一台H3C WX2540H(Version 7.1.064, Release 5272),在ac上配置portal认证。使用二层旁路组网:AC——核心交换机——poe交换机——AP,核心交换机通过防火墙连接外网。
1)dhcp在AC上(在核心上也试过,网关指向核心或指向AC都试过,都出现过客户端无法获取IP情况)。
2)现在客户端获取IP并经过认证后,只能ping通同网段IP,ping核心交换机上不同网段IP不通。路由都加过。
3)客户端经常掉线,需要重连,有时重连连不上,无法获取IP。
(0)
最佳答案
				
				
					1、可以发配置文档出来看看嘛,看下配置是什么样的,应该不会获取不到IP地址才对
2、获取IP并经过认证后只能ping通同网段IP,检查认证配置是否有问题,只能访问同网段可能是由于认证有问题,在ac上没有生成认证表项导致只能访问同网段ip
3、客户端重连是因为没有流量上行的时候,认证服务器会认为这个终端已经休眠了或是没在使用了,而把客户端踢下线
(0)
配置如下,您帮忙看看。
vlan101的网段是哪个网段,无线用户的dhcp现在是在核心还是ac
vlan100是给AP的,vlan101是给用户终端的。现在dhcp都在AC上
那vlan101的网段是40.0那个吗,我看你配置上没有配置int vlan 40的IP地址啊
配了,AC上vlan101的IP配了192.168.40.2,刚没复制上
那这个按理说不应该啊,地址都获取不到
是啊,同核心就是一个二层的互联。把pvid都换了一遍也不行。是不是在这个型号的AC上做portal认证会出现问题
掉线问题不要配置这一条authorization-attribute idle-cut 120 这是闲置切断的命令
哦哦,好的
把ac的版本升级至最新试试,版本有点低了
哦,好的
							
							
									
