之前设置不给上外网的,现在需要上外网
ac 配置如下:
#
version 5.20, ESS 3703P61
#
sysname H3C
#
domain default enable system
#
dns proxy enable
#
telnet server enable
#
port-security enable
#
wlan client learn-ipaddr enable
#
wlan auto-ap enable
wlan auto-persistent enable
#
password-recovery enable
#
vlan 1
#
vlan 10
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
dhcp server ip-pool ap
network 192.168.11.0 mask 255.255.255.0
gateway-list 192.168.11.1
#
dhcp server ip-pool client
network 192.168.10.0 mask 255.255.255.0
gateway-list 192.168.10.1
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$Cs1SGD0Tm7z+WL6bEOKad8RZYX86yjmz
authorization-attribute level 3
service-type telnet
service-type web
#
wlan rrm
dot11a mandatory-rate 6 12 24
dot11a supported-rate 9 18 36 48 54
dot11b mandatory-rate 1 2
dot11b supported-rate 5.5 11
dot11g mandatory-rate 1 2 5.5 11
dot11g supported-rate 6 9 12 18 24 36 48 54
#
wlan service-template 1 clear
ssid H3C
bind WLAN-ESS 1
#
wlan service-template 2 crypto
ssid XINHAOXUAN
bind WLAN-ESS 0
cipher-suite ccmp
security-ie rsn
security-ie wpa
#
wlan service-template 3 crypto
ssid XHX
bind WLAN-ESS 2
cipher-suite tkip
cipher-suite ccmp
security-ie rsn
security-ie wpa
service-template enable
#
wlan ap-group default_group
ap a-01
ap a-02
ap b-01
ap b-02
ap b-03
ap b-04
ap b-05
ap b-06
ap c-01
ap c-02
ap bb-01
ap bb-02
ap a-you01
ap a-zuo01
ap c-stm01
ap c-stm02
ap d-mumen
ap zong-01
ap zong-02
ap zong-03
ap zong-04
ap zong-05
ap zong-06
ap zong-07
ap zong-08
ap zong-09
ap zong-10
ap a-cangku
ap c-gubo01
ap c-gubo02
ap c-gubo03
ap a-houzoulang
dot11a service-template 1
dot11bg service-template 1
dot11a radio enable
dot11bg radio enable
#
interface Cellular1/0/1
async mode protocol
link-protocol ppp
#
interface NULL0
#
interface Vlan-interface1
ip address 192.168.10.1 255.255.255.0
#
interface Vlan-interface10
ip address 192.168.11.1 255.255.255.0
#
interface GigabitEthernet1/0/5
port link-mode route
ip address 192.168.0.235 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/2
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/3
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/4
port link-mode bridge
port access vlan 10
#
interface WLAN-ESS0
port link-type hybrid
port hybrid vlan 1 untagged
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$wZuhdkyAHQwzGEzUsgnVvbG1Xu8qNwWgyUtPxOU=
#
interface WLAN-ESS1
#
interface WLAN-ESS2
port link-type hybrid
port hybrid vlan 1 untagged
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$6iwKwZx0dlU141tqMnlKx0dudALq+Gb3pvbUuphB8w==
#
wlan ap a-01 model WAP712C id 22
serial-id 219801A0X4917BG004XF
radio 1
service-template 1
service-template 2
service-template 3
radio enable
radio 2
service-template 1
service-template 2
service-template 3
radio enable
#
wlan ap a-02 model WAP712C id 21
serial-id 219801A0X4917BG0064C
radio 1
service-template 1
service-template 2
service-template 3
radio enable
radio 2
service-template 1
service-template 2
service-template 3
radio enable
#
wlan ap a-cangku model WAP712C id 8
serial-id 219801A0X49183G002SC
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap a-houzoulang model WAP712C id 3
serial-id 219801A0X49183G002SV
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap a-you01 model WAP712C id 23
serial-id 219801A0X4917BG005S2
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap a-zuo01 model WAP712C id 7
serial-id 219801A0X4917BG0064P
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap b-01 model WAP712C id 4
serial-id 219801A0X4917BG005ZY
radio 1
service-template 1
service-template 2
service-template 3
radio enable
radio 2
service-template 1
service-template 2
service-template 3
radio enable
#
wlan ap b-02 model WAP712C id 6
serial-id 219801A0X4917BG0063Z
radio 1
service-template 1
service-template 2
service-template 3
radio enable
radio 2
service-template 1
service-template 2
service-template 3
radio enable
#
wlan ap b-03 model WAP712C id 10
serial-id 219801A0X4917BG005ZB
radio 1
service-template 1
service-template 2
service-template 3
radio enable
radio 2
service-template 1
service-template 2
service-template 3
radio enable
#
wlan ap b-04 model WAP712C id 11
serial-id 219801A0X4917BG005YK
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap b-05 model WAP712C id 2
serial-id 219801A0X4917BG001Z3
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap b-06 model WAP712C id 5
serial-id 219801A0X4917BG0060V
