资源描述
单击此处编辑母版标题样式,单击此处编辑母版文本样式,第二级,第三级,第四级,第五级,单击此处编辑母版标题样式,单击此处编辑母版文本样式,第二级,第三级,第四级,第五级,XXX,实验,5.3 简单的AC+FIT AP无线局域网实验,实验背景,1,实验目的与内容,2,实验设备,3,实验步骤,4,实验背景,FIT AP是新兴的一种WLAN组网模式,其相对FAT AP方案增加了Wireless Switch(无线交换机)作为中央集中控制管理设备,原先在FAT AP自身上承载的认证终结、漫游切换、动态密钥等复杂业务功能转移到Wireless Switch上来进行。AP与Wireless Switch之间通过隧道方式进行通信,之间可以跨越局域网络甚至广域网进行连接,因此减少了单个AP的负担,提高了整网的工作效率。同时由于FIT AP方案这种集中式管理的特点,可以很方便的通过升级Wireless Switch的软件版本实现更丰富业务功能的扩展。FIT AP的组网有三种模式:FIT AP与无线交换机相连,无线交换机接入IP网络;FIT AP与一般交换机相连,一般交换机与无线交换机相连,无线交换机再接入IP网络,FIT AP与无线交换机之间通过隧道进行通信;FIT AP与一般交换机相连,一般交换机接入IP网络,IP网络通过无线交换机接入Internet,通常在网络规模较大且存在分支机构应用无线网络的环境。,实验背景,表5.1 FAT AP方案与FIT AP方案的不同,实验目的与内容,【实验目的】,掌握简单的FIT AP无线局域网搭建技术。,【实验内容】,搭建FAT AP无线局域网,并通过交换机将无线局域网接入IP网。,实验设备,一个具有无线网卡的计算机,一个FIT AP,一个三层交换机,一个无线控制器,一个DHCP服务器,双绞线三根,配置线一根。网络拓扑结构如图5.10所示。,图5.10 简单的AC+FIT AP无线局域网实验拓扑结构图,实验步骤,1.设置无线控制器。,(1)初始化无线控制模块,设置相应的接口为Trunk接口并允许所有的VLAN通过。,system-view,H3Cinterface vlan-interface 1,H3C-vlan-interface1ip address 192.168.1.99 255.255.255.0,H3C-vlan-interface1quit,H3Csysname WC /无线控制模块更名为WC,WCinterface GigabitEthernet 1/0/1,WC-GigabitEthernet 1/0/1port link-type trunk,WC-GigabitEthernet 1/0/1port trunk permit vlan all,WC-GigabitEthernet 1/0/1quit,WCquit,(2)初始化交换模块,设置相应的接口为Trunk接口并允许所有的VLAN通过。,oap connect slot 0 /进入交换模块,system-view,H3Csysname SC /交换模块更名为SC,SCinterface GigabitEthernet 1/0/2,SC-GigabitEthernet 1/0/2port link-type trunk,SC-GigabitEthernet 1/0/2port trunk permit vlan all,实验步骤,SC-GigabitEthernet 1/0/2quit,SCCtrl+K /返回无线控制模块,(3)开启无线服务,创建VLAN,建立二层虚拟接口,system-view,WCwlan enable,WCvlan 2 to 4,WCinterface WLAN-ESS 1,WC-WLAN-ESS1port access vlan 4,(4)创建无线服务模板,配置SSID和认证方式,与虚拟接口1绑定并开启服务模板1,WC-WLAN-ESS1quit,WCwlan service-template 1 clear,WC-wlan-st-1ssid jsjxy,WC-wlan-st-1authentication-method open-system,WC-wlan-st-1bind WLAN-ESS 1,WC-wlan-st-1service-template enable,实验步骤,(5)设置注册AP参数,WC-wlan-st-1quit,WCwlan ap jsjzx model WA2600,WC-wlan-ap-jsjzxserial-id 625630A22W7662563265 /AP对应的序列号,(6)创建射频接口1,工作在802.11g,绑定服务模板1并开启射频接口,WC-wlan-ap-jsjzxradio 1 type dot11g,WC-wlan-ap-jsjzx-radio-1service-template 1,WC-wlan-ap-jsjzx-radio-1radio enable,WC-wlan-ap-jsjzx-radio-1quit,WC-wlan-ap-jsjzxquit,(7)设置路由,WCip route-static 0.0.0.0 0.0.0.0 192.168.1.254,实验步骤,2.设置三层交换机。