本手冊適用於如下產品:支持11ac協議的V5平台fat模式的ap,包含:WAP712C、WAP722等
設備默認管理地址是192.168.0.50,登錄賬號是admin/h3capadmin。
注:因AP的推薦功能是做無線接入點,推薦將NAT和路由做在上層路由設備上,AP推薦當無線交換機使用。
本案例介紹如何通過命令行給WAP712C配置靜態ip地址上網。
假設WAP712C 以太網口連接上層交換機(可以直連運營商),分配的公網地址、網關及DNS如下:
|
上聯地址 |
網關 |
DNS |
|
192.168.1.2/24 |
192.168.1.1/24 |
114.114.114.114 |
|
內網網段 |
內網網關 |
DNS |
|
192.168.10.0/24 |
192.168.10.1/24 |
114.114.114.114 |
AP發射無線信號讓無線終端連接並獲取地址上網。PC自動獲取192.168.10.0/24網段,網關為vlan2口地址192.168.10.1,DNS服務器地址為114.114.114.114。

外網ip vlan1:192.168.1.2
內網ip vlan2:192.168.10.1
# 配置外部ip地址。
[H3C]int Vlan-interface 1
[H3C-Vlan-interface1] ip address 192.168.1.2 24
[H3C-Vlan-interface1]quit
# 創建vlan2,配置內網ip地址。
[H3C]vlan 2
[H3C-vlan2]quit
[H3C]int Vlan-interface 2
[H3C-Vlan-interface2]ip address 192.168.10.2 24
[H3C-Vlan-interface2]quit
# 配置出口缺省路由下一跳指向公網網關,外網互聯接口下開啟NAT地址轉換功能。
[H3C]ip route-static 0.0.0.0 0 192.168.1.1
[H3C]int Vlan-interface 1
[H3C-Vlan-interface1]nat outbound
[H3C-Vlan-interface1]quit
# 給內網客戶端開啟地址自動分配功能,客戶端連接無線能自動獲取ip地址和網關以及DNS信息。
[H3C]dhcp enable
[H3C]dhcp server ip-pool 1
[H3C-dhcp-pool-1] network 192.168.10.0 24
[H3C-dhcp-pool-1] gateway-list 192.168.10.1
[H3C-dhcp-pool-1] dns-list 114.114.114.114
[H3C-dhcp-pool-1] quit
# 開啟端口安全功能(有無線秘鑰時必配),創建Bss口設置無線密碼12345678和無線客戶端所在VLAN2。
[H3C]port-security enable
[H3C]interface wlan-bss 1
[H3C-WLAN-BSS1]port-security port-mode psk
[H3C-WLAN-BSS1]port-security preshared-key pass-phrase simple 12345678
[H3C-WLAN-BSS1]port-security tx-key-type 11key
[H3C-WLAN-BSS1]port access vlan 2
[H3C-WLAN-BSS1]quit
# 設置無線服務模板,設置SSID為psktest並啟用。
[H3C]wlan service-template 1 crypto
[H3C-wlan-st-1]ssid psktest
[H3C-wlan-st-1]security-ie rsn
[H3C-wlan-st-1]cipher-suite ccmp
[H3C-wlan-st-1]authentication-method open-system
[H3C-wlan-st-1]service-template enable
[H3C-wlan-st-1]quit
# 進入無線radio口綁定服務模板。
[H3C]interface wlan-radio1/0/1
[H3C-WLAN-Radio1/0/1]service-template 1 interface wlan-bss 1
[H3C]interface wlan-radio1/0/2
[H3C-WLAN-Radio1/0/2]service-template 1 interface wlan-bss 1
[H3C-WLAN-Radio1/0/2]quit
[H3C]save force
我按照這樣的配置配置了無線路由,但是還是上不了網,有沒有大神能解釋一下
# version 5.20, Release 1509P01
# sysname WA4320
# clock timezone UTC add 00:00:00
# domain default enable system
# ip host DNS 218.203.59.116 ip host DNS1 218.203.59.216
# telnet server enable
# port-security enable
# password-recovery enable
# undo attack-defense tcp fragment enable
# vlan 1
# vlan 2
# domain system access-limit disable state active idle-cut disable self-service-url disable
# dhcp server ip-pool 1
network 192.168.10.0 mask 255.255.255.0
gateway-list 192.168.10.1
dns-list 218.203.59.116
# user-group system
group-attribute allow-guest
# local-user admin
password cipher $c$3$K+PTBmOvzwflQze7Oos+NvFDERIM23JA
authorization-attribute level 3
service-type telnet
service-type web
# wlan rrm
dot11a mandatory-rate 6 12 24
dot11a supported-rate 9 18 36 48 54
dot11b mandatory-rate 1 2
dot11b supported-rate 5.5 11
dot11g mandatory-rate 1 2 5.5 11
dot11g supported-rate 6 9 12 18 24 36 48 54
# wlan service-template 3 crypto
ssid DigitalBranch
cipher-suite ccmp
security-ie rsn
service-template enable
# cwmp undo cwmp enable
# interface NULL0
# interface Vlan-interface1
ip address 192.168.1.52 255.255.255.0
undo dhcp select server global-pool
nat outbound
# interface Vlan-interface2
ip address 192.168.10.2 255.255.255.0
# interface GigabitEthernet1/0/1
# interface WLAN-BSS36
port link-type hybrid
port hybrid vlan 1 to 2 untagged
port hybrid pvid vlan 2
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$vEzyPaFzIwwpS551kpsfoOTE7HPNcglSWNIw1A==
# interface WLAN-BSS37
port link-type hybrid
port hybrid vlan 1 to 2 untagged
port hybrid pvid vlan 2
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$vEzyPaFzIwwpS551kpsfoOTE7HPNcglSWNIw1A==
# interface WLAN-Radio1/0/1
service-template 3 interface wlan-bss 36
# interface WLAN-Radio1/0/2
service-template 3 interface wlan-bss 37
# ip route-static 0.0.0.0 0.0.0.0 192.168.1.1
# dhcp enable
# ssh server enable
# arp-snooping enable
# load xml-configuration
# load tr069-configuration
# user-interface con 0
user-interface vty 0 4
authentication-mode scheme #
(0)
找到原因了 內網地址應該是192.168.10.1
[H3C]vlan 2
[H3C-vlan2]quit
[H3C]int Vlan-interface 2
[H3C-Vlan-interface2]ip address 192.168.10.1 24
[H3C-Vlan-interface2]quit
這裏
(0)
✖
案例意見反饋
親~登錄後才可以操作哦!
確定你的郵箱還未認證,請認證郵箱或綁定手機後進行當前操作