首先,我们需要构建一个实验拓扑图,以便于直观地了解整个网络的物理连接。在这个实验中,我们使用了两台设备:一台交换机(SW1)和一台无线接入控制器(AC1)。交换机连接到多个VLAN,并配置了相应的接口和网关,而AC1则负责管理与AP的通信。
### 1. 交换机配置
在SW1上,我们首先创建并配置了两个VLAN,分别为100和101。接下来,我们配置了两个千兆接口作为Trunk类型,允许这两个VLAN的流量通过。同时,为VLAN100和101分别配置了ip地址,用作对应的网关。
```plaintext [SW1]vlan batch 10 100 101 [SW1]interface GigabitEthernet0/0/1 [SW1-GigabitEthernet0/0/1]port-link-type trunk [SW1-GigabitEthernet0/0/1]port-trunk allow-pass vlan 100 to 101 [SW1]interface Vlanif10 [SW1-Vlanif10]ip address 192.168.13.1 255.255.255.0 [SW1]interface Vlanif100 [SW1-Vlanif100]ip address 192.168.100.254 255.255.255.0 ```
### 2. AC配置
在AC1上,我们同样配置了VLAN,并设置了与SW1相连的接口为trunk类型。接着,我们为AC配置了一个IP地址,并设置了默认路由,确保AP能够与AC进行通信。
```plaintext [AC]vlan batch 10 100 101 [AC]interface GigabitEthernet0/0/1 [AC-GigabitEthernet0/0/1]port-link-type trunk [AC]interface Vlanif10 [AC-Vlanif10]ip address 192.168.13.2 255.255.255.0 [AC]ip route-static 192.168.100.0 24 192.168.13.1 ```
### 3. 模板配置
在AC上,我们还需要配置SSID、安全模板和vap模板,这些配置将决定无线网络的服务质量、安全性和管理方式。
```plaintext [AC]wlan [AC-wlan-view]ssid-profile name ljr [AC-wlan-ssid-prof-ljr]ssid ljrnetwork [AC-wlan-sec-prof-ljr]security WPA2psk pass-phrase 2018060301324 [AC-wlan-vap-prof-ljr]forward-mode direct-forward [AC-wlan-vap-prof-ljr]service-vlan vlan-id 101 ```
### 4. 实验验证
完成上述配置后,我们需要验证AP是否成功上线。在AC上执行相关命令,检查AP的状态。若AP状态为“nor”,则表示已成功上线。
```plaintext [AC]disap all ```
最后,我们可以在客户端设备上验证是否能通过无线网络获取IP地址,这通常通过在命令行输入“Ipconfig”来完成。
通过这个实验,我们可以了解到WLAN组网的基本配置步骤,以及如何确保不同设备之间的正常通信。实验中的每个步骤都是网络构建中至关重要的一环,掌握这些基础知识对于后续的网络管理和优化至关重要。
转载请注明以下内容:
来源:公众号【网络技术干货圈】
作者:圈圈
ID:wljsghq
最简单的WLAN三层组网实验
1、拓扑图
2、组网配置
SW1配置:
[SW1]vlanbatch10101102 //放行VLAN [SW1]interfaceGigabitEthernet0/0/1 [SW1-GigabitEthernet0/0/1]portlink-typetrunk [SW1-GigabitEthernet0/0/1]porttrunkpvidvlan100 [SW1-GigabitEthernet0/0/1]porttrunkallow-passvlan100to101 //放行VLAN [SW1]interfaceGigabitEthernet0/0/2 [SW1-GigabitEthernet0/0/2]portlink-typetrunk [SW1-GigabitEthernet0/0/2]porttrunkallow-passvlan10101 //配置网关 [SW1]interfaceVlanif10 [SW1-Vlanif10]ipaddress192.168.13.1255.255.255.0 [SW1]interfaceVlanif100 [SW1-Vlanif100]iPaddress192.168.100.254255.255.255.0 [SW1-Vlanif100]dhcpseLECtinterface [SW1-Vlanif100]dhcPSErveroption43sub-option2ip-address192.168.13.2 [SW1]interfaceVlanif101 [SW1-Vlanif101]ipaddress192.168.101.254255.255.255.0 [SW1-Vlanif101]dhcpselectinterface
查看SW1中MAC地址
00e0-fc4e-5810是AP的MAC地址后面有用