,(1)建立相应的VLAN并设置接口地址,system-view,H3Csysname SWITCH,SWITCHvlan 2-4,SWITCHinterface vlan-interface 1,SWITCH-vlan-interface1ip address 192.168.1.254 24,SWITCH-vlan-interface1quit,SWITCHinterface vlan-interface 2,SWITCH-vlan-interface2ip address 192.168.2.254 24,SWITCH-vlan-interface2quit,SWITCHinterface vlan-interface 3,SWITCH-vlan-interface3ip address 192.168.3.254 24,SWITCH-vlan-interface3quit,SWITCHinterface vlan-interface 4,SWITCH-vlan-interface4ip address 192.168.4.254 24,SWITCH-vlan-interface4quit,(2)在FIT AP无外接电源的情况下,若交换模块的外部千兆以太网口2连接的是FIT AP,那么千兆接口2要开启POE供电。,实验步骤,SWITCHinterface GigabitEthernet 1/0/2,SWITCH-GigabitEthernet 1/0/2poe enable,SWITCH-GigabitEthernet 1/0/2quit,(3)开启DHCP服务,指明DHCP服务器地址,在VLAN接口2上告知AP如何获取地址,VLAN接口4上告知无线客户端如何获取地址,完成DHCP中继的设置,SWITCHdhcp enable,SWITCHdhcp relay server-group 1 ip 192.168.3.99,SWITCHinterface vlan-interface 2,SWITCH-vlan-interface2dhcp select relay,SWITCH-vlan-interface2dhcp server-select 1,SWITCH-vlan-interface2quit,SWITCHinterface vlan-interface 4,SWITCH-vlan-interface4dhcp select relay,SWITCH-vlan-interface4dhcp server-select 1,SWITCH-vlan-interface4quit,实验步骤,(4)设置连接DHCP服务器的接口的信息。,SWITCHinterface GigabitEthernet 1/0/3,SWITCH-GigabitEthernet 1/0/3port access vlan 3,SWITCH-GigabitEthernet 1/0/3quit,(5)设置路由。,SWITCHip route-static 0.0.0.0 0.0.0.0 192.168.1.99,3.配置DHCP服务器。,此处略。,也可以使用无线控制交换一体机和FIT AP构建WLAN,即图5.10中的无线控制器和三层交换机为一台复合设备,DHCP Server也搭建在这样的设备上。这种结构下需要做如下配置:,(1)设置无线控制器。,设置WC内部千兆以太网口1的参数。,system-view,H3Csysname WC /无线控制模块更名为WC,WCinterface GigabitEthernet 1/0/1,实验步骤,WC-GigabitEthernet 1/0/1port link-type trunk,WC-GigabitEthernet 1/0/1port trunk permit vlan all,WC-GigabitEthernet 1/0/1quit,设置虚接口地址,虚接口1用于管理,虚接口3用于DHCP Server。,WCvlan 2 to 4,WCinterface vlan-interface 1,WC-vlan-interface1ip address 192.168.1.99 255.255.255.0,WC-vlan-interface1quit,WCinterface vlan-interface 3,WC-vlan-interface3ip address 192.168.3.99 255.255.255.0,WC-vlan-interface3quit,开启DHCP服务,在WC上创建地址池1,用于AP获取地址,为跨越三层网络实现AP的注册,使用Option 43数值,Option的固定数值是80 07 00 00 01,192.168.1.99的十六进制表示形式为C0 A8 01 63;在WC上创建地址池2,用于无线客户端获取地址。,实验步骤,WCdhcp enable,WCdhcp server ip-pool 1,WC-dhcp-server-ip-pool1network 192.168.2.0 mask 255.255.255.0,WC-dhcp-server-ip-pool1gate way-list 192.168.2.254,WC-dhcp-server-ip-pool1option 43 hex 80 07 00 00 01 C0 A8 01 63,WC-dhcp-server-ip-pool1quit,WCdhcp server ip-pool 2,WC-dhcp-server-ip-pool2network 192.168.4.0 mask 255.255.255.0,WC-dhcp-server-ip-pool2gate way-list 192.168.4.254,WC-dhcp-server-ip-pool2quit,设置禁止分配的地址。,WCdhcp server forbidden-ip 192.168.2.254,WCdhcp server forbidden-ip 192.168.4.254,创建无线接口1,属于VLAN 4。,WCinterface WLAN-ESS 1,实验步骤,WC-WLAN-ESS1port access vlan 4,WC-WLAN-ESS1quit,创建服务模板3并开启,明文,与无线接口1绑定。,WCwlan service-template 3 clear,WC-wlan-st-3ssid jsjxy,WC-wlan-st-3bind WLAN-ESS 1,W
展开阅读全文