- A+
网络拓扑结构如下图:2台S5700三层网络交换机,1台AC6005无线网络控制器进行组网。较早前做的一个实验,现将配置信息导出。

1.S5700-A交换机配置
- [S5700-A]DIS CUR
- #
- sysname S5700-A
- #
- info-center source DS channel 0 log state off trap state off
- #
- vlan batch 100 to 102
- #
- cluster enable
- ntdp enable
- ndp enable
- #
- drop illegal-mac alarm
- #
- diffserv domain default
- #
- drop-profile default
- #
- aaa
- authentication-scheme default
- authorization-scheme default
- accounting-scheme default
- domain default
- domain default_admin
- local-user admin password simple admin
- local-user admin service-type http
- #
- interface Vlanif1
- #
- interface MEth0/0/1
- #
- interface GigabitEthernet0/0/1
- port link-type trunk
- port trunk pvid vlan 100
- port trunk allow-pass vlan 100 to 101
- port-isolate enable group 1
- #
- interface GigabitEthernet0/0/2
- port link-type trunk
- port trunk pvid vlan 100
- port trunk allow-pass vlan 100 102
- port-isolate enable group 1
- #
- interface GigabitEthernet0/0/3
- port link-type trunk
- port trunk allow-pass vlan 100 to 102
- #
- interface GigabitEthernet0/0/4
- port link-type trunk
- port trunk pvid vlan 100
- port trunk allow-pass vlan 100 to 101
- port-isolate enable group 1
- #
- interface GigabitEthernet0/0/5
- #
- interface GigabitEthernet0/0/6
- #
- interface GigabitEthernet0/0/7
- #
- interface GigabitEthernet0/0/8
- #
- interface GigabitEthernet0/0/9
- #
- interface GigabitEthernet0/0/10
- #
- interface GigabitEthernet0/0/11
- #
- interface GigabitEthernet0/0/12
- #
- interface GigabitEthernet0/0/13
- #
- interface GigabitEthernet0/0/14
- #
- interface GigabitEthernet0/0/15
- #
- interface GigabitEthernet0/0/16
- #
- interface GigabitEthernet0/0/17
- #
- interface GigabitEthernet0/0/18
- #
- interface GigabitEthernet0/0/19
- #
- interface GigabitEthernet0/0/20
- #
- interface GigabitEthernet0/0/21
- #
- interface GigabitEthernet0/0/22
- #
- interface GigabitEthernet0/0/23
- #
- interface GigabitEthernet0/0/24
- #
- interface NULL0
- #
- user-interface con 0
- user-interface vty 0 4
- #
- return
- [S5700-A]
2.S5700-B交换机配置
- [S5700-B]dis cur
- #
- sysname S5700-B
- #
- info-center source DS channel 0 log state off trap state off
- #
- vlan batch 100 to 102 200
- #
- cluster enable
- ntdp enable
- ndp enable
- #
- drop illegal-mac alarm
- #
- dhcp enable
- #
- diffserv domain default
- #
- drop-profile default
- #
- aaa
- authentication-scheme default
- authorization-scheme default
- accounting-scheme default
- domain default
- domain default_admin
- local-user admin password simple admin
- local-user admin service-type http
- #
- interface Vlanif1
- #
- interface Vlanif100
- ip address 192.168.10.1 255.255.255.0
- dhcp select relay
- dhcp relay server-ip 172.16.100.1
- #
- interface Vlanif101
- ip address 192.168.11.1 255.255.255.0
- dhcp select relay
- dhcp relay server-ip 172.16.100.1
- #
- interface Vlanif102
- ip address 192.168.12.1 255.255.255.0
- dhcp select relay
- dhcp relay server-ip 172.16.100.1
- #
- interface Vlanif200
- ip address 172.16.100.10 255.255.255.0
- #
- interface MEth0/0/1
- #
- interface GigabitEthernet0/0/1
- port link-type trunk
- port trunk allow-pass vlan 100 to 102
- #
- interface GigabitEthernet0/0/2
- port link-type trunk
- port trunk allow-pass vlan 200
- #
- interface GigabitEthernet0/0/3
- #
- interface GigabitEthernet0/0/4
- #
- interface GigabitEthernet0/0/5
- #
- interface GigabitEthernet0/0/6
- #
- interface GigabitEthernet0/0/7
- #
- interface GigabitEthernet0/0/8
- #
- interface GigabitEthernet0/0/9
- #
- interface GigabitEthernet0/0/10
- #
- interface GigabitEthernet0/0/11
- #
- interface GigabitEthernet0/0/12
- #
- interface GigabitEthernet0/0/13
- #
- interface GigabitEthernet0/0/14
- #
- interface GigabitEthernet0/0/15
- #
- interface GigabitEthernet0/0/16
- #
- interface GigabitEthernet0/0/17
- #
- interface GigabitEthernet0/0/18
- #
- interface GigabitEthernet0/0/19
- #
- interface GigabitEthernet0/0/20
- #
- interface GigabitEthernet0/0/21
- #
- interface GigabitEthernet0/0/22
- #
- interface GigabitEthernet0/0/23
- #
- interface GigabitEthernet0/0/24
- #
- interface NULL0
- #
- ip route-static 0.0.0.0 0.0.0.0 172.16.100.1
- #
- user-interface con 0
- user-interface vty 0 4
- #
- return
- [S5700-B]
- [S5700-B]
3.AC6005无线网络控制器配置
- <AC6005>dis cur
- #
- undo snmp-agent
- #
- http timeout 3
- #
- vlan batch 1030 1040 1050 4001 to 4002
- #
- dot1x enable
- #
- wlan ac-global carrier id other ac id 1
- #
- dhcp enable
- #
- diffserv domain default
- #
- vlan 1050
- description B3F1
- #
- pki realm default
- enrollment self-signed
- #
- aaa
- authentication-scheme default
- authorization-scheme default
- accounting-scheme default
- domain default
- domain default_admin
- local-user admin password cipher %@%@*bo]Dnyrm1\x`qC3g=d;3Uw}%@%@
- local-user admin service-type http
- #
- interface Vlanif4001
- description ac_guanli
- ip address 10.128.254.200 255.255.255.0
- #
- interface Vlanif4002
