当前网络环境为上次交换机做了MAC绑定,客户电脑主机只能使用192.168.1.0/24网段的IP地址,未开启DHCP。
我手上的712C如标题所述,已刷入FAT版本固件,固件版本WA4300S-CMW520-R1508P02-FAT,可以通过进入到WEB管理界面,也可以通过串口进入命令行界面,请教在此种情况下,如何在WEB界面设置,才可以将AP设置成固定IP上网的模式,又该如何配置命令行?
另外如果可以的话,想知道内部各个interface之间,数据究竟是怎么跑的,接入无线网络的主机是怎么样通过AP(路由器)实现上网的。
感谢~
<Yuantian>dis cur
# version 5.20, Release 1508P11
# sysname Yuantian
# undo copyright-info enable
# domain default enable system
# telnet server enable
# port-security enable
# password-recovery enable
# undo attack-defense tcp fragment enable
# vlan 1
# domain system
access-limit disable
state active idle-cut
disable self-service-url
disable
# user-group
system group-attribute allow-guest
# local-user admin
password cipher $c$3$MDqSzz95XDWyx+jTv7ly6hb9GamPUqHrmdtU578=
authorization-attribute level
3 service-type telnet
service-type web
# wlan rrm
dot11a mandatory-rate 6 12 24
dot11a supported-rate 9 18 36 48 54
dot11b mandatory-rate 1 2
dot11b supported-rate 5.5 11
dot11g mandatory-rate 1 2 5.5 11
dot11g supported-rate 6 9 12 18 24 36 48 54
# wlan service-template 1 clear
ssid H3C
service-template enable
# cwmp
undo cwmp enable
# interface NULL0
# interface Vlan-interface1
ip address 192.168.0.50 255.255.255.0
# interface GigabitEthernet1/0/1
# interface WLAN-BSS32
port link-type hybrid
port hybrid vlan 1 untagged
# interface WLAN-BSS33
port link-type hybrid
port hybrid vlan 1 untagged
# interface WLAN-Radio1/0/1
# interface WLAN-Radio1/0/2
service-template 1 interface wlan-bss 33
# arp-snooping enable
# load xml-configuration
# load tr069-configuration
# user-interface con 0
user-interface vty 0 4
authentication-mode scheme
# return
(0)
最佳答案
参考配置为文档的快读配置,可以快速配置无线终端上网;
WAP712C不是定位为一款可以做出口的无线路由器,它的定位为最末端的无线终端接入,她也没有下行有线接口。
(0)
请问是否可以将设备的唯一的以太网口作为通常意义的wan口,把无线作为接入的端口,使用NAT及ACL来实现地址分配呢?
不建议这么干,可能会出问题。
嗯,很感谢你,但是却并没有解决我的问题,所以这里我不会采纳了。 另外,我上面的配置重新编辑了,是华三专家配置的,可参考。目前是可用的,稳定性还有待验证。
dis cur
# version 5.20, Release 1508P11
# sysname Yuantian
# domain default enable system
# telnet server enable
# port-security enable
# password-recovery enable
# undo attack-defense tcp fragment enable
# vlan 1
# vlan 100
# domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
# dhcp server
ip-pool 1111111
network 172.16.0.0
mask 255.255.255.0
gateway-list 172.16.0.1
dns-list 221.12.1.227
# user-group system
group-attribute allow-guest
# local-user admin
password cipher $c$3$2SNnzgOrHEXaM798PX9DuaBHUHtRktFEkSgHxo8=
authorization-attribute level 3
service-type telnet
# wlan rrm
dot11a mandatory-rate 6 12 24
dot11a supported-rate 9 18 36 48 54
dot11b mandatory-rate 1 2
dot11b supported-rate 5.5 11
dot11g mandatory-rate 1 2 5.5 11
dot11g supported-rate 6 9 12 18 24 36 48 54
# wlan service-template 1 clear
ssid office-YT
# wlan service-template 2 crypto
ssid office-YT
cipher-suite ccmp
security-ie rsn
security-ie wpa
service-template enable
# cwmp
undo cwmp enable
# interface NULL0
# interface Vlan-interface1
ip address 192.168.1.220 255.255.255.0
nat outbound
# interface Vlan-interface100
ip address 172.16.0.1 255.255.255.0
# interface GigabitEthernet1/0/1
# interface WLAN-BSS8
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 100 untagged
port hybrid pvid vlan 100
mac-vlan enable port-security
port-mode psk
port-security tx-key-type 11key
port-security preshared-key pass-phrase cipher $c$3$OrIfy/UWw+oDpUpQZXXHG34czqUg4ygscCOg9mE=
# interface WLAN-BSS32
port link-type hybrid
port hybrid vlan 1 untagged
# interface WLAN-BSS33
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 100 untagged
port hybrid pvid vlan 100
mac-vlan enable
port-security
port-mode psk
port-security tx-key-type 11key port-security preshared-key pass-phrase cipher $c$3$zTJp2kl4se4MbwweKJzHGGfrcCFZi/uqjUNYzW8=
# interface WLAN-Radio1/0/1
# interface WLAN-Radio1/0/2
service-template 2 interface wlan-bss 8
# ip route-static 0.0.0.0 0.0.0.0 192.168.1.1
# dhcp server forbidden-ip 172.16.0.1
# dhcp enable
# arp-snooping enable
# load xml-configuration
# load tr069-configuration
# user-interface con 0
user-interface vty 0 4
authentication-mode scheme
# return
(0)
这个是经调试后的命令行,可参考。
这个是经调试后的命令行,可参考。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
嗯,很感谢你,但是却并没有解决我的问题,所以这里我不会采纳了。 另外,我上面的配置重新编辑了,是华三专家配置的,可参考。目前是可用的,稳定性还有待验证。