AC6605无线组网实验ensp_安全策略

AC6605无线组网实验ensp_无线ap ac6605_02

101.AC6605无线组网实验

inte vlan 1

ip addr 10.0.10.254 24

dhcp enable

inte vlanif 1

dhcp select interface  接口地址模式

dhcp server excluded-ip-addres 10.0.10.254  排除服务器地址

quit

capwap source interface vlanif 1  为capwap绑定隧道(源端口绑定VLAN1)

wlan wlan视图

ap auth-mode mac-auth 认证模式为MAC认证

ap-id 1 ap-mac 0000-0000-cvbd 定义第一个ap ID为 1 绑定MAC

ap-name ap-1  ap 名字

2.创建安全策略

wlan

security-profile name sec-cfg-1 配置安全模板1

security wpa-wpa2 psk pass-phrase abcd1111 aes  安全策略

quit


ssid-profile name ssid-cfg-1 ssid模板

ssid wifi-2.4G 频段

quit

vap-profile name vap-cfg-1 vap模板

 forward-mode direct-forward  模式直接转发

 security-profile sec-cfg-1 引用安全模板

 ssid-profile ssid-cfg-1 引用ssid模板

ssid-profile name ssid-cfg-2 射频ssid模板

ssid wifi-5G

vap-profile name vap-cfg-2 vap模板

 forward-mode direct-forward  模式直接转发

 security-profile sec-cfg-1 引用安全模板1

 ssid-profile ssid-cfg-2 引用射频ssid模板


ap-name AP-1

vap-profile vap-cfg-1 wlan 1 radio 0

vap-profile vap-cfg-2 wlan 1 radio 1

quit

ap-name AP-2

vap-profile vap-cfg-1 wlan 1 radio 0

vap-profile vap-cfg-2 wlan 1 radio 1

quit


====================================================

<AC6605>syst

Enter system view, return user view with Ctrl+Z.

[AC6605]sysn ac-1

[ac-1]inte vlanif 1

[ac-1-Vlanif1]ip addr 10.0.10.254 24

[ac-1-Vlanif1]quit

[ac-1]dhcp enable

[ac-1]inte vlanif 1

[ac-1-Vlanif1]dhcp select interface  

[ac-1-Vlanif1]dhcp server excluded-ip-address 10.0.10.254

[ac-1-Vlanif1]quit

[ac-1]capwap source inte vlanif 1

[ac-1]wlan

[ac-1-wlan-view]ap auth-mode mac-auth  

[ac-1-wlan-view]ap-id 1 ap-mac 00E0-FC8A-1280

[ac-1-wlan-ap-1]ap-name AP-1

[ac-1-wlan-ap-1]quit

[ac-1-wlan-view]ap-id 2 ap-mac 00E0-FCAD-5160  

[ac-1-wlan-ap-2]ap-name AP-2

[ac-1-wlan-ap-2]quit

[ac-1-wlan-view]quit

[ac-1]disp ap all

Info: This operation may take a few seconds. Please wait for a moment.done.

Total AP information:

nor  : normal          [2]

--------------------------------------------------------------------------------

--------

ID   MAC            Name Group   IP          Type            State STA Uptime

--------------------------------------------------------------------------------

--------

1    00e0-fcbd-6350 AP-1 default 10.0.10.223 AP3030DN        nor   0   1M:13S

2    00e0-fcad-5160 AP-2 default 10.0.10.231 AP3030DN        nor   0   1S

--------------------------------------------------------------------------------

--------

Total: 2

==========================================================

[ac-1]wlan

[ac-1-wlan-view]security-profile name sec-cfg-1 安全模板

[ac-1-wlan-sec-prof-sec-cfg-1]security wpa-wpa2 psk pass-phrase abcd1111 aes 安全策略无线接入密码为abcd1111

[ac-1-wlan-sec-prof-sec-cfg-1]quit

[ac-1-wlan-view]ssid-profile name ssid-cfg-1 (SSID模板设置对应频段0)

[ac-1-wlan-ssid-prof-ssid-cfg-1]ssid wifi-2.4G

[ac-1-wlan-ssid-prof-ssid-cfg-1]quit

[ac-1-wlan-view]ssid-profile name ssid-cfg-2

[ac-1-wlan-ssid-prof-ssid-cfg-2]ssid wifi-5G  (SSID模板设置对应频段1)

[ac-1-wlan-ssid-prof-ssid-cfg-2]quit


[ac-1-wlan-view]vap-profile name vap-cfg-1 创建VAP模板1

[ac-1-wlan-vap-prof-vap-cfg-1]forward-mode direct-forward  转发模式为直接转发

[ac-1-wlan-vap-prof-vap-cfg-1]security-profile sec-cfg-1 引用安全模板

[ac-1-wlan-vap-prof-vap-cfg-1]ssid-profile ssid-cfg-1  引用SSID模板

[ac-1-wlan-vap-prof-vap-cfg-1]quit

[ac-1-wlan-view]vap-profile name vap-cfg-2  创建VAP模板2

[ac-1-wlan-vap-prof-vap-cfg-2]forward-mode direct-forward  转发模式为直接转发

[ac-1-wlan-vap-prof-vap-cfg-2]security-profile sec-cfg-1 引用安全模板

[ac-1-wlan-vap-prof-vap-cfg-2]ssid-profile ssid-cfg-2  引用SSID模板

[ac-1-wlan-vap-prof-vap-cfg-2]quit

[ac-1-wlan-view]

ap-name AP-1

[ac-1-wlan-AP-1]vap-profile vap-cfg-1 wlan 1 radio 0

[ac-1-wlan-AP-1]vap-profile vap-cfg-2 wlan 1 radio 1

quit

ap-name AP-2

[ac-1-wlan-AP-2]vap-profile vap-cfg-1 wlan 1 radio 0

[ac-1-wlan-AP-2]vap-profile vap-cfg-2 wlan 1 radio 1

quit