拓扑如上,需实现两个ssid 的网段隔离,模拟环境发现无线终端连接ssid获取dhcp失败.
补充:
核心配置:
dhcp enable
vlan 1
#
vlan 10
vlan 20
vlan 30
dhcp server ip-pool vlan10
gateway-list 192.168.10.1
network 192.168.10.0 mask 255.255.255.0
dns-list 8.8.8.8
#
dhcp server ip-pool vlan20
gateway-list 192.168.20.1
network 192.168.20.0 mask 255.255.255.0
dns-list 8.8.8.8
#
dhcp server ip-pool vlan30
gateway-list 192.168.30.1
network 192.168.30.0 mask 255.255.255.0
dns-list 8.8.8.8
#
interface Vlan-interface10
description 管理vlan10
ip address 192.168.10.1 255.255.255.0
#
interface Vlan-interface20
description 业务vlan20
ip address 192.168.20.1 255.255.255.0
#
interface Vlan-interface30
description guest访客vlan30
ip address 192.168.30.1 255.255.255.0
#
#
interface GigabitEthernet1/0/10 // 核心 与 AC连接的接口
port link-mode bridge
description to AC
port link-type trunk
port trunk permit vlan 1 10 20 30
combo enable fiber
#
interface GigabitEthernet1/0/11 //核心与接入poe交换机连接的接口
port link-mode bridge
description to SW_POE
port link-type trunk
port trunk permit vlan 1 10 20 30
port trunk pvid vlan 10
combo enable fiber
###############################
接入的POE交换机 switch-poe配置:
#
vlan 1
#
vlan 10
#
vlan 20
#
vlan 30
#
#
interface Vlan-interface10
ip address dhcp-alloc
#
interface GigabitEthernet1/0/1
port link-mode bridge
description to Core
port link-type trunk
port trunk permit vlan 1 10 20 30
port trunk pvid vlan 10
combo enable fiber
#
#
interface GigabitEthernet1/0/3 // poe交换机与 AP3接口
port link-mode bridge
description ap3
port link-type trunk
port trunk permit vlan 1 10 20 30
port trunk pvid vlan 10
combo enable fiber
#
interface GigabitEthernet1/0/4 // poe交换机与 AP4接口
port link-mode bridge
description ap4
port link-type trunk
port trunk permit vlan 1 10 20 30
port trunk pvid vlan 10
combo enable fiber
接口:display ip int brief
Interface Physical Protocol IP Address Description
MGE0/0/0 down down -- --
Vlan10 up up 192.168.10.3 --
##################################################
AP配置:
vlan 1 10 20 30
interface GigabitEthernet0/0/1 // 与接入poe交换机的接口配置
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 10 20 30
combo enable fiber
AP的接口状态
display ip int brief
*down: administratively down
(s): spoofing (l): loopback
Interface Physical Protocol IP Address Description
Vlan1 up up 192.168.10.2 --
Vlan20 up up 192.168.20.2 --
Vlan30 up up 192.168.30.2 --
测试 在ap上创建 vlanif 20 30 均可以获取到核心的dhcp,但是无线ssid就不行。
##############################################################
AC配置:
vlan 1
#
vlan 10
#
vlan 20
#
vlan 30
#
vlan 99
#
wlan service-template dyx_ssid1
description 192.168.20.0/24
ssid dyx_ssid1_vlan20
vlan 10
beacon ssid-hide
client association-location ap
client forwarding-location ap vlan 20
akm mode psk
preshared-key pass-phrase cipher $c$3$8zYmW/kmR3Dq9LhTeO35oMppiTRXiwMOoDrJRcPB
cipher-suite ccmp
security-ie rsn
service-template enable
#
wlan service-template vlan30
ssid vlan30
beacon ssid-hide
client forwarding-location ap vlan 30
service-template enable
#
#
interface Vlan-interface10
ip address dhcp-alloc
#
#
interface GigabitEthernet1/0/0 // 与核心的接口
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 10 20 30
combo enable fiber
#
#
ip http enable
ip https enable
#
wlan ap-group default-group
vlan 1
radio-load-balance band-navigation enable association-reject
ap-model WA6320-HCL
map-configuration flash:/AP_map.txt
radio 1
radio enable
radio 2
radio enable
service-template vlan30 vlan 30
service-template dyx_ssid1 vlan 20
gigabitethernet 1
#
wlan virtual-ap-group default-virtualapgroup
#
wlan ap AP3 model WA6320-HCL
serial-id H3C_B2-B9-D7-69-03-00
description 左侧AP3
map-configuration flash:/AP_map.txt
vlan 1
radio 1
radio 2
service-template dyx_ssid1
service-template vlan30
gigabitethernet 1
#
wlan ap AP4 model WA6320-HCL
serial-id H3C_B2-BA-04-B4-04-00
description 右侧AP4
map-configuration flash:/AP_map.txt
vlan 1
radio 1
radio 2
service-template dyx_ssid1 vlan 20
service-template vlan30 vlan 30
gigabitethernet 1
#
return
<AC_5>
AC下发的 MAP文件:
system-view
vlan 20
quit
vlan 30
quit
interface GE0/0/1
port link-type trunk
port trunk permit vlan 10 20 30
quit
问题:不知为何 无线移动终端 连接wifi获取不到ip地址,是否配置有问题。 1,vlan透传部分,2.,ac配置部分。
(0)
可以在AP上配置一个vlan 20 30的虚接口让他自动获取看下是否正常,如果不正常可以手工配置VLAN20 30的地址ping测试看下
(1)
谢谢老师
配置看着没问题,可能是模拟器的问题,找个真机配置看下
(1)
谢谢老师
谢谢老师
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
谢谢老师