当前位置:网站首页>华为无线设备配置WAPI-证书安全策略
华为无线设备配置WAPI-证书安全策略
2022-07-24 15:33:00 【51CTO】

1. 配置LSW和AC,使AP与AC之间能够传输CAPWAP报文
[LSW1]vlan batch 100
[LSW1-GigabitEthernet0/0/1]port link-type trunk
[LSW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
[LSW1-GigabitEthernet0/0/2]port link-type trunk
[LSW1-GigabitEthernet0/0/2]port trunk allow-pass vlan 100
[LSW1-GigabitEthernet0/0/2]port trunk pvid vlan 100
[LSW1-GigabitEthernet0/0/2]port-isolate enable
[AC1]vlan batch 100
[AC1-GigabitEthernet0/0/1]port link-type trunk
[AC1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
2. 配置AC与上层网络设备互通
[AC1]vlan batch 101 102 103
[AC1-Vlanif101]ip add 10.1.101.1 24
[AC1-Vlanif102]ip add 10.1.102.1 24
[AC1-Vlanif103]ip add 10.1.103.1 24
[AC1-GigabitEthernet0/0/2]port link-type access
[AC1-GigabitEthernet0/0/2]port default vlan 102
[AC1-GigabitEthernet0/0/3]port link-type trunk
[AC1-GigabitEthernet0/0/3]port trunk allow-pass vlan 103
[AC1-GigabitEthernet0/0/3]port trunk pvid vlan 103
[AC1]ip route-static 0.0.0.0 0.0.0.0 10.1.102.2
3. 配置AC给AP分配IP地址,AR给STA分配IP地址
[AC1]dhcp enable
[AC1-Vlanif100]ip add 10.1.100.1 24
[AC1-Vlanif100]dhcp select interface
[AC1-Vlanif101]dhcp select relay
[AC1-Vlanif101]dhcp relay server-ip 10.1.102.2
[AR1]dhcp enable
[AR1-ip-pool-sta]gateway-list 10.1.101.1
[AR1-ip-pool-sta]dns-list 8.8.8.8
[AR1-ip-pool-sta]network 10.1.101.0 mask 24
[AR1-GigabitEthernet0/0/0]ip add 10.1.102.2 24
[AR1-GigabitEthernet0/0/0]dhcp select global
[AR1]ip route-static 10.1.101.0 24 10.23.102.1
4. 配置AP上线
创建AP组
[AC1]wlan
[AC1-wlan-view]ap-group name ap-group1
创建域管理模板,在域管理模板下配置AC的国家码并在AP组下引用域管理模板
[AC1-wlan-view]regulatory-domain-profile name domain1
[AC1-wlan-regulate-domain-domain1]country-code cn
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]regulatory-domain-profile domain1
[AC1]capwap source interface Vlanif 100
在AC上离线导入AP,并将AP加入AP组
[AC1-wlan-view]ap auth-mode mac-auth
[AC1-wlan-view]ap-id 0 ap-mac 00e0-fc19-7cf0
[AC1-wlan-ap-0]ap-name ap1
[AC1-wlan-ap-0]ap-group ap-group1

