vlan 8
配置console口密码
user-interface con 0 authentication-mode password set authentication password cipher 18752548229zy@# idle-timeout 30
无线控制器
配置vlan
vlan batch 2 4 6 8 10 int vlanif 8 ip add 172.16.8.1/24 int vlanif 10 ip add 172.16.10.3/24
配置接口
int g0/0/1 port link-type trunk port trunk allow-pass vlan 2 4 6 8 port trunk pvid vlan 8 int g0/0/8 port link-type access port default vlan 10
配置管理vlandhcp
dhcp enable int vlanif 8 dhcp select interface
配置路由
ip route-static 172.16.2.0 23 172.16.10.2 ip route-static 172.16.4.0 23 172.16.10.2 ip route-static 172.16.6.0 23 172.16.10.2
查看AP的MAC地址
dis mac-address
00e0-fccc-40a0 00e0-fc49-3cd0
配置capwap源接口
capwap source interface Vlanif 8
创建AP组增加ap
[AC6605]wlan [AC6605-wlan-view]ap-group name perfct [AC6605-wlan-ap-group-perfct]q [AC6605-wlan-view]ap-id 0 ap-mac 00e0-fccc-40a0 [AC6605-wlan-ap-0]ap-name meeting0 [AC6605-wlan-ap-0]ap-group perfct [AC6605-wlan-ap-0]q [AC6605-wlan-view]ap-id 1 ap-mac 00e0-fc49-3cd0 [AC6605-wlan-ap-1]ap-name meeting1 [AC6605-wlan-ap-1]ap-group perfct [AC6605-wlan-ap-1]q [AC6605-wlan-view]dis ap all
配置安全模板 配置SSID模板 配置VAP模板:调用安全模板;调用ssid模板;转发模式;服务vlan 将VAP模板应用到AP射频上
[AC6605]wlan [AC6605-wlan-view]security-profile name perfct [AC6605-wlan-sec-prof-perfct]security wpa2 ? dot1x 802.1x authentication psk Pre-shared key [AC6605-wlan-sec-prof-perfct]security wpa2 psk pass-phrase 12345678 aes [AC6605-wlan-sec-prof-perfct]q [AC6605-wlan-view]ssid-profile name perfct [AC6605-wlan-ssid-prof-perfct]ssid perfct [AC6605-wlan-ssid-prof-perfct]q [AC6605-wlan-view]vap [AC6605-wlan-view]vap-profile name perfct [AC6605-wlan-vap-prof-perfct]security-profile perfct [AC6605-wlan-vap-prof-perfct]ssid-profile perfct [AC6605-wlan-vap-prof-perfct]forward-mode ? direct-forward tunnel softgre Softgre profile tunnel Tunnel [AC6605-wlan-vap-prof-perfct]forward-mode direct-forward [AC6605-wlan-vap-prof-perfct]service-vlan vlan-id 2 [AC6605-wlan-vap-prof-perfct]q [AC6605-wlan-view]ap-group name perfct [AC6605-wlan-ap-group-perfct]vap-profile perfct wlan 1 radio 1 同样的 vlan4 vlan6可以设置另外两个ssid
配置console口密码
user-interface con 0 authentication-mode password set authentication password cipher 18752548229zy@# idle-timeout 30
注意事项
配置时确认设备是否支持所配置的命令
删除vlanif:undo interface vlanif x
管理vlan不为1时要修改本征VLAN: port trunk pvid vlan x
隧道转发配置核心就行,接入无需配置,本地转发降低了ac压力但是接入层交换机都需要配置相同的trunk,配置较多