防火墙上网配置请参考“2.2 防火墙上网配置方法”进行配置,本文只针对无线配置进行介绍。
#创建vlan1的接口,并设置IP地址为192.168.20.1。
<H3C>system-view
[H3C]interface Vlan-interface 1
[H3C-Vlan-interface1]ip address 192.168.20.11 24
[H3C-Vlan-interface1]quit
#将Vlan-interface 1从Management区域换到trust区域。
[H3C]security-zone name Management
[H3C-security-zone-Management]undo import interface Vlan-interface 1
[H3C-security-zone-Management]quit
[H3C]security-zone name trust
[H3C-security-zone-Trust]import interface Vlan-interface 1
[H3C-security-zone-Trust]quit
#配置安全策略放通trust和local之间的数据。
[H3C]security-policy ip
[H3C-security-policy-ip]rule name hutong
[H3C-security-policy-ip-0-hutong]action pass
[H3C-security-policy-ip-0-hutong]source-zone trust
[H3C-security-policy-ip-0-hutong]source-zone local
[H3C-security-policy-ip-0-hutong]destination-zone trust
[H3C-security-policy-ip-0-hutong]destination-zone local
[H3C-security-policy-ip-0-hutong]quit
[H3C-security-policy-ip]quit
#开启DHCP服务并制定动态下发的地址以及网关等参数。
[H3C]dhcp enable
[H3C]dhcp server ip-pool 0
[H3C-dhcp-pool-0]network 192.168.20.0 24
[H3C-dhcp-pool-0]gateway-list 192.168.20.11
[H3C-dhcp-pool-0]dns-list 114.114.114.114
[H3C-dhcp-pool-0]quit
#开启AP的自动注册及自动固化,使AP能够自动上线并固化为手工AP(AP首次注册需15分钟以上)。
[H3C]wlan auto-ap enable
[H3C]wlan auto-persistent enable
#创建无线服务模板,ssid为FWLAN
[H3C]wlan service-template 0
[H3C-wlan-st-0]ssid FWLAN
#配置AKM为PSK,配置PSK密钥,使用明文的字符串12345678作为共享密钥。
[H3C-wlan-st-0]akm mode psk
[H3C-wlan-st-0]preshared-key pass-phrase simple 12345678
# 配置CCMP为加密套件,配置WPA2为安全信息元素。
[H3C-wlan-st-0]cipher-suite ccmp
[H3C-wlan-st-0]security-ie wpa
# 使能无线服务模板。
[H3C-wlan-st-0]service-template enable
[H3C-wlan-st-0]quit
#查看注册上线的AP
[H3C]display wlan ap all
Total number of APs: 1
Total number of connected APs: 1
Total number of connected manual APs: 1
Total number of connected auto APs: 0
Total number of connected common APs: 1
Total number of connected WTUs: 0
Total number of inside APs: 0
Maximum supported APs: 16
Remaining APs: 15
Total AP licenses: 20
Local AP licenses: 20
Server AP licenses: 0
Remaining Local AP licenses: 19
Sync AP licenses: 0
AP information
State : I = Idle, J = Join, JA = JoinAck, IL = ImageLoad
C = Config, DC = DataCheck, R = Run, M = Master, B = Backup
AP name APID State Model Serial ID
782c-2975-5180 1 R/M SIC-AP220 219801A1HK8194E0001Q
#进入已上线的AP,开启射频并绑定无线服务模板
[H3C]wlan ap 782c-2975-5180
[H3C-wlan-ap-782c-2975-5180]radio 1
[H3C-wlan-ap-782c-2975-5180-radio-1]radio enable
[H3C-wlan-ap-782c-2975-5180-radio-1]service-template 0
[H3C-wlan-ap-782c-2975-5180-radio-1]radio 2
[H3C-wlan-ap-782c-2975-5180-radio-2]radio enable
[H3C-wlan-ap-782c-2975-5180-radio-2]service-template 0
[H3C-wlan-ap-782c-2975-5180-radio-2]quit
[H3C-wlan-ap-782c-2975-5180]quit
[H3C]save force
Validating file. Please wait...
Saved the current configuration to mainboard device successfully.
<H3C>display wlan client
Total number of clients: 1
MAC address User name AP name RID IP address VLAN
044a-6cdb-7a33 N/A 782c-2975-5180 1 192.168.20.4 1
无
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作