当前位置:网站首页>Configuring WAPI certificate security policy for Huawei wireless devices
Configuring WAPI certificate security policy for Huawei wireless devices
2022-07-24 15:36:00 【51CTO】

1. To configure LSW and AC, send AP And AC Can transmit between CAPWAP message
[LSW1]vlan batch 100
[LSW1-GigabitEthernet0/0/1]port link-type trunk
[LSW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
[LSW1-GigabitEthernet0/0/2]port link-type trunk
[LSW1-GigabitEthernet0/0/2]port trunk allow-pass vlan 100
[LSW1-GigabitEthernet0/0/2]port trunk pvid vlan 100
[LSW1-GigabitEthernet0/0/2]port-isolate enable
[AC1]vlan batch 100
[AC1-GigabitEthernet0/0/1]port link-type trunk
[AC1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
2. To configure AC Interworking with the upper network equipment
[AC1]vlan batch 101 102 103
[AC1-Vlanif101]ip add 10.1.101.1 24
[AC1-Vlanif102]ip add 10.1.102.1 24
[AC1-Vlanif103]ip add 10.1.103.1 24
[AC1-GigabitEthernet0/0/2]port link-type access
[AC1-GigabitEthernet0/0/2]port default vlan 102
[AC1-GigabitEthernet0/0/3]port link-type trunk
[AC1-GigabitEthernet0/0/3]port trunk allow-pass vlan 103
[AC1-GigabitEthernet0/0/3]port trunk pvid vlan 103
[AC1]ip route-static 0.0.0.0 0.0.0.0 10.1.102.2
3. To configure AC to AP Distribute IP Address ,AR to STA Distribute IP Address
[AC1]dhcp enable
[AC1-Vlanif100]ip add 10.1.100.1 24
[AC1-Vlanif100]dhcp select interface
[AC1-Vlanif101]dhcp select relay
[AC1-Vlanif101]dhcp relay server-ip 10.1.102.2
[AR1]dhcp enable
[AR1-ip-pool-sta]gateway-list 10.1.101.1
[AR1-ip-pool-sta]dns-list 8.8.8.8
[AR1-ip-pool-sta]network 10.1.101.0 mask 24
[AR1-GigabitEthernet0/0/0]ip add 10.1.102.2 24
[AR1-GigabitEthernet0/0/0]dhcp select global
[AR1]ip route-static 10.1.101.0 24 10.23.102.1
4. To configure AP go online
establish AP Group
[AC1]wlan
[AC1-wlan-view]ap-group name ap-group1
Create domain management template , Configure... Under the domain management template AC Country code and in AP Reference domain management template under group
[AC1-wlan-view]regulatory-domain-profile name domain1
[AC1-wlan-regulate-domain-domain1]country-code cn
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]regulatory-domain-profile domain1
[AC1]capwap source interface Vlanif 100
stay AC Import online and offline AP, And will AP Join in AP Group
[AC1-wlan-view]ap auth-mode mac-auth
[AC1-wlan-view]ap-id 0 ap-mac 00e0-fc19-7cf0
[AC1-wlan-ap-0]ap-name ap1
[AC1-wlan-ap-0]ap-group ap-group1

