- SW1的配置
#创建vlan 100 200
vlan batch 100 200 #创建vlan 100 200
#在接口上放行vlan 100 200
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 100 200
#在接口上放行vlan 100 200
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 100
#配置vlan200的IP地址并且200的网关向下通过dhcp分发地址 需要在全局开启dhcp功能
interface Vlanif200
ip address 192.168.200.1 255.255.255.0
dhcp select interface
- SW2的基础配置
#在接口上放行vlan 100
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 100
#连接ap的接口需要打上100的标签 capwap隧道通过vlan 100建立
interface GigabitEthernet0/0/2
port link-type access
port default vlan 100
- AC的基础配置
#创建vlan 100 配置地址 全局开启dhcp功能并且让ap通过dhcp自动获得地址
interface Vlanif100
ip address 192.168.100.1 255.255.255.0
dhcp select interface
#在接口上放行vlan100 200
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 100 200
- 在AC上配置WLAN
#建立capwap隧道
[AC6005]capwap source ip-address 192.168.100.1
#配置ap组并上线ap
[AC6005-wlan-view]ap-group name huawei
[AC6005-wlan-ap-group-huawei]q
[AC6005-wlan-view]ap-id 1 ap-mac 00e0-fca8-4520
[AC6005-wlan-ap-1]
[AC6005-wlan-ap-1]ap-name ap1
[AC6005-wlan-ap-1]ap-group huawei
[AC6005-wlan-ap-1]q
#配置ssid模版
[AC6005-wlan-view]ssid-profile name huawei1
[AC6005-wlan-ssid-prof-huawei1]ssid huawei
[AC6005-wlan-ssid-prof-huawei1]q
#配置安全模版
[AC6005-wlan-view]security-profile name huawei2
[AC6005-wlan-sec-prof-huawei2]security wpa-wpa2 psk pass-phrase huawei123 aes
[AC6005-wlan-sec-prof-huawei2]q
#配置vap模版
[AC6005-wlan-view]vap-profile name huawei3
[AC6005-wlan-vap-prof-huawei3]forward-mode tunnel
[AC6005-wlan-vap-prof-huawei3]service-vlan vlan-id 200
[AC6005-wlan-vap-prof-huawei3]ssid-profile huawei1
[AC6005-wlan-vap-prof-huawei3]security-profile huawei2
#调用vap模版
[AC6005-wlan-view]ap-group name huawei
[AC6005-wlan-ap-group-huawei]vap-profile huawei3 wlan 1 radio 0
- 在上图中采用三层组网,管理vlan采用vlan150,dhcp下发还是使用vlan100
#与ap使用150建立capwap隧道
[AC6005]capwap source ip-address 192.168.100.1
#创建vlan150
interface Vlanif150
ip address 192.168.150.1 255.255.255.0
#使用option43字段跨网段通信
interface Vlanif100
ip address 192.168.100.1 255.255.255.0
dhcp select interface
dhcp server option 43 sub-option 2 ip-address 192.168.150.1
- 抓包