									
 version 7.1.064, Release 5272
#
 sysname AC
#
 clock protocol ntp
#
 telnet server enable
#
 dhcp enable
 dhcp server forbidden-ip 192.168.30.2
#
 dns server 114.114.114.114
#
 password-recovery enable
#
vlan 1
#
vlan 100
#
vlan 101
 name WIFI
#
dhcp server ip-pool 1
 gateway-list 192.168.30.1
 network 192.168.30.0 mask 255.255.254.0
 dns-list 202.99.96.68 133.16.40.2
#
dhcp server ip-pool WIFI
 gateway-list 192.168.40.1
 network 192.168.40.0 mask 255.255.255.0
 dns-list 202.99.96.68 114.114.114.114
#
wlan service-template 1
 ssid HXCZ-Guest
 vlan 101
 portal enable method direct
 portal domain portal
 portal apply web-server portal
 service-template enable
#
wlan service-template 2
 ssid HXCZ
 vlan 101
 portal enable method direct
 portal domain portal
 portal apply web-server portal
 portal apply mac-trigger-server localportal
 service-template enable
#
interface NULL0
#              
interface Vlan-interface100
 ip address 192.168.30.2 255.255.254.0
#
interface GigabitEthernet1/0/6
 port link-mode route
#
interface GigabitEthernet1/0/1
 port link-mode bridge
#
interface GigabitEthernet1/0/2
 port link-mode bridge
#
interface GigabitEthernet1/0/3
 port link-mode bridge
#
interface GigabitEthernet1/0/4
 port link-mode bridge
#
interface GigabitEthernet1/0/5
 port link-mode bridge
 port link-type trunk
 port trunk permit vlan all
#              
 scheduler logfile size 16
#
line class console
 user-role network-admin
#
line class vty
 user-role network-operator
#
line con 0
 authentication-mode scheme
 user-role network-admin
#
line vty 0 31
 authentication-mode scheme
 user-role network-operator
#
 ip route-static 0.0.0.0 0 192.168.30.1
#
 undo info-center enable
 undo info-center logfile enable
#
 ntp-service enable
 ntp-service unicast-server oasis.h3c.com
#
domain icu
#
domain portal
 authentication portal local
 authorization portal none
 accounting portal none
#
domain system
#
 domain default enable system
#
role name level-0
 description Predefined level-0 role
#
role name level-1
 description Predefined level-1 role
#
role name level-2
 description Predefined level-2 role
#
role name level-3
 description Predefined level-3 role
#
role name level-4
 description Predefined level-4 role
#
role name level-5
 description Predefined level-5 role
#
role name level-6
 description Predefined level-6 role
#
role name level-7
 description Predefined level-7 role
#
role name level-8
 description Predefined level-8 role
#
role name level-9
 description Predefined level-9 role
#
role name level-10
 description Predefined level-10 role
#
role name level-11
 description Predefined level-11 role
#
role name level-12
 description Predefined level-12 role
#
role name level-13
 description Predefined level-13 role
#
role name level-14
 description Predefined level-14 role
#
user-group system
#
local-user admin class manage
 password hash $h$6$l5JUYpUVXVpstSUh$iDZsNVpNDjBKaSOPWugH/OYD/Q4ulhMi2E4BXhiLKuaZfvAS6CJK1UWxCfxNElVGGlYSJsnJ9TPGT8imcBnNeg==
 service-type telnet http https
 authorization-attribute user-role network-admin
#
local-user hxcz class manage
 password hash $h$6$kwveLjVSU39n4+jn$7fUABLHqQt2ICJjb5U86LVAc1FCMAkuZ7qQ3bg0/MmEEUVn074hY9RJHJ5xWXzYXrq+UL7fLE5K13FweUp1Gzg==
 service-type ssh telnet terminal
 authorization-attribute user-role level-15
 authorization-attribute user-role network-admin
#
local-user admin class network
 password cipher $c$3$PlVDfuz6TFV8uIm/Dl3eENZARKSVGJ6I
 access-limit 100
 service-type portal
 authorization-attribute user-role network-operator
#
local-user test class network
 password cipher $c$3$j24YwPEUvvlEELJM/K53m1zE9kDdAjo=
 access-limit 60
 service-type portal
 authorization-attribute idle-cut 120
 authorization-attribute user-role network-operator
#
 portal host-check enable
 portal free-rule 1 destination ip 202.99.96.68 255.255.255.255
 portal free-rule 2 destination ip 114.114.114.114 255.255.255.255
 portal free-rule 3 source interface GigabitEthernet1/0/5
 portal free-rule 7 destination ip 192.168.30.0 255.255.255.0
 portal free-rule 8 source mac 10c7-53b6-5504
 portal free-rule 9 source mac 7cb3-7b8b-ae36
 portal free-rule 10 source mac 40cd-7a71-55c0
 portal free-rule 11 source mac 7cb3-7b78-11d8
 portal free-rule 12 source mac 40cd-7ab2-7b16
#
portal web-server portal
 url http://192.168.30.2/portal
#
portal local-web-server http 
 default-logon-page defaultfile.zip
#
 ip http enable
 ip https enable
#
portal mac-trigger-server localportal
 ip 192.168.30.2
 local-binding aging-time 10080
 local-binding enable
#
 wlan auto-ap enable
 wlan auto-persistent enable
#
wlan global-configuration
 nas-id cm-0-1298699-210235A1JM9208Q000B2
#
wlan ap-group default-group
 vlan 1
 ap-model WA5320-SI
  radio 1
   rate mandatory 12 24 
   rate supported 18 36 48 54 
   rate disabled 6 9 
   radio enable
  radio 2
   rate mandatory 11 
   rate supported 12 18 24 36 48 54 
   rate disabled 1 2 5.5 6 9 
   radio enable
  gigabitethernet 1
#
 cmtunnel server domain oasisdev.h3c.com
#
 cloud-management server domain oasis.h3c.com
#
return
(0)
							
							看配置,有几个问题点,无线是集中转发,正常是AC 本地PORTAL认证,但后面又是对接云简单平台;DHCP写的是30、40段,无线信号模板下应用的是100\101,要么是创建vlan 30\40,应用也是30、40,要么DHCP写的段是100、101;DHCP获取不到地址,最近做无线时遇到过,一般都是核心没有相应的vlan 或者交换机直连口没有放通相应的VLAN导致
(1)
	
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
哦,好的