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap bb-01 model WAP712C id 29
serial-id 219801A0X59195G000HT
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap bb-02 model WAP712C id 28
serial-id 219801A0X59195G000MX
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap c-01 model WAP712C id 25
serial-id 219801A0X49176G01498
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap c-02 model WAP712C id 26
serial-id 219801A0X49176G01512
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap c-gubo01 model WAP712C id 30
serial-id 219801A0X49186G0034Z
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap c-gubo02 model WAP712C id 32
serial-id 219801A0X49195G001M9
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap c-gubo03 model WAP712C id 31
serial-id 219801A0X49195G001GX
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap c-stm01 model WAP712C id 12
serial-id 219801A0X49183G00032
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap c-stm02 model WAP712C id 14
serial-id 219801A0X49184G0006L
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap d-mumen model WAP712C id 27
serial-id 219801A0X4917BG0000D
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-01 model WAP712C id 13
serial-id 219801A0X4917BG005XR
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-02 model WAP712C id 24
serial-id 219801A0X4917BG0065D
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-03 model WAP712C id 15
serial-id 219801A0X4917BG0060M
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-04 model WAP712C id 20
serial-id 219801A0X4917BG0020J
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-05 model WAP712C id 1
serial-id 219801A0X4917BG0061J
country-code CN
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-06 model WAP712C id 16
serial-id 219801A0X4917BG0063R
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-07 model WAP712C id 18
serial-id 219801A0X4917BG005ZL
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-08 model WAP712C id 19
serial-id 219801A0X4917BG00631
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-09 model WAP712C id 17
serial-id 219801A0X4917BG005XH
radio 1
service-template 1
service-template 3
radio enable
radio 2
service-template 1
service-template 3
radio enable
#
wlan ap zong-10 model WAP712C id 9
serial-id 219801A0X4917BG00609
radio 1
service-template 1
service-template 2
service-template 3
radio enable
radio 2
service-template 1
service-template 2
service-template 3
radio enable
#
wlan ips
malformed-detect-policy default
signature deauth_flood signature-id 1
signature broadcast_deauth_flood signature-id 2
signature disassoc_flood signature-id 3
signature broadcast_disassoc_flood signature-id 4
signature eapol_logoff_flood signature-id 5
signature eap_success_flood signature-id 6
signature eap_failure_flood signature-id 7
signature pspoll_flood signature-id 8
signature cts_flood signature-id 9
signature rts_flood signature-id 10
signature addba_req_flood signature-id 11
signature-policy default
countermeasure-policy default
attack-detect-policy default
virtual-security-domain default
attack-detect-policy default
malformed-detect-policy default
signature-policy default
countermeasure-policy default
#
ip route-static 182.168.0.0 255.255.255.0 GigabitEthernet1/0/5 192.168.0.1 preference 62
ip route-static 192.168.0.0 255.255.255.0 GigabitEthernet1/0/5 192.168.0.1
ip route-static 192.168.9.0 255.255.255.0 GigabitEthernet1/0/5 192.168.0.1 preference 61
#
snmp-agent
snmp-agent local-engineid 800063A20394282E9879E9
snmp-agent community read public
snmp-agent community write private
snmp-agent sys-info version all
#
dhcp enable
#
ntp-service refclock-master 2
#
load xml-configuration
#
user-interface con 0
user-interface tty 4
user-interface vty 0 4
authentication-mode scheme
user privilege level 3
#
return
(0)
最佳答案
配的有点乱七八糟,
interface Vlan-interface1
ip address 192.168.10.1 255.255.255.0
#
interface Vlan-interface10
ip address 192.168.11.1 255.255.255.0#
interface GigabitEthernet1/0/5
port link-mode route
ip address 192.168.0.235 255.255.255.0
AC缺少静态路由。, ip rout 0.0.0.0 0 192.168.0.1, 这个是在AC做的二级路由的情况下。默认路由删除掉。
若做旁路的话,需要在AC新建一个虚接口, 修改intvlan1 ip add 192.168.0.222 24
静态路由 0.0.0.0 0 192.168.0.1
路由需要做个回程路由, 192.168.10.0 24 192.168.0.222
(0)
五号口在做个 NAT转换 NAT OUT
五号口在做个 NAT转换 NAT OUT
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
这种情况建议联系当地H3C办事处或当地H3C认证代理商沟通即可。