AP 下的主机不能与交换机上其它的网段主机互访,配置如下;
Trying 192.168.12.254...
Connected to 192.168.12.254.
Escape character is '^]'.
******************************************************************************
* Copyright (c) 2004-2016 Hangzhou H3C Tech. Co., Ltd. All rights reserved. *
* Without the owner's prior written consent, *
* no decompiling or reverse-engineering shall be allowed. *
******************************************************************************
Login authentication
Username:admin
Password:
<WA4320-ACN-C>dis cu
#
version 5.20, Release 1508P08
#
sysname WA4320-ACN-C
#
domain default enable system
#
telnet server enable
#
undo wlan-client-isolation enable
#
port-security enable
#
password-recovery enable
#
undo attack-defense tcp fragment enable
#
vlan 1
#
vlan 5
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$YlX 9XQV0Ri/hsAglaoXJNhbHU1jCPo5Wu myYs=
authorization-attribute level 3
service-type telnet
service-type web
#
wlan rrm
dot11a mandatory-rate 6 12 24
dot11a supported-rate 9 18 36 48 54
dot11b mandatory-rate 1 2
dot11b supported-rate 5.5 11
dot11g mandatory-rate 1 2 5.5 11
dot11g supported-rate 6 9 12 18 24 36 48 54
#
wlan service-template 2 crypto
ssid Decomen
cipher-suite tkip
cipher-suite ccmp
security-ie rsn
security-ie wpa
service-template enable
#
cwmp
undo cwmp enable
#
interface NULL0
#
interface Vlan-interface5
ip address 192.168.12.254 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-type trunk
port trunk permit vlan all
#
interface WLAN-BSS34
port link-type hybrid
port hybrid vlan 1 5 untagged
port hybrid pvid vlan 5
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$ICypyGnlUSS VxG17x/y4ku4Zvoj2pZxNjGJ
#
interface WLAN-BSS35
port link-type hybrid
port hybrid vlan 1 5 untagged
port hybrid pvid vlan 5
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$ICypyGnlUSS VxG17x/y4ku4Zvoj2pZxNjGJ
#
interface WLAN-Radio1/0/1
service-template 2 interface wlan-bss 34
#
interface WLAN-Radio1/0/2
service-template 2 interface wlan-bss 35
#
ip route-static 0.0.0.0 0.0.0.0 192.168.12.1
#
undo info-center enable
#
ssh server enable
#
arp-snooping enable
#
load xml-configuration
#
load tr069-configuration
#
user-interface con 0
user-interface vty 0 4
authentication-mode scheme
#
return
<WA4320-ACN-C>
<WA4320-ACN-C>
<WA4320-ACN-C>
第三点路由有配置指向的!上常上网没有问题! 第四没有做过任何ACL