
拓撲如上,需實現兩個ssid 的網段隔離,模擬環境發現無線終端連接ssid獲取dhcp失敗.
補充:
核心配置:
dhcp enable
vlan 1
#
vlan 10
vlan 20
vlan 30
dhcp server ip-pool vlan10
gateway-list 192.168.10.1
network 192.168.10.0 mask 255.255.255.0
dns-list 8.8.8.8
#
dhcp server ip-pool vlan20
gateway-list 192.168.20.1
network 192.168.20.0 mask 255.255.255.0
dns-list 8.8.8.8
#
dhcp server ip-pool vlan30
gateway-list 192.168.30.1
network 192.168.30.0 mask 255.255.255.0
dns-list 8.8.8.8
#
interface Vlan-interface10
description 管理vlan10
ip address 192.168.10.1 255.255.255.0
#
interface Vlan-interface20
description 業務vlan20
ip address 192.168.20.1 255.255.255.0
#
interface Vlan-interface30
description guest訪客vlan30
ip address 192.168.30.1 255.255.255.0
#
#
interface GigabitEthernet1/0/10 // 核心 與 AC連接的接口
port link-mode bridge
description to AC
port link-type trunk
port trunk permit vlan 1 10 20 30
combo enable fiber
#
interface GigabitEthernet1/0/11 //核心與接入poe交換機連接的接口
port link-mode bridge
description to SW_POE
port link-type trunk
port trunk permit vlan 1 10 20 30
port trunk pvid vlan 10
combo enable fiber
###############################
接入的POE交換機 switch-poe配置:
#
vlan 1
#
vlan 10
#
vlan 20
#
vlan 30
#
#
interface Vlan-interface10
ip address dhcp-alloc
#
interface GigabitEthernet1/0/1
port link-mode bridge
description to Core
port link-type trunk
port trunk permit vlan 1 10 20 30
port trunk pvid vlan 10
combo enable fiber
#
#
interface GigabitEthernet1/0/3 // poe交換機與 AP3接口
port link-mode bridge
description ap3
port link-type trunk
port trunk permit vlan 1 10 20 30
port trunk pvid vlan 10
combo enable fiber
#
interface GigabitEthernet1/0/4 // poe交換機與 AP4接口
port link-mode bridge
description ap4
port link-type trunk
port trunk permit vlan 1 10 20 30
port trunk pvid vlan 10
combo enable fiber
接口:display ip int brief
Interface Physical Protocol IP Address Description
MGE0/0/0 down down -- --
Vlan10 up up 192.168.10.3 --
##################################################
AP配置:
vlan 1 10 20 30
interface GigabitEthernet0/0/1 // 與接入poe交換機的接口配置
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 10 20 30
combo enable fiber
AP的接口狀態
display ip int brief
*down: administratively down
(s): spoofing (l): loopback
Interface Physical Protocol IP Address Description
Vlan1 up up 192.168.10.2 --
Vlan20 up up 192.168.20.2 --
Vlan30 up up 192.168.30.2 --
測試 在ap上創建 vlanif 20 30 均可以獲取到核心的dhcp,但是無線ssid就不行。
##############################################################
AC配置:
vlan 1
#
vlan 10
#
vlan 20
#
vlan 30
#
vlan 99
#
wlan service-template dyx_ssid1
description 192.168.20.0/24
ssid dyx_ssid1_vlan20
vlan 10
beacon ssid-hide
client association-location ap
client forwarding-location ap vlan 20
akm mode psk
preshared-key pass-phrase cipher $c$3$8zYmW/kmR3Dq9LhTeO35oMppiTRXiwMOoDrJRcPB
cipher-suite ccmp
security-ie rsn
service-template enable
#
wlan service-template vlan30
ssid vlan30
beacon ssid-hide
client forwarding-location ap vlan 30
service-template enable
#
#
interface Vlan-interface10
ip address dhcp-alloc
#
#
interface GigabitEthernet1/0/0 // 與核心的接口
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 10 20 30
combo enable fiber
#
#
ip http enable
ip https enable
#
wlan ap-group default-group
vlan 1
radio-load-balance band-navigation enable association-reject
ap-model WA6320-HCL
map-configuration flash:/AP_map.txt
radio 1
radio enable
radio 2
radio enable
service-template vlan30 vlan 30
service-template dyx_ssid1 vlan 20
gigabitethernet 1
#
wlan virtual-ap-group default-virtualapgroup
#
wlan ap AP3 model WA6320-HCL
serial-id H3C_B2-B9-D7-69-03-00
description 左側AP3
map-configuration flash:/AP_map.txt
vlan 1
radio 1
radio 2
service-template dyx_ssid1
service-template vlan30
gigabitethernet 1
#
wlan ap AP4 model WA6320-HCL
serial-id H3C_B2-BA-04-B4-04-00
description 右側AP4
map-configuration flash:/AP_map.txt
vlan 1
radio 1
radio 2
service-template dyx_ssid1 vlan 20
service-template vlan30 vlan 30
gigabitethernet 1
#
return
<AC_5>
AC下發的 MAP文件:
system-view
vlan 20
quit
vlan 30
quit
interface GE0/0/1
port link-type trunk
port trunk permit vlan 10 20 30
quit
問題:不知為何 無線移動終端 連接wifi獲取不到ip地址,是否配置有問題。 1,vlan透傳部分,2.,ac配置部分。
(0)
可以在AP上配置一個vlan 20 30的虛接口讓他自動獲取看下是否正常,如果不正常可以手工配置VLAN20 30的地址ping測試看下
(1)
謝謝老師
配置看著沒問題,可能是模擬器的問題,找個真機配置看下
(1)
謝謝老師
謝謝老師
親~登錄後才可以操作哦!
確定你的郵箱還未認證,請認證郵箱或綁定手機後進行當前操作
舉報
×
侵犯我的權益
×
侵犯了我企業的權益
×
抄襲了我的內容
×
原文鏈接或出處
誹謗我
×
對根叔社區有害的內容
×
不規範轉載
×
舉報說明
謝謝老師