5. To configure WLAN Business parameters
Create a security template , And configure the security policy
[AC1]wlan
[AC1-wlan-view]security-profile name wlan-security
[AC1-wlan-sec-prof-wlan-security]security wapi certificate
[AC1-wlan-sec-prof-wlan-security]wapi asu ip 10.1.103.2
[AC1-wlan-sec-prof-wlan-security]wapi import certificate ac format pem file-name flash:/as.cer
[AC1-wlan-sec-prof-wlan-security]wapi import certificate asu format pem file-name flash:/as.cer
[AC1-wlan-sec-prof-wlan-security]wapi import certificate issuer format pem file-name flash:/as.cer
[AC1-wlan-sec-prof-wlan-security]wapi import private-key format pem file-name flash:/ae.cer
establish SSID Templates , And configuration SSID name
[AC1-wlan-view]ssid-profile name wlan-ssid
[AC1-wlan-ssid-prof-wlan-ssid]ssid wlan-net
establish VAP Templates , Configure business data forwarding mode 、 Business VLAN, And reference the security template 、 Certification templates and SSID Templates
[AC1-wlan-view]vap-profile name wlan-vap
[AC1-wlan-vap-prof-wlan-vap]forward-mode tunnel
[AC1-wlan-vap-prof-wlan-vap]service-vlan vlan-id 101
[AC1-wlan-vap-prof-wlan-vap]security-profile wlan-security
[AC1-wlan-vap-prof-wlan-vap]ssid-profile wlan-ssid
To configure AP Group reference VAP Templates ,AP RF on 0 And RF 1 All use VAP Template configuration
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]vap-profile wlan-vap wlan 1 radio 0
[AC1-wlan-ap-group-ap-group1]vap-profile wlan-vap wlan 1 radio 1
6. To configure AP RF channel and power
Turn off the RF channel and power auto tuning function
[AC1-wlan-view]rrm-profile name default
[AC1-wlan-rrm-prof-default]calibrate auto-channel-select disable
[AC1-wlan-rrm-prof-default]calibrate auto-txpower-select disable
To configure AP RF channel and power
[AC1-wlan-view]ap-id 0
[AC1-wlan-ap-0]radio 0
[AC1-wlan-radio-0/0]channel 20mhz 6
[AC1-wlan-radio-0/0]eirp 127
[AC1-wlan-ap-0]radio 1
[AC1-wlan-radio-0/1]channel 20mhz 149
[AC1-wlan-radio-0/1]eirp 127
边栏推荐
- Analysis of some difficulties in VAE (variational self encoder)
- 2022 RoboCom 世界机器人开发者大赛-本科组(省赛)-- 第二题 智能服药助手 (已完结)
- [machine learning basics] - another perspective to explain SVM
- Pattern water flow lamp 1: check the table and display the LED lamp
- 4279. Cartesian tree
- 华为无线设备配置WAPI-证书安全策略
- Here comes the problem! Unplug the network cable for a few seconds and plug it back in. Does the original TCP connection still exist?
- Huawei camera capability
- 遭受DDoS时,高防IP和高防CDN的选择
- C# - partial 关键字
猜你喜欢
![[adaptiveavgpool3d] pytorch tutorial](/img/d0/60ee74ff554effa06084d5d01a03e1.png)
[adaptiveavgpool3d] pytorch tutorial

Reentrantlock reentrant lock

Getting started with mongodb

Windows10安装免安装版redis

VAE(变分自编码器)的一些难点分析

C - partial keyword

Yolo5face: why reinvent the face detector

从哪些维度评判代码质量的好坏?如何具备写出高质量代码的能力?

2022 robocom world robot developer competition - undergraduate group (provincial competition) -- question 1: don't waste gold (finished)

Join parameter processing and @param
随机推荐
Cloud development standalone image Jiugongge traffic main source code
ZABBIX administrator forgot login password
(09) flask is OK if it has hands - cookies and sessions
Leetcode 1288. delete the covered interval (yes, solved)
Research on stability of time-delay systems based on Lambert function
15. Talk about these common multi-threaded interview questions
Join parameter processing and @param
Getting started with mongodb
How do novices buy stocks for the first time? Which securities company is the best and safest to open an account
Yolo5face: why reinvent the face detector
【tf.keras】:版本从1.x升级到2.x遇到的一个问题:InvalidArgumentError: Cannot assign a device for operation embedding_
华为无线设备配置WAPI-证书安全策略
Use of keywords const, volatile and pointer; Assembly language and view of register status
ReentrantLock 可重入锁
C# - partial 关键字
[adaptiveavgpool3d] pytorch tutorial
C - partial keyword
C# SQLite Database Locked exception
未来数据库需要关心的硬核创新
Windows10安装免安装版redis