当前位置:网站首页>华为无线设备配置WAPI-证书安全策略
华为无线设备配置WAPI-证书安全策略
2022-07-25 07:12:00 【Tony_long7483】

配置LSW和AC,使AP与AC之间能够传输CAPWAP报文
[LSW1]vlan batch 100
[LSW1-GigabitEthernet0/0/1]port link-type trunk
[LSW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
[LSW1-GigabitEthernet0/0/2]port link-type trunk
[LSW1-GigabitEthernet0/0/2]port trunk allow-pass vlan 100
[LSW1-GigabitEthernet0/0/2]port trunk pvid vlan 100
[LSW1-GigabitEthernet0/0/2]port-isolate enable
[AC1]vlan batch 100
[AC1-GigabitEthernet0/0/1]port link-type trunk
[AC1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100配置AC与上层网络设备互通
[AC1]vlan batch 101 102 103
[AC1-Vlanif101]ip add 10.1.101.1 24
[AC1-Vlanif102]ip add 10.1.102.1 24
[AC1-Vlanif103]ip add 10.1.103.1 24
[AC1-GigabitEthernet0/0/2]port link-type access
[AC1-GigabitEthernet0/0/2]port default vlan 102
[AC1-GigabitEthernet0/0/3]port link-type trunk
[AC1-GigabitEthernet0/0/3]port trunk allow-pass vlan 103
[AC1-GigabitEthernet0/0/3]port trunk pvid vlan 103
[AC1]ip route-static 0.0.0.0 0.0.0.0 10.1.102.2配置AC给AP分配IP地址,AR给STA分配IP地址
[AC1]dhcp enable
[AC1-Vlanif100]ip add 10.1.100.1 24
[AC1-Vlanif100]dhcp select interface
[AC1-Vlanif101]dhcp select relay
[AC1-Vlanif101]dhcp relay server-ip 10.1.102.2
[AR1]dhcp enable
[AR1-ip-pool-sta]gateway-list 10.1.101.1
[AR1-ip-pool-sta]dns-list 8.8.8.8
[AR1-ip-pool-sta]network 10.1.101.0 mask 24
[AR1-GigabitEthernet0/0/0]ip add 10.1.102.2 24
[AR1-GigabitEthernet0/0/0]dhcp select global
[AR1]ip route-static 10.1.101.0 24 10.23.102.1配置AP上线
创建AP组
[AC1]wlan
[AC1-wlan-view]ap-group name ap-group1
创建域管理模板,在域管理模板下配置AC的国家码并在AP组下引用域管理模板
[AC1-wlan-view]regulatory-domain-profile name domain1
[AC1-wlan-regulate-domain-domain1]country-code cn
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]regulatory-domain-profile domain1
[AC1]capwap source interface Vlanif 100
在AC上离线导入AP,并将AP加入AP组
[AC1-wlan-view]ap auth-mode mac-auth
[AC1-wlan-view]ap-id 0 ap-mac 00e0-fc19-7cf0
[AC1-wlan-ap-0]ap-name ap1
[AC1-wlan-ap-0]ap-group ap-group1
配置WLAN业务参数
创建安全模板,并配置安全策略
[AC1]wlan
[AC1-wlan-view]security-profile name wlan-security
[AC1-wlan-sec-prof-wlan-security]security wapi certificate
[AC1-wlan-sec-prof-wlan-security]wapi asu ip 10.1.103.2
[AC1-wlan-sec-prof-wlan-security]wapi import certificate ac format pem file-name flash:/as.cer
[AC1-wlan-sec-prof-wlan-security]wapi import certificate asu format pem file-name flash:/as.cer
[AC1-wlan-sec-prof-wlan-security]wapi import certificate issuer format pem file-name flash:/as.cer
[AC1-wlan-sec-prof-wlan-security]wapi import private-key format pem file-name flash:/ae.cer
创建SSID模板,并配置SSID名称
[AC1-wlan-view]ssid-profile name wlan-ssid
[AC1-wlan-ssid-prof-wlan-ssid]ssid wlan-net
创建VAP模板,配置业务数据转发模式、业务VLAN,并且引用安全模板、认证模板和SSID模板
[AC1-wlan-view]vap-profile name wlan-vap
[AC1-wlan-vap-prof-wlan-vap]forward-mode tunnel
[AC1-wlan-vap-prof-wlan-vap]service-vlan vlan-id 101
[AC1-wlan-vap-prof-wlan-vap]security-profile wlan-security
[AC1-wlan-vap-prof-wlan-vap]ssid-profile wlan-ssid
配置AP组引用VAP模板,AP上射频0和射频1都使用VAP模板的配置
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]vap-profile wlan-vap wlan 1 radio 0
[AC1-wlan-ap-group-ap-group1]vap-profile wlan-vap wlan 1 radio 1配置AP射频的信道和功率
关闭射频的信道和功率自动调优功能
[AC1-wlan-view]rrm-profile name default
[AC1-wlan-rrm-prof-default]calibrate auto-channel-select disable
[AC1-wlan-rrm-prof-default]calibrate auto-txpower-select disable
配置AP射频的信道和功率
[AC1-wlan-view]ap-id 0
[AC1-wlan-ap-0]radio 0
[AC1-wlan-radio-0/0]channel 20mhz 6
[AC1-wlan-radio-0/0]eirp 127
[AC1-wlan-ap-0]radio 1
[AC1-wlan-radio-0/1]channel 20mhz 149
[AC1-wlan-radio-0/1]eirp 127
边栏推荐
- 分布式爬虫中的增量爬虫
- Qt实战案例(53)——利用QDrag实现拖拽拼图功能
- [Yugong series] July 2022 go teaching course 015 assignment operators and relational operators of operators
- 如何在KVM环境中使用网络安装部署多台虚拟服务器
- Ask the bosses: MySQL CDC stores configuration data, and Kafka has history
- "Game illustrated book": a memoir dedicated to game players
- EFCore高级Saas系统下单DbContext如何支持不同数据库的迁移
- Kyligence Li Dong: from the data lake to the index middle stage, improve the ROI of data analysis
- List derivation
- 代码中的软件工程:正则表达式十步通关
猜你喜欢

