# 创建业务VLAN30
vlan 30
# 三层接口,用户网关
interface Vlan-interface 30
ip address 3.3.3.1 255.255.255.0
# DHCP地址池,下发3.3.3.0段
dhcp server ip-pool WLAN-USER
network 3.3.3.0 mask 255.255.255.0
gateway-list 3.3.3.1
dns-list 223.5.5.5
lease day 3
# 全局开启DHCP
dhcp server enable
# 互联接口透传VLAN30到下联S6850_2
interface GigabitEthernet 1/0/1
port link-type trunk
port trunk permit vlan 10 30
# 上联核心透传VLAN30
interface GigabitEthernet 1/0/1
port link-type trunk
port trunk permit vlan 10 30
# AP接入上联口,Trunk放行管理VLAN(2.2.2.0对应VLAN)+业务VLAN30
interface GigabitEthernet 1/0/2
port link-type trunk
port trunk permit vlan AP-MGMT-VLAN 30
# AP三层网关Vlanif(2.2.2.1)配置不变
interface Vlan-interface AP-MGMT-VLAN
ip address 2.2.2.1 255.255.255.0
wlan service-template WLAN-LOCAL
ssid Office-WiFi
# 开启本地转发(核心命令,业务流量不回AC)
client forwarding-mode local
# 指定用户业务VLAN30
service-vlan 30
# 认证按需配置(open/802.1x/portal)
client-security authentication-mode open
wlan ap ap3 model WAxxxx
serial-id xxxx-xxxx
radio 1
service-template WLAN-LOCAL
radio 2
service-template WLAN-LOCAL
# AC静态路由回程AP管理网段2.2.2.0/24
ip route-static 2.2.2.0 255.255.255.0 10.0.0.254
service-vlan 30,默认 VLAN1;client forwarding-mode local,变成集中转发,流量回 AC 无 3.3.3.0 网段;
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
那就中继呗