組網:核心作為網關、dhcp服務器,多vlan 10-60
AC接入在vlan10的彙聚交換機上trunk放通所有vlan,AP使用option43注冊
其他vlan上注冊的ap都能正常使用,隻有vlan10也就是ac\ap同vlan下終端就無法上網
vlan10的ap可以正常獲取ip,可以ping通,終端也可以獲取正常的ip地址,核心的arp表上也有ap和終端的地址
發現終端的接口是WLAN-BSS時就不通網關和路由。隻能訪問AC
ac上創建了vlan10-60,不同的ap綁定射頻和不同的vlan
總之就是vlan10下ap綁定vlan10,連接的終端不通內網,射頻綁定到其他vlan反倒可以(應該是走的ac隧道)
(0)
方便發配置看一下嗎?要不然不好發現問題
(0)
nqa entry h3c_g_b52680 test type icmp-echo destination ip 114.114.114.114 frequency 5000 history-record enable history-record number 1 probe timeout 500 # nqa schedule h3c_g_b52680 test start-time now lifetime forever # wlan service-template st_4460598527748232 description 1 ssid KQGYL akm mode psk preshared-key pass-phrase cipher $c$3$mCTtvJd8kjecReqHDR9oIweqDIcQsHgA/clH+C4C cipher-suite ccmp cipher-suite tkip security-ie rsn security-ie wpa bss transition-management enable portal domain cloud service-template enable # wlan service-template st_06250951092244272 description 1 ssid KQ-IOT user-isolation enable akm mode psk preshared-key pass-phrase cipher $c$3$Lgb7bQuZwJz9ZoVmKtSdONyAib2WSh94Ficot2Bs6oA= cipher-suite ccmp cipher-suite tkip security-ie rsn security-ie wpa bss transition-management enable portal domain cloud service-template enable # wlan service-template st_18179241701327298 description 2 ssid KQ-Guest user-isolation enable akm mode psk preshared-key pass-phrase cipher $c$3$OyebvlboqAEcxOGHl4Rmgd6PRz1fNBc3INvTflnu cipher-suite ccmp cipher-suite tkip security-ie rsn security-ie wpa bss transition-management enable portal domain cloud service-template enable # wlan service-template test ssid test client forwarding-location ap vlan 10 bss transition-management enable service-template enable # interface NULL0 # interface Vlan-interface10 ip address 192.168.10.200 255.255.255.0 portal enable method layer3 portal apply web-server go # interface GigabitEthernet1/0/1 port link-mode bridge port link-type hybrid port hybrid vlan 1 untagged # interface GigabitEthernet1/0/2 port link-mode bridge # interface GigabitEthernet1/0/3 port link-mode bridge # interface GigabitEthernet1/0/4 port link-mode bridge port link-type hybrid port hybrid vlan 1 untagged # interface GigabitEthernet1/0/5 port link-mode bridge port link-type trunk port trunk permit vlan 1 10 20 30 40 50 60 70 # scheduler logfile size 16 # line class console user-role network-admin # line class vty user-role network-operator # line con 0 authentication-mode scheme user-role network-admin # line vty 0 31 authentication-mode scheme user-role network-operator # ip route-static 0.0.0.0 0 192.168.10.1 # undo info-center logfile enable info-center source STAMGR console deny info-center source STAMGR logbuffer deny # ssh server enable sftp server enable scp server enable # nqa server enable # ntp-service enable ntp-service unicast-server ***.*** # acl basic name guest # acl mac name guest rule 0 permit # domain system authentication portal radius-scheme ruoyi-radius # domain default enable system #
nqa entry h3c_g_b52680 test type icmp-echo destination ip 114.114.114.114 frequency 5000 history-record enable history-record number 1 probe timeout 500 # nqa schedule h3c_g_b52680 test start-time now lifetime forever # wlan service-template st_4460598527748232 description 1 ssid KQGYL akm mode psk preshared-key pass-phrase cipher $c$3$mCTtvJd8kjecReqHDR9oIweqDIcQsHgA/clH+C4C cipher-suite ccmp cipher-suite tkip security-ie rsn security-ie wpa bss transition-management enable portal domain cloud service-template enable # wlan service-template st_06250951092244272 description 1 ssid KQ-IOT user-isolation enable akm mode psk preshared-key pass-phrase cipher $c$3$Lgb7bQuZwJz9ZoVmKtSdONyAib2WSh94Ficot2Bs6oA= cipher-suite ccmp cipher-suite tkip security-ie rsn security-ie wpa bss transition-management enable portal domain cloud service-template enable # wlan service-template st_18179241701327298 description 2 ssid KQ-Guest user-isolation enable akm mode psk preshared-key pass-phrase cipher $c$3$OyebvlboqAEcxOGHl4Rmgd6PRz1fNBc3INvTflnu cipher-suite ccmp cipher-suite tkip security-ie rsn security-ie wpa bss transition-management enable portal domain cloud service-template enable # wlan service-template test ssid test client forwarding-location ap vlan 10 bss transition-management enable service-template enable # interface NULL0 # interface Vlan-interface10 ip address 192.168.10.200 255.255.255.0 portal enable method layer3 portal apply web-server go # interface GigabitEthernet1/0/1 port link-mode bridge port link-type hybrid port hybrid vlan 1 untagged # interface GigabitEthernet1/0/2 port link-mode bridge # interface GigabitEthernet1/0/3 port link-mode bridge # interface GigabitEthernet1/0/4 port link-mode bridge port link-type hybrid port hybrid vlan 1 untagged # interface GigabitEthernet1/0/5 port link-mode bridge port link-type trunk port trunk permit vlan 1 10 20 30 40 50 60 70 # scheduler logfile size 16 # line class console user-role network-admin # line class vty user-role network-operator # line con 0 authentication-mode scheme user-role network-admin # line vty 0 31 authentication-mode scheme user-role network-operator # ip route-static 0.0.0.0 0 192.168.10.1 # undo info-center logfile enable info-center source STAMGR console deny info-center source STAMGR logbuffer deny # ssh server enable sftp server enable scp server enable # nqa server enable # ntp-service enable ntp-service unicast-server ***.*** # acl basic name guest # acl mac name guest rule 0 permit # domain system authentication portal radius-scheme ruoyi-radius # domain default enable system #
***.***/wiki/VWVOwNotXieIyfksyn8cTgS4nwb?from=from_copylink
https://mcncdf9ynq6w.飛書.cn/ 被屏蔽了,麻煩拚一下 wiki/VWVOwNotXieIyfksyn8cTgS4nwb?from=from_copylink
***.***/ 好了 wiki/VWVOwNotXieIyfksyn8cTgS4nwb?from=from_copylink
親~登錄後才可以操作哦!
確定你的郵箱還未認證,請認證郵箱或綁定手機後進行當前操作
舉報
×
侵犯我的權益
×
侵犯了我企業的權益
×
抄襲了我的內容
×
原文鏈接或出處
誹謗我
×
對根叔社區有害的內容
×
不規範轉載
×
舉報說明
***.***/ 好了 wiki/VWVOwNotXieIyfksyn8cTgS4nwb?from=from_copylink