5. 配置WLAN业务参数
创建安全模板,并配置安全策略
[AC1]wlan
[AC1-wlan-view]security-profile name wlan-security
[AC1-wlan-sec-prof-wlan-security]security wapi certificate
[AC1-wlan-sec-prof-wlan-security]wapi asu ip 10.1.103.2
[AC1-wlan-sec-prof-wlan-security]wapi import certificate ac format pem file-name flash:/as.cer
[AC1-wlan-sec-prof-wlan-security]wapi import certificate asu format pem file-name flash:/as.cer
[AC1-wlan-sec-prof-wlan-security]wapi import certificate issuer format pem file-name flash:/as.cer
[AC1-wlan-sec-prof-wlan-security]wapi import private-key format pem file-name flash:/ae.cer
创建SSID模板,并配置SSID名称
[AC1-wlan-view]ssid-profile name wlan-ssid
[AC1-wlan-ssid-prof-wlan-ssid]ssid wlan-net
创建VAP模板,配置业务数据转发模式、业务VLAN,并且引用安全模板、认证模板和SSID模板
[AC1-wlan-view]vap-profile name wlan-vap
[AC1-wlan-vap-prof-wlan-vap]forward-mode tunnel
[AC1-wlan-vap-prof-wlan-vap]service-vlan vlan-id 101
[AC1-wlan-vap-prof-wlan-vap]security-profile wlan-security
[AC1-wlan-vap-prof-wlan-vap]ssid-profile wlan-ssid
配置AP组引用VAP模板,AP上射频0和射频1都使用VAP模板的配置
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]vap-profile wlan-vap wlan 1 radio 0
[AC1-wlan-ap-group-ap-group1]vap-profile wlan-vap wlan 1 radio 1
6. 配置AP射频的信道和功率
关闭射频的信道和功率自动调优功能
[AC1-wlan-view]rrm-profile name default
[AC1-wlan-rrm-prof-default]calibrate auto-channel-select disable
[AC1-wlan-rrm-prof-default]calibrate auto-txpower-select disable
配置AP射频的信道和功率
[AC1-wlan-view]ap-id 0
[AC1-wlan-ap-0]radio 0
[AC1-wlan-radio-0/0]channel 20mhz 6
[AC1-wlan-radio-0/0]eirp 127
[AC1-wlan-ap-0]radio 1
[AC1-wlan-radio-0/1]channel 20mhz 149
[AC1-wlan-radio-0/1]eirp 127
边栏推荐
- 2022 RoboCom 世界机器人开发者大赛-本科组(省赛) CAIP 完整版题解
- C # exit login if there is no operation
- Read the paper with me - multi model text recognition network
- Huawei camera capability
- 【量化测试】
- DS graph - minimum spanning tree
- Analysys analysis "2022 China data security market data monitoring report" was officially launched
- Introduction to single chip microcomputer: LED lights cycle to the left and turn on
- 什么是防火墙?防火墙能发挥什么样的作用?
- YOLO5Face:为什么要重新发明人脸检测器
猜你喜欢

Existence form and legitimacy of real data in C language (floating point number)

文件操作详解

Cloud development standalone image Jiugongge traffic main source code

(09) flask is OK if it has hands - cookies and sessions

Android section 13 detailed explanation of 03sqlite database

2022 robocom world robot developer competition - undergraduate group (provincial competition) -- fifth question tree and bipartite diagram (completed)

被攻击怎么解决?DDoS高防IP防护策略

Multus of kubernetes multi network card scheme_ CNI deployment and basic use

Do you understand the working principle of gyroscope?

MySQL学习笔记(总结)
随机推荐
Outlook tutorial, how to set rules in outlook?
JUC源码学习笔记3——AQS等待队列和CyclicBarrier,BlockingQueue
Read the paper with me - multi model text recognition network
【机器学习基础】——另一个视角解释SVM
Five principles of solid are indispensable for good architecture design
25.从生磁盘到文件
Use of keywords const, volatile and pointer; Assembly language and view of register status
DS diagram - the shortest path of the diagram (excluding the code framework)
matlab图像去雾技术GUI界面-全局平衡直方图
MySQL build master-slave synchronization - build with docker
2022 RoboCom 世界机器人开发者大赛-本科组(省赛)-- 第二题 智能服药助手 (已完结)
云开发单机版图片九宫格流量主源码
PyTorch的自动求导
C. Recover an RBS
Database learning – select (multi table joint query) [easy to understand]
哈夫曼树(最优二叉树)
【AdaptiveAvgPool3d】pytorch教程
[USENIX atc'22] an efficient distributed training framework whale that supports the super large-scale model of heterogeneous GPU clusters
SQL row to column, column to row
[quantitative test]