拓扑图如上,AP与S1在同一VLAN,S1与AC在同一VLAN,AP采用三层发现AC,AP与客户的DHCP由S1提供。
S1配置
vlan batch 10 20 30
dhcp enable
ip pool ap
gateway-list 192.168.20.1
network 192.168.20.0 mask 255.255.255.0
option 43 sub-option 3 ascii 192.168.10.2 //分配给ap地址池时,采用option 43指定AC管理地址
interface Vlanif10
ip address 192.168.10.1 255.255.255.0
#
interface Vlanif20
ip address 192.168.20.1 255.255.255.0
dhcp select global
#
interface Vlanif30
ip address 192.168.30.1 255.255.255.0
dhcp select interface
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk pvid vlan 20
port trunk allow-pass vlan 10 20 30
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 10 20
#
AC配置
#
vlan batch 10 20
#
interface Vlanif10
ip address 192.168.10.2 255.255.255.0
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20
#
ip route-static 0.0.0.0 0.0.0.0 192.168.10.1
capwap source interface vlanif10
wlan
regulatory-domain-profile name 123 设置国家码
country-code CN
ap-group name default
regulatory-domain-profile dalong //关联域
security-profile name dalong 配置模板
security wpa2 psk pass-phrase %^%#{6rJLW`(bAW,~A%{LC8(W;ey0*Gs+E'+Z6&o#mhR%^%#
ssid-profile name dalong
ssid dalong
vap-profile name dalong
forward-mode direct-forward
service-vlan vlan-id 30
ssid-profile dalong
security-profile dalong
ap-group name default
vap-profile dalong wlan 1 radio all//下发