AC在外网AP在内网 (高级)
实验拓扑
项目须知:AP在内网,经过NAT转换,到公网找AC,进行注册,注意此种组网方案:AP采用本地转发
配置步骤
1、出口NAT设备配置
sysname NAT
#
ospf 1
default-route-advertise always // 发布默认路由
area 0.0.0.0
network 10.1.1.0 0.0.0.3
#
interface GigabitEthernet0/0
ip address 100.1.1.1 255.255.255.0 // nat地址转化
nat outbound 2000
#
interface GigabitEthernet0/1
ip address 10.1.1.1 255.255.255.252
#
ip route-static 0.0.0.0 0 100.1.1.2
#
acl basic 2000
rule 0 permit // 允许AP地址段上网
2、内网交换机SW配置
sysname SW1
#
ospf 1
area 0.0.0.0
network 10.1.1.0 0.0.0.3
network 192.168.1.0 0.0.0.255
#
dhcp enable
#
vlan 10
#
vlan 20
description ==AP== // AP获取IP地址
#
vlan 30
description ==user== // 无线用户获取地IP地址
#
dhcp server ip-pool ap
gateway-list 192.168.1.1
network 192.168.1.0 mask 255.255.255.0
option 138 ip-address 200.1.1.2 // 通知AC注册地址
#
dhcp server ip-pool user
gateway-list 30.1.1.1
network 30.1.1.0 mask 255.255.255.0
dns-list 8.8.8.8
#
interface Vlan-interface10
ip address 10.1.1.2 255.255.255.252
#
interface Vlan-interface20
description ==AP==
ip address 192.168.1.1 255.255.255.0
#
interface Vlan-interface30
description ==user==
ip address 30.1.1.1 255.255.255.0
#
interface GigabitEthernet1/0/1
port access vlan 10
#
interface GigabitEthernet1/0/2
port link-type trunk
port trunk permit vlan 1 20 30
port trunk pvid vlan 20
#
interface GigabitEthernet1/0/3
port access vlan 20
3、模拟ISP路由器配置
sysname ISP
#
interface GigabitEthernet0/0
ip address 100.1.1.2 255.255.255.0
#
interface GigabitEthernet0/1
ip address 200.1.1.1 255.255.255.0
4、无线控制器AC配置
sysname AC
#
wlan global-configuration
#
vlan 30
#
wlan service-template 1
ssid H3C
vlan 30
client forwarding-location ap // 本地转发
service-template enable
#
interface GigabitEthernet1/0/1
port link-mode route
combo enable fiber
ip address 200.1.1.2 255.255.255.0
#
ip route-static 0.0.0.0 0 200.1.1.1
#
wlan ap 1 model WA6320-HCL
serial-id H3C_46-3E-29-CF-03-00
map-configuration flash:/ap.txt // 上传本地转发需要文档
vlan 1
radio 1
radio enable
service-template 1
radio 2
radio enable
service-template 1
gigabitethernet 1
5、本地转发 ap.txt配置内容,上传到AC中
system-veiw
vlan 30
int g/0/0
port link-type trunk
port trunk permit vlan 30
6、测试情况
1:查看AP上线情况 display wlan ap all
2: 查看用户上线情况