一台H3C WX2540H(Version 7.1.064, Release 5272),在ac上配置portal认证。使用二层旁路组网:AC——核心交换机——poe交换机——AP,核心交换机通过防火墙连接外网。
1)dhcp在AC上(在核心上也试过,网关指向核心或指向AC都试过,都出现过客户端无法获取IP情况)。
2)现在客户端获取IP并经过认证后,只能ping通同网段IP,ping核心交换机上不同网段IP不通。路由都加过。
3)客户端经常掉线,需要重连,有时重连连不上,无法获取IP。
(0)
最佳答案
1、可以发配置文档出来看看嘛,看下配置是什么样的,应该不会获取不到IP地址才对
2、获取IP并经过认证后只能ping通同网段IP,检查认证配置是否有问题,只能访问同网段可能是由于认证有问题,在ac上没有生成认证表项导致只能访问同网段ip
3、客户端重连是因为没有流量上行的时候,认证服务器会认为这个终端已经休眠了或是没在使用了,而把客户端踢下线
(0)
配置如下,您帮忙看看。
vlan101的网段是哪个网段,无线用户的dhcp现在是在核心还是ac
vlan100是给AP的,vlan101是给用户终端的。现在dhcp都在AC上
那vlan101的网段是40.0那个吗,我看你配置上没有配置int vlan 40的IP地址啊
配了,AC上vlan101的IP配了192.168.40.2,刚没复制上
那这个按理说不应该啊,地址都获取不到
是啊,同核心就是一个二层的互联。把pvid都换了一遍也不行。是不是在这个型号的AC上做portal认证会出现问题
掉线问题不要配置这一条authorization-attribute idle-cut 120 这是闲置切断的命令
哦哦,好的
把ac的版本升级至最新试试,版本有点低了
哦,好的
version 7.1.064, Release 5272
#
sysname AC
#
clock protocol ntp
#
telnet server enable
#
dhcp enable
dhcp server forbidden-ip 192.168.30.2
#
dns server 114.114.114.114
#
password-recovery enable
#
vlan 1
#
vlan 100
#
vlan 101
name WIFI
#
dhcp server ip-pool 1
gateway-list 192.168.30.1
network 192.168.30.0 mask 255.255.254.0
dns-list 202.99.96.68 133.16.40.2
#
dhcp server ip-pool WIFI
gateway-list 192.168.40.1
network 192.168.40.0 mask 255.255.255.0
dns-list 202.99.96.68 114.114.114.114
#
wlan service-template 1
ssid HXCZ-Guest
vlan 101
portal enable method direct
portal domain portal
portal apply web-server portal
service-template enable
#
wlan service-template 2
ssid HXCZ
vlan 101
portal enable method direct
portal domain portal
portal apply web-server portal
portal apply mac-trigger-server localportal
service-template enable
#
interface NULL0
#
interface Vlan-interface100
ip address 192.168.30.2 255.255.254.0
#
interface GigabitEthernet1/0/6
port link-mode route
#
interface GigabitEthernet1/0/1
port link-mode bridge
#
interface GigabitEthernet1/0/2
port link-mode bridge
#
interface GigabitEthernet1/0/3
port link-mode bridge
#
interface GigabitEthernet1/0/4
port link-mode bridge
#
interface GigabitEthernet1/0/5
port link-mode bridge
port link-type trunk
port trunk permit vlan all
#
scheduler logfile size 16
#
line class console
user-role network-admin
#
line class vty
user-role network-operator
#
line con 0
authentication-mode scheme
user-role network-admin
#
line vty 0 31
authentication-mode scheme
user-role network-operator
#
ip route-static 0.0.0.0 0 192.168.30.1
#
undo info-center enable
undo info-center logfile enable
#
ntp-service enable
ntp-service unicast-server oasis.h3c.com
#
domain icu
#
domain portal
authentication portal local
authorization portal none
accounting portal none
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
password hash $h$6$l5JUYpUVXVpstSUh$iDZsNVpNDjBKaSOPWugH/OYD/Q4ulhMi2E4BXhiLKuaZfvAS6CJK1UWxCfxNElVGGlYSJsnJ9TPGT8imcBnNeg==
service-type telnet http https
authorization-attribute user-role network-admin
#
local-user hxcz class manage
password hash $h$6$kwveLjVSU39n4+jn$7fUABLHqQt2ICJjb5U86LVAc1FCMAkuZ7qQ3bg0/MmEEUVn074hY9RJHJ5xWXzYXrq+UL7fLE5K13FweUp1Gzg==
service-type ssh telnet terminal
authorization-attribute user-role level-15
authorization-attribute user-role network-admin
#
local-user admin class network
password cipher $c$3$PlVDfuz6TFV8uIm/Dl3eENZARKSVGJ6I
access-limit 100
service-type portal
authorization-attribute user-role network-operator
#
local-user test class network
password cipher $c$3$j24YwPEUvvlEELJM/K53m1zE9kDdAjo=
access-limit 60
service-type portal
authorization-attribute idle-cut 120
authorization-attribute user-role network-operator
#
portal host-check enable
portal free-rule 1 destination ip 202.99.96.68 255.255.255.255
portal free-rule 2 destination ip 114.114.114.114 255.255.255.255
portal free-rule 3 source interface GigabitEthernet1/0/5
portal free-rule 7 destination ip 192.168.30.0 255.255.255.0
portal free-rule 8 source mac 10c7-53b6-5504
portal free-rule 9 source mac 7cb3-7b8b-ae36
portal free-rule 10 source mac 40cd-7a71-55c0
portal free-rule 11 source mac 7cb3-7b78-11d8
portal free-rule 12 source mac 40cd-7ab2-7b16
#
portal web-server portal
url http://192.168.30.2/portal
#
portal local-web-server http
default-logon-page defaultfile.zip
#
ip http enable
ip https enable
#
portal mac-trigger-server localportal
ip 192.168.30.2
local-binding aging-time 10080
local-binding enable
#
wlan auto-ap enable
wlan auto-persistent enable
#
wlan global-configuration
nas-id cm-0-1298699-210235A1JM9208Q000B2
#
wlan ap-group default-group
vlan 1
ap-model WA5320-SI
radio 1
rate mandatory 12 24
rate supported 18 36 48 54
rate disabled 6 9
radio enable
radio 2
rate mandatory 11
rate supported 12 18 24 36 48 54
rate disabled 1 2 5.5 6 9
radio enable
gigabitethernet 1
#
cmtunnel server domain oasisdev.h3c.com
#
cloud-management server domain oasis.h3c.com
#
return
(0)
看配置,有几个问题点,无线是集中转发,正常是AC 本地PORTAL认证,但后面又是对接云简单平台;DHCP写的是30、40段,无线信号模板下应用的是100\101,要么是创建vlan 30\40,应用也是30、40,要么DHCP写的段是100、101;DHCP获取不到地址,最近做无线时遇到过,一般都是核心没有相应的vlan 或者交换机直连口没有放通相应的VLAN导致
(1)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
哦,好的