拓扑图如上,AP与S1在同一VLAN,S1与AC在同一VLAN,AP采用三层发现AC,AP与客户的DHCP由S1提供。
S1配置
vlan batch 10 20 30
dhcp enable
ip pool apgateway-list 192.168.20.1network 192.168.20.0 mask 255.255.255.0option 43 sub-option 3 ascii 192.168.10.2 //分配给ap地址池时,采用option 43指定AC管理地址interface Vlanif10ip address 192.168.10.1 255.255.255.0
#
interface Vlanif20ip address 192.168.20.1 255.255.255.0dhcp select global
#
interface Vlanif30ip address 192.168.30.1 255.255.255.0dhcp select interface
#
interface GigabitEthernet0/0/1port link-type trunkport trunk pvid vlan 20port trunk allow-pass vlan 10 20 30
#
interface GigabitEthernet0/0/2port link-type trunkport trunk allow-pass vlan 10 20
#
AC配置
#
vlan batch 10 20
#
interface Vlanif10ip address 192.168.10.2 255.255.255.0
#
interface GigabitEthernet0/0/1port link-type trunkport trunk allow-pass vlan 10 20
#
ip route-static 0.0.0.0 0.0.0.0 192.168.10.1
capwap source interface vlanif10wlan
regulatory-domain-profile name 123 设置国家码
country-code CN
ap-group name defaultregulatory-domain-profile dalong //关联域security-profile name dalong 配置模板security wpa2 psk pass-phrase %^%#{6rJLW`(bAW,~A%{LC8(W;ey0*Gs+E'+Z6&o#mhR%^%#
ssid-profile name dalongssid dalong
vap-profile name dalongforward-mode direct-forwardservice-vlan vlan-id 30ssid-profile dalongsecurity-profile dalongap-group name default
vap-profile dalong wlan 1 radio all//下发