项目简单概述
本文只是一篇小项目的复盘!
15台48口交换机,型号为LS-5130S-52P-PWR-EI;
4台24口交换机,型号为LS-5130S-28P-HPWR-EI;
一台AC控制器的型号为EWP-WX3510H;
需求:19层楼的所有PC终端和移动用户都能获取到IP地址并能正常上网。
一共19层楼,每层楼一台POE交换机,每一层有15-25台AP;
拓扑
基本配置
只写有代表性的设备(注意:命令不全)
AC
AC
sysname XX-AC
#
telnet server enable
#
port-security enable
#
dhcp enable
#
password-recovery enable
#
vlan 1
#
vlan 100 #管理VLAN
description This is Manager VLAN .
#
vlan 200 to 1600
#
vlan 1000 #VLAN1000为无线
description This is WLAN AP VLAN .
#
vlan 1612 to 4094
#
dhcp server ip-pool ap #DHCP服务器
gateway-list 10.10.181.254 #网关
network 10.10.180.0 mask 255.255.254.0 #所分配的网段
#
wlan service-template 1 #配置无线服务模板1
ssid AA #创建无线名称
vlan 1501 #绑定VLAN,绑定哪个 VLAN,PC连接的 WIFI 就获取哪个 VLAN 业务地址
service-template enable #开启无线模板功能
#
wlan service-template 2
ssid BB
vlan 1505
service-template enable
#
interface NULL0
#
interface Vlan-interface100
ip address 192.31.100.10 255.255.255.0
#
interface Vlan-interface1000
ip address 10.10.181.254 255.255.254.0
#
interface GigabitEthernet1/0/1
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/2
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/3
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/4
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/5
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/6
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/7
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/8
port link-type trunk
port trunk permit vlan all
#
user-interface vty 0 4
authentication-mode scheme
user-role network-operator
set authentication password simple 1008611
#
ip route-static 0.0.0.0 0 192.31.100.1
#
authorization-attribute user-role level-15
#
wlan auto-ap enable #使能自动 AP
wlan auto-persistent enable #使能自动固化
#
wlan ap-group default-group #默认AP组里面配置对应的 AP 型号
vlan 1
vlan 1501
ap-model WA6320 #AP 型号为WA6320
radio 1
max-power 20
radio enable
channel band-width 20
service-template 1 #5G 射频绑定无线服务模板 1
radio 2
radio enable
service-template 1 #2.4G 射频绑定无线服务模板 1
gigabitethernet 1
ap-model WA6320H
radio 1
max-power 20 #配置射频的最大传输功率为20
radio enable
channel band-width 20 #配置当前Radio接口的带宽模式;射频接口的工作方式为20MHz
service-template 1
radio 2
max-power 20
radio enable
service-template 1
gigabitethernet 1
gigabitethernet 2
gigabitethernet 3
gigabitethernet 4
gigabitethernet 5
ap-model WA6330
radio 1
max-power 20
radio enable
channel band-width 20
service-template 1
radio 2
max-power 20
radio enable
channel band-width 20
service-template 1
radio 3
radio enable
service-template 1
gigabitethernet 1
smartrate-ethernet 1
#
wlan ap-group yrz
vlan 1
vlan 1501
ap XX
ap ...
......
ap-model WA6320
radio 1
max-power 20
radio enable
channel band-width 20
service-template 1
radio 2
max-power 20
radio enable
service-template 1
gigabitethernet 1
ap-model WA6320H
radio 1
max-power 20
radio enable
service-template 1
radio 2
max-power 20
radio enable
service-template 1
gigabitethernet 1
gigabitethernet 2
gigabitethernet 3
gigabitethernet 4
gigabitethernet 5
ap-model WA6330
radio 1
max-power 20
radio enable
channel band-width 20
service-template 1
radio 2
max-power 20
radio enable
channel band-width 20
service-template 1
radio 3
radio enable
service-template 1
gigabitethernet 1
smartrate-ethernet 1
wlan ap-group yrz-16
vlan 1
vlan 1505
ap XX
ap ...
......
ap-model WA6320
radio 1
max-power 20
radio enable
channel band-width 20
service-template 2
radio 2
max-power 20
radio enable
service-template 2
gigabitethernet 1
ap-model WA6320H
radio 1
max-power 20
radio enable
channel band-width 20
service-template 2
radio 2
max-power 20
radio enable
service-template 2
gigabitethernet 1
gigabitethernet 2
gigabitethernet 3
gigabitethernet 4
gigabitethernet 5
ap-model WA6330
radio 1
max-power 20
radio enable
channel band-width 20
service-template 2
radio 2
max-power 20
radio enable
channel band-width 20
service-template 2
radio 3
max-power 20
radio enable
service-template 2
gigabitethernet 1
smartrate-ethernet 1
#
wlan ap XX model WA6320 #上线 AP 时,获取到IP地址后会自动上线
serial-id XXXXXXXXXXXX
vlan 1
radio 1
radio 2
gigabitethernet 1
#
.......
核心交换机
HX
sysname XX-HX
#
domain default enable system
#
telnet server enable
#
vlan 1
.......
#
vlan 100 to 990
#
vlan 1000
description This is WLAN AP VLAN .
