无线AC+瘦AP搭建好了,笔记本和苹果手机终端都能正常获取地址上网,唯独安卓手机获取不到地址,安卓手机设置静态地址又可以。
//client forwarding-location ap vlan xxx已加上也不行
组网描述
1.AC(WAC361)以trunk方式接入核心交换机,允许业务和管理通过,本AC做本地转发,只对AP进行管理,核心为AP和STA终端做DHCP
2.连接AP交换机口为trunk,放行业务和管理,pvid为管理vlan
3.无线配置使用正常,采用本地转发,目前存在问题是安卓手机不能获取地址,手动设置地址可上外网,苹果手机和笔记本电脑能正常获取地址,正常上网
4.无线名称全英文
---------------------------------------------
AC配置
<AC>dis cur
#
version 5.20, ESS 3703P73
#
sysname AC
#
clock timezone UTC add 00:00:00
#
domain default enable system
#
dns proxy enable
#
telnet server enable
#
port-security enable
#
wlan client learn-ipaddr enable
#
wlan auto-ap enable
wlan auto-persistent enable
#
password-recovery enable
#
vlan 1
#
vlan 10
#
vlan 100
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$Hcmh4398zUqVLR01HaC7wTNEyesRpTfkNcLU
authorization-attribute level 3
service-type telnet
service-type web
#
wlan rrm
dot11a mandatory-rate 6 12 24
dot11a supported-rate 9 18 36 48 54
dot11b mandatory-rate 1 2
dot11b supported-rate 5.5 11
dot11g mandatory-rate 1 2 5.5 11
dot11g supported-rate 6 9 12 18 24 36 48 54
dot11a calibrate-channel self-decisive
dot11a calibrate-power self-decisive
dot11bg calibrate-channel self-decisive
dot11bg calibrate-power self-decisive
#
wlan service-template 1 clear
ssid H3C
bind WLAN-ESS 1
#
wlan service-template 2 crypto
ssid TEST
bind WLAN-ESS 0
cipher-suite ccmp
security-ie rsn
security-ie wpa
undo gtk-rekey enable
client forwarding-mode local vlan 10
service-template enable
#
wlan ap-group default_group
ap bgl-4f-401
ap bgl-4f-402
ap bgl-5f-502
//此处省略其它AP信息
dot11a service-template 1
dot11a service-template 2
dot11bg service-template 1
dot11bg service-template 2
dot11a radio enable
dot11bg radio enable
#
interface Cellular1/0/1
async mode protocol
link-protocol ppp
#
interface NULL0
#
interface Vlan-interface1
#
interface Vlan-interface10
#
interface Vlan-interface100
ip address 172.16.0.4 255.255.255.0
#
interface GigabitEthernet1/0/5
port link-mode route
nat outbound
dns server 61.139.2.69
dns server 202.98.96.69
#
interface GigabitEthernet1/0/1
port link-mode bridge
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 10 100
dhcp-snooping trust
#
interface GigabitEthernet1/0/2
port link-mode bridge
#
interface GigabitEthernet1/0/3
port link-mode bridge
#
interface GigabitEthernet1/0/4
port link-mode bridge
#
interface WLAN-ESS0
port link-type hybrid
port hybrid vlan 1 10 untagged
port hybrid pvid vlan 10
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$k6zseWVQGohaOuiyQRqWb/Dx9nB9YR003jEv
#
interface WLAN-ESS1
port access vlan 10
#
interface WLAN-ESS2
port link-type hybrid
port hybrid vlan 1 untagged
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$/9ikxO5vptFM9rKnGCreED/7kpxL99j+aLxgKw==
#
interface WLAN-ESS3
port link-type hybrid
port hybrid vlan 1 10 untagged
port hybrid pvid vlan 10
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$WSxSoIiiXwm484RWS7fwSgnn7Rx8OAFft4oN
#
wlan ap 9c06-1b2b-2680 model WAP722E id 11
serial-id 219801A0Q39174G00879
radio 1
service-template 1
service-template 2
service-template 3
service-template 4
radio enable
radio 2
service-template 1
service-template 2
service-template 3
service-template 4
radio enable
//此处省略其它AP信息
#
wlan ips
malformed-detect-policy default
signature deauth_flood signature-id 1
signature broadcast_deauth_flood signature-id 2
signature disassoc_flood signature-id 3
signature broadcast_disassoc_flood signature-id 4
signature eapol_logoff_flood signature-id 5
signature eap_success_flood signature-id 6
signature eap_failure_flood signature-id 7
signature pspoll_flood signature-id 8
signature cts_flood signature-id 9
signature rts_flood signature-id 10
signature addba_req_flood signature-id 11
signature-policy default
countermeasure-policy default
attack-detect-policy default
virtual-security-domain default
attack-detect-policy default
malformed-detect-policy default
signature-policy default
countermeasure-policy default
#
dhcp-snooping
#
ip route-static 0.0.0.0 0.0.0.0 172.16.0.1
#
undo info-center enable
#
snmp-agent
snmp-agent local-engineid 800063A20360DA83B40B59
snmp-agent community read public
snmp-agent community write private
snmp-agent sys-info version all
#
ntp-service refclock-master 2
#
undo local-server log change-password-prompt
#
load xml-configuration
#
user-interface con 0
user-interface tty 4
user-interface vty 0 4
authentication-mode scheme
user privilege level 3
#
return
---------------------------------
AC web无线服务载图
(0)
最佳答案
信息太乱了
1、配置不合理,既然本地转发map文件呢
2、既然安卓静态ip正常,那说明无线ac工作正常呀
建议参考思路
1、是仔细检查下组网细节吧
2、另外v5设备大概率过保了,建议考虑续保或联系购买渠道H3C认证代理商沟通下细节由专业工程师定位处理
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论