New tea, start "fighting in groups"

CTF Crypto---RSA KCS1_ Oaep mode

Talk about practice, do solid work, and become practical: tour the digitalized land of China

《游戏机图鉴》:一份献给游戏玩家的回忆录

"Game illustrated book": a memoir dedicated to game players

代码中的软件工程:正则表达式十步通关

Microorganisms are healthy. Don't exclude microorganisms in the human body

Not only log collection, but also the installation, configuration and use of project monitoring tool sentry

File operation-
![[Yugong series] July 2022 go teaching course 016 logical operators and other operators of operators](/img/36/9ad3f76078153f6af6c5b59d99564a.png)
[Yugong series] July 2022 go teaching course 016 logical operators and other operators of operators
随机推荐
leetcode刷题:动态规划06(整数拆分)
批量导入数据,一直提示 “失败原因:SQL解析失败:解析文件失败::null”怎么回事?
微信小程序wx.request接口
9大最佳工程施工项目管理系统
Baidu Post Bar crawler gets web pages
Leetcode skimming: dynamic programming 06 (integer splitting)
Purpose of SQL square brackets
Upload and download multiple files using web APIs
从ACL 2022 Onsite经历看NLP热点
【terminal】x86 Native Tools Command Prompt for VS 2017
Oracle table creation statement template
How to learn C language?
如何在KVM环境中使用网络安装部署多台虚拟服务器
Dynamic memory management
"Game illustrated book": a memoir dedicated to game players
睡眠不足有哪些危害?
YOLOv7模型推理和训练自己的数据集
探讨影响自动化测试成败的重要因素
[semidrive source code analysis] [drive bringup] 39 - touch panel touch screen debugging
Two week learning results of machine learning