华为ac+ap 3层组网架构web配置+命令行配置 |
您所在的位置:网站首页 › 按键映射什么意思 › 华为ac+ap 3层组网架构web配置+命令行配置 |
1、所有的dhcp都在核心 2、ap管理地址dhcp也在核心 3、接入交换机接ap口要设置pvlan 4、业务vlan 10 20 5、ap管理vlan 100 这个vlan下要有一条option 43 sub-option 3 ascii 10.0.0.2 10.0.0.2为ac的vlan999 地址用于和核心互连 核心配置: dis cu dis current-configuration sysname HX undo info-center enable vlan batch 10 20 100 999 stp disable cluster enable ntdp enable ndp enable drop illegal-mac alarm dhcp enable diffserv domain default drop-profile default dhcp server group vlan10 ip pool vlan10 gateway-list 192.168.10.1 network 192.168.10.0 mask 255.255.255.0 ip pool vlan20 gateway-list 192.168.20.1 network 192.168.20.0 mask 255.255.255.0 ip pool vlan100 gateway-list 172.16.0.1 network 172.16.0.0 mask 255.255.255.0 option 43 sub-option 3 ascii 10.0.0.2 aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password simple admin local-user admin service-type http interface Vlanif1 interface Vlanif10 ip address 192.168.10.1 255.255.255.0 dhcp select global interface Vlanif20 ip address 192.168.20.1 255.255.255.0 dhcp select global interface Vlanif100 ip address 172.16.0.1 255.255.255.0 dhcp select global interface Vlanif999 ip address 10.0.0.1 255.255.255.0 interface MEth0/0/1 interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 2 to 4094 interface GigabitEthernet0/0/2 port link-type trunk port trunk allow-pass vlan 2 to 4094 interface GigabitEthernet0/0/3 port link-type access port default vlan 999 interface NULL0 user-interface con 0 user-interface vty 0 4 return 接入配置: dis curr dis current-configuration sysname jr vlan batch 10 20 100 stp disable cluster enable ntdp enable ndp enable drop illegal-mac alarm diffserv domain default drop-profile default aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password simple admin local-user admin service-type http interface Vlanif1 interface MEth0/0/1 interface Ethernet0/0/1 port link-type trunk port trunk pvid vlan 100 port trunk allow-pass vlan 10 20 100 interface Ethernet0/0/2 port link-type trunk port trunk allow-pass vlan 2 to 4094 interface Ethernet0/0/3 port link-type trunk port trunk pvid vlan 100 port trunk allow-pass vlan 10 20 100 interface NULL0 user-interface con 0 user-interface vty 0 4 return ac控制器配置(web配置): 设置源ip 创建互通vlan 设置虚拟ip 设置默认路由: 新建立SSID使用自带的默认default模版,不用自己建立模版了: 改上线的ap名称并加入到default组的ssid中: ac控制器配置(命令行配置): dis curr dis current-configuration sysname ac http server enable set memory-usage threshold 0 ssl renegotiation-rate 1 vlan 999 authentication-profile name default_authen_profile authentication-profile name dot1x_authen_profile authentication-profile name mac_authen_profile authentication-profile name portal_authen_profile authentication-profile name macportal_authen_profile diffserv domain default radius-server template default pki realm default rsa local-key-pair default enrollment self-signed ike proposal default encryption-algorithm aes-256 dh group14 authentication-algorithm sha2-256 authentication-method pre-share integrity-algorithm hmac-sha2-256 prf hmac-sha2-256 free-rule-template name default_free_rule portal-access-profile name portal_access_profile aaa authentication-scheme default authentication-scheme radius authentication-mode radius authorization-scheme default accounting-scheme default domain default authentication-scheme radius radius-server default domain default_admin authentication-scheme default local-user yu password irreversible-cipher local-user yeng privilege level 15 local-user yeng service-type web local-user admin password irreversible-cipher |
今日新闻 |
点击排行 |
|
推荐新闻 |
图片新闻 |
|
专题文章 |
CopyRight 2018-2019 实验室设备网 版权所有 win10的实时保护怎么永久关闭 |