举例中使用的AP为AP6010DN-AGN,具有射频0和射频1两个射频。AP6010DN-AGN的射频0为2.4GHz射频,射频1为5GHz射频。 [AC] wlan
[AC-wlan-view] ap auth-mode mac-auth
[AC-wlan-view] ap-id 0 ap-mac 60de-4476-e360 [AC-wlan-ap-0] ap-name area_1 [AC-wlan-ap-0] ap-group ap-group1
Warning: This operation maybe cause AP reset. If the country code changes, it will clear channel, power and antenna gain configurati ons of the radio, Whether to continue? [Y/N]y [AC-wlan-ap-0] quit
# 将AP上电后,当执行命令display ap all查看到AP的“State”字段为“nor”时,表示AP正常上线。
[AC-wlan-view] display ap all Total AP information: nor : normal [1]
-------------------------------------------------------------------------------------
ID MAC Name Group IP Type State STA Uptime
-------------------------------------------------------------------------------------
0 60de-4476-e360 area_1 ap-group1 10.23.100.254 AP6010DN-AGN nor 0 10S
------------------------------------------------------------------------------------- Total: 1
5. 配置WLAN业务参数
# 创建名为“wlan-security”的安全模板,并配置安全策略。
说明:
举例中以配置WPA2+PSK+AES的安全策略为例,密码为“a1234567”,实际配置中请根据实际情况,配置符合实际要求的安全策略。
[AC-wlan-view] security-profile name wlan-security
[AC-wlan-sec-prof-wlan-security] security wpa2 psk pass-phrase a1234567 aes [AC-wlan-sec-prof-wlan-security] quit
# 创建名为“wlan-ssid”的SSID模板,并配置SSID名称为“wlan-net”。 [AC-wlan-view] ssid-profile name wlan-ssid [AC-wlan-ssid-prof-wlan-ssid] ssid wlan-net
Warning: This action may cause service interruption. Continue?[Y/N]y [AC-wlan-ssid-prof-wlan-ssid] quit
# 创建名为“wlan-vap”的VAP模板,配置业务数据转发模式、业务VLAN,并且引用安全模板和SSID模板。
[AC-wlan-view] vap-profile name wlan-vap [AC-wlan-vap-prof-wlan-vap] forward-mode tunnel
Warning: This action may cause service interruption. Continue?[Y/N]y [AC-wlan-vap-prof-wlan-vap] service-vlan vlan-id 101 [AC-wlan-vap-prof-wlan-vap] security-profile wlan-security [AC-wlan-vap-prof-wlan-vap] ssid-profile wlan-ssid [AC-wlan-vap-prof-wlan-vap] quit
# 配置AP组引用VAP模板,AP上射频0和射频1都使用VAP模板“wlan-vap”的配置。
[AC-wlan-view] ap-group name ap-group1
[AC-wlan-ap-group-ap-group1] vap-profile wlan-vap wlan 1 radio all [AC-wlan-ap-group-ap-group1] quit 6. 验证配置结果
WLAN业务配置会自动下发给AP,配置完成后,通过执行命令display vap ssid wlan-net查看如下信息,当“Status”项显示为“ON”时,表示AP对应的射频上的VAP已创建成功。
[AC-wlan-view] display vap ssid wlan-net WID : WLAN ID
--------------------------------------------------------------------------------
AP ID AP name RfID WID SSID BSSID Status Auth type STA --------------------------------------------------------------------------------
0 area_1 0 1 wlan-net 60DE-4476-E360 ON WPA2-PSK 0 0 area_1 1 1 wlan-net 60DE-4476-E370 ON WPA2-PSK 0 ------------------------------------------------------------------------------- Total: 2
STA搜索到名为“wlan-net”的无线网络,输入密码“a1234567”并正常关联后,在AC上执行display station ssid wlan-net命令,可以查看到用户已经接入到无线网络“wlan-net”中。
[AC-wlan-view] display station ssid wlan-net Rf/WLAN: Radio ID/WLAN ID
Rx/Tx: link receive rate/link transmit rate(Mbps)
---------------------------------------------------------------------------------
STA MAC AP ID Ap name Rf/WLAN Band Type Rx/Tx RSSI VLAN IP address
---------------------------------------------------------------------------------
e019-1dc7-1e08 0 area_1 1/1 5G 11n 46/59 -68 101 10.23.101.254
---------------------------------------------------------------------------------
Total: 1 2.4G: 0 5G: 1
配置文件
? AC的配置文件 ? #
? sysname AC ? #
? vlan batch 100 to 101 ? #
? dhcp enable ? #
? interface Vlanif100
? ip address 10.23.100.1 255.255.255.0 ? dhcp select interface ? #
? interface Vlanif101
? ip address 10.23.101.1 255.255.255.0 ? dhcp select interface ? #
? interface GigabitEthernet0/0/1 ? port link-type trunk ? port trunk pvid vlan 100 ? port trunk allow-pass vlan 100 ? #
? interface GigabitEthernet0/0/2 ? port link-type trunk
? port trunk allow-pass vlan 101 ? #
? capwap source interface vlanif100 ? # ? wlan
? security-profile name wlan-security ? security wpa2 psk
pass-phrase %^%#m\~7.[`^6RWdzwCy16hJj/Mc!,}s`X*B]}A%^%# aes ? ssid-profile name wlan-ssid ? ssid wlan-net
? vap-profile name wlan-vap ? forward-mode tunnel ? service-vlan vlan-id 101 ? ssid-profile wlan-ssid
? security-profile wlan-security ? regulatory-domain-profile name domain1 ? ap-group name ap-group1
? regulatory-domain-profile domain1 ? radio 0
? vap-profile wlan-vap wlan 1 ? radio 1
? vap-profile wlan-vap wlan 1
? ap-id 0 type-id 19 ap-mac 60de-4476-e360 ap-sn 210235554710CB000042 ? ap-name area_1 ? ap-group ap-group1