#
vlan 1011 to 1999
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
user-group system
#
stp enable
stp region-configuration
region-name XX
revision-level 1
instance 1 vlan 2 to 1999
active region-configuration
#
interface NULL0
#
interface Vlan-interface100
description This is Manager Vlan .
ip address 192.31.100.1 255.255.255.0
#
interface Vlan-interface1000
description This is WWLAN AP VLAN .
ip address 10.10.181.1 255.255.255.0
#
interface GigabitEthernet2/0/1
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/2
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/3
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/4
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/5
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/6
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/7
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/8
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/9
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/10
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/11
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/12
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/13
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/14
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/15
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/16
port link-mode bridge
port link-type trunk
port trunk permit vlan all
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/17
port link-mode bridge
port link-type trunk
port trunk permit vlan all
shutdown
mirroring-group 1 mirroring-port both
#
interface GigabitEthernet2/0/18
port link-mode bridge
port link-type trunk
port trunk permit vlan all
shutdown
mirroring-group 1 mirroring-port both
#
.......
#
interface M-Ethernet0/0/0
#
ip route-static 1XX.1XX.2XX.0 255.255.255.0 192.31.100.10
#
snmp-agent
snmp-agent local-engineid XXXXXXXX
snmp-agent community read public
snmp-agent community write private
snmp-agent sys-info version all
#
load xml-configuration
#
user-interface aux 0
user-interface vty 0 4
user privilege level 3
set authentication password simple 1008611
user-interface vty 5 15
......
接入交换机
S
sysname XXPOE
#
telnet server enable
#
dhcp snooping enable
#
password-recovery enable
#
vlan 1
#
vlan 100
description This is manager VLAN.
#
#
vlan 220 to 320
#
vlan 1000
description This is WLAN AP VLAN
#
stp region-configuration
region-name XX
revision-level 1
instance 1 vlan 200 to 600
active region-configuration
#
stp global enable
#
interface NULL0
#
interface Vlan-interface100
ip address 192.31.100.17 255.255.255.0
#
interface GigabitEthernet1/0/1
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/2
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/3
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/4
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/5
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/6
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/7
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/8
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/9
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/10
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/11
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/12
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/13
port access vlan 1000
stp edged-port
poe enable
loopback-detection enable vlan 1000
#
.......
#
interface GigabitEthernet1/0/48
port access vlan 1000
poe enable
loopback-detection enable vlan 1000
#
interface GigabitEthernet1/0/49
#
interface GigabitEthernet1/0/50
#
interface GigabitEthernet1/0/51
#
interface GigabitEthernet1/0/52
port link-type trunk
port trunk permit vlan all
dhcp snooping trust
#
scheduler logfile size 16
#
line class aux
user-role network-admin
#
line class vty
user-role network-operator
#
line aux 0
user-role network-admin
#
line vty 0 4
user-role level-15
user-role network-operator
set authentication password simple 1008611
#
line vty 5 63
user-role network-operator
#
ip route-static 0.0.0.0 0 192.31.100.1
#
snmp-agent
snmp-agent local-engineid XXXXXXXXXXXXX
snmp-agent community write private
snmp-agent community read public
snmp-agent sys-info version all
#
radius scheme system
user-name-format without-domain
#
domain system
#
domain default enable system
#
......
#
user-group system
#
local-user admin class manage
service-type telnet
authorization-attribute user-role network-operator
#
.......
其他接入层交换机配置类似
简单测试
display wlan ap all
display wlan ap-group brief
AP没上线,如何解决
AP没上线,一般是什么问题或者用什么办法解决?
1、AP是否上电
2、AP与接入交换机接线是否正常
3、交换机配置是否有误,比如端口类型ACCESS TRUNK是否配置正确,是否放行了相关的VLAN
4、交换机是否在接口上开启POE功能(交换机为POE交换机)
5、以上都没问题的话,可重启交换机,或者是在接口上把POE功能先关掉再开启POE功能
6、IP地址是否够用,可扩展DHCP地址池,或者增加DHCP服务器
如果/24掩码的DHCP地址池不够用的话,可改用为/23的;例如:10.10.181.0/24的,改为10.10.180.0/23,网关为10.10.181.254,这样只有253IP地址可用,就能再增加256个IP可用地址了。
7、检查接口是否是DOWN/UP(使用命令为:display interface brief)
VLAN为啥DOWN了?怎么办
为啥在VLAN视图下配置了IP地址为DOWN?
[SW1]vlan 200
[SW1-vlan200]q
[SW1]int Vlanif 200
[SW1-Vlanif200]ip address 10.10.1.254 24
[SW1-Vlanif200]q
display ip int brief
因为在VLAN 200下没有数据转发,即VLAN 200下没有正常连接的终端或者是没有使用到VLAN 200的数据。把某个口划入到VLAN 200,链接到PC终端,VLAN 200状态就起来了。
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/1]port default vlan 200
PC1的配置
再查看VLAN 200接口,是否为UP?
由以上输出结果可知,状态已为UP。
常识扩展
常用网络设备的接口E、S、F、G、XG代表了什么?
Ethernet接口,叫以太网接口,普通的双绞线,E代表的是百兆口;
Serial接口,也叫高速异步串口,可以设置R-R带宽;
FastEthernet接口,快速以太网口,也叫百兆口;
GigabitEthernet可以是光口,也可以是电口,也叫千兆口。
XG指的是Ten-GigabitEthernet ,也就是万兆以太网口;
设备里面的ethernet是100M接口
gigabitethernet是1000M接口
ethernet不能配置IP,因为这个接口为二层口,所以不能设置IP。
(思科:在该接口试图上运行no switchport然后关闭二层接口并启用三层接口;然后可配置IP地址。)
好了这期就到这里了,如果你喜欢这篇文章的话,请点赞评论分享收藏,如果你还能点击关注,那真的是对我最大的鼓励。谢谢大家,下期见!