[SW1]dismac-address MACaddresstableofslot0: ------------------------------------------------------------------------------- MACAddressVLAN/PEVLANCEVLANPortTypeLSP/LSR-ID VSI/SIMAC-Tunnel ------------------------------------------------------------------------------- 00e0-fc63-169810--GE0/0/2dynamic0/- 00e0-fc4e-5810100--GE0/0/1dynamic0/- ------------------------------------------------------------------------------- Totalmatchingitemsonslot0displayed=2
AC1配置
[AC]vlanbatch10101 //放行VLAN [AC]interfaceGigabitEthernet0/0/1 [AC-GigabitEthernet0/0/1]portlink-typetrunk [AC-GigabitEthernet0/0/1]porttrunkallow-passvlan10101 //配置IP地址 [AC]interfaceVlanif10 [AC-Vlanif10]ipaddress192.168.13.2255.255.255.0 [AC]capwapsourceip-address192.168.13.2 //配置默认路由使AP与AC互通 [AC]iproute-static192.168.100.024192.168.13.1 //配置AP上线 [AC]wlan [AC-wlan-view]ap-id0ap-mac00e0-fc63-1698
查看ap是否以及上线
0 00e0-fc4e-5810 00e0-fc4e-5810 default 192.168.100.253 AP2050DN nor
0 14S
这里为nor即为已上线
[AC]disapall Info:Thisoperationmaytakeafewseconds.Pleasewaitforamoment.done. TotalAPinformation: nor:normal[1] -------------------------------------------------------------------------------- ---------------------- IDMACNameGroupIPTypeState STAuptime -------------------------------------------------------------------------------- ---------------------- 000e0-fc4e-581000e0-fc4e-5810default192.168.100.253AP2050DNnor 014S -------------------------------------------------------------------------------- ---------------------- Total:1
AC模板配置
[AC]wlan [AC-wlan-view]ssid-profilenameljr//ljr为自定义名字 [AC-wlan-ssid-prof-ljr]ssidlinjianrong//linjianrong可以理解为WIFI的名字 [AC-wlan-ssid-prof-ljr]q [AC-wlan-view]security-profilenameljr//ljr为自定义名字 [AC-wlan-sec-prof-ljr]securitywpa2pskpass-phrase2018060301324tkip Warning:Thecurrentpasswordistoosimple.Forthesakeofsecurity,youarea dvisedtosetapasswordcontainingatleasttwoofthefollowing:lowercaselet tersatoz,uppercaselettersAtoZ,digits,anDSPecialcharacters.Continue? [Y/N]:y Warning:Ifthewmmdisablecommand,TKIP,WEP,orradIoTypeof802.11a/b/gis configured,thefunctionofdenyingAccessoflegacySTAsCANnottakeeffect. 这里的2018060301324为密码 [AC-wlan-sec-prof-ljr]q [AC-wlan-view]vap-profilenameljr [AC-wlan-vap-prof-ljr]forward-modedirect-forward//direct-forward为直接转发模式 [AC-wlan-vap-prof-ljr]service-vlanvlan-id101//管理的vlan,即ap下面管理的PC [AC-wlan-vap-prof-ljr]ssid-profileljr//ssid模块 [AC-wlan-vap-prof-ljr]security-profileljr//安全模块 [AC-wlan-view]ap-groupnamedefault [AC-wlan-ap-group-default]vap-profileljrwlan1radioall Info:Thisoperationmaytakeafewseconds,pleasewait...done.
上面的敲完后会出现下面的情况
双击1、2,输入密码2018060301324,点击确定完成连接
可以看到已经连上了
双击STA1,在命令行输入ipconfig查看是否已经获取IP地址
到此为止,整个实验完成。
3、总结:
(1)在ensp中观察不到AP上线可能需要重启AP;
(2)AP与192.168.13.2IP地址需要互通,AP才可能上线;