大家好!经过大家的帮助配置上了AC带AP,也可以连接上AP了,现在就是上不了外网?怎么查故障啊?再次感谢大家的帮助,能否看下我这个配置是哪儿的问题?
H3C WX3024E AP模式配置如下:
<ap>disp cu
#
version 5.20, Release 3507P22
#
sysname ap
#
domain default enable system
#
telnet server enable
#
port-security enable
#
oap management-ip 192.168.0.101 slot 0
#
wlan auto-ap enable
#
password-recovery enable
#
vlan 1
#
vlan 4000 to 4001
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
dhcp server ip-pool vlan4000
network 10.80.255.0 mask 255.255.255.0
gateway-list 10.80.255.254
#
dhcp server ip-pool vlan4001
network 10.80.254.0 mask 255.255.255.0
gateway-list 10.80.254.254
dns-list 218.201.4.3 61.128.192.68
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$8xKWRHUPd5zq8q0oa34NOyPJ7ijpZod3
authorization-attribute level 3
service-type telnet
#
wlan rrm
dot11a mandatory-rate 6 12 24
dot11a supported-rate 9 18 36 48 54
dot11b mandatory-rate 1 2
dot11b supported-rate 5.5 11
dot11g mandatory-rate 1 2 5.5 11
dot11g supported-rate 6 9 12 18 24 36 48 54
#
wlan service-template 2 crypto
ssid zcjx
bind WLAN-ESS 1
cipher-suite ccmp
security-ie rsn
service-template enable
#
wlan ap-group default_group
ap cqzc
ap 7425-8a8b-0ba0
#
interface Bridge-Aggregation1
port link-type trunk
port trunk permit vlan all
#
interface NULL0
#
interface Vlan-interface4000
ip address 10.80.255.254 255.255.255.0
#
interface Vlan-interface4001
ip address 10.80.254.254 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
#
interface GigabitEthernet1/0/2
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
#
interface WLAN-ESS1
port access vlan 4001
port-security port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$Z+1S5gua91CIURxi+h5CEC3F9Mi
L4/774hf/ew==
#
wlan ap 7425-8a8b-0ba0 model WA2620i-AGN id 2
serial-id 219801A0CNC141002960
radio 1
service-template 2
radio enable
radio 2
service-template 2
radio enable
#
wlan ap cqzc model WA2620i-AGN id 1
serial-id auto
radio 1
service-template 2
radio enable
radio 2
service-template 2
radio enable
#
wlan ips
malformed-detect-policy default
signature deauth_flood signature-id 1
signature broadcast_deauth_flood signature-id 2
signature disassoc_flood signature-id 3
signature broadcast_disassoc_flood signature-id 4
signature eapol_logoff_flood signature-id 5
signature eap_success_flood signature-id 6
signature eap_failure_flood signature-id 7
signature pspoll_flood signature-id 8
signature cts_flood signature-id 9
signature rts_flood signature-id 10
signature addba_req_flood signature-id 11
signature-policy default
countermeasure-policy default
attack-detect-policy default
virtual-security-domain default
attack-detect-policy default
malformed-detect-policy default
signature-policy default
countermeasure-policy default
#
ip route-static 0.0.0.0 0.0.0.0 10.80.254.252
#
dhcp enable
#
user-interface con 0
user-interface vty 0 4
authentication-mode scheme
user privilege level 3
#
return
WX3024E 交换机模式配置如下:
<ap>oap connect slot 0
Press CTRL+K to quit.
Connected to OAP!
<h3c3024>disp cu
#
version 5.20, Release 3507P22
#
sysname h3c3024
#
domain default enable system
#
telnet server enable
#
oap management-ip 192.168.0.100 slot 1
#
password-recovery enable
#
vlan 1
#
vlan 4000 to 4001
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
user-group system
#
local-user admin
password cipher $c$3$hjd/ZlWhk36WqK0QYt4JylBOjOKsRUhS
authorization-attribute level 3
service-type telnet
#
interface Bridge-Aggregation1
port link-type trunk
port trunk permit vlan all
#
interface NULL0
#
interface Vlan-interface4000
ip address 10.80.255.253 255.255.255.0
#
interface Vlan-interface4001
ip address 10.80.254.253 255.255.255.0
#
interface GigabitEthernet1/0/1
poe enable
.
.
.
#
interface GigabitEthernet1/0/6
port access vlan 4000
poe enable
#
interface GigabitEthernet1/0/7
port access vlan 4001
poe enable
#
interface GigabitEthernet1/0/29
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
#
interface GigabitEthernet1/0/30
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
#
dhcp enable
#
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
user-interface vty 5 15
#
return
<h3c3024>
(0)
最佳答案
问题挺多,主要以下两点改一下:
1,把这些网络配置配到交换板卡上,AC板卡只配置无线注册信息:
dhcp信息
dhcp server ip-pool vlan4001
network 10.80.254.0 mask 255.255.255.0
gateway-list 10.80.254.254
dns-list 218.201.4.3 61.128.192.68
网关信息
interface Vlan-interface4001
ip address 10.80.254.254 255.255.255.0
2,不知道你是不是用3024E做核心,从你的配置上来看像是核心,如果是核心,应该上联路由器吧,那么你的3024 E就得做条缺省路由,下一跳指向路由器lan口,路由器和核心交换机起个互联网段,路由器做回程路由,下一跳指向交换机互联接口
(0)
你好!感谢你花这么多时间来帮助我排错。我的拓扑是:H3C-WX3024E(AC)——H3C S7506E-S(核心交换机)———AC1400(深信服行为网关)——H3C F-1000-S-AI(防火墙),深信服的行为网关是桥接的,还没做限制是全部放行,没有做任何限制,可以忽略这个设备不存在。你说的第一点DHCP和网关在核心交换机上有做,AP也获取得到IP地址,就是这个外网不通,是不是要在防火墙上还是在核心上做什么路由之类的?你看我这样的拓扑应该怎么去排错这个不能上外网的问题?再次感谢你。
你好!感谢你花这么多时间来帮助我排错。我的拓扑是:H3C-WX3024E(AC)——H3C S7506E-S(核心交换机)———AC1400(深信服行为网关)——H3C F-1000-S-AI(防火墙),深信服的行为网关是桥接的,还没做限制是全部放行,没有做任何限制,可以忽略这个设备不存在。你说的第一点DHCP和网关在核心交换机上有做,AP也获取得到IP地址,就是这个外网不通,是不是要在防火墙上还是在核心上做什么路由之类的?你看我这样的拓扑应该怎么去排错这个不能上外网的问题?再次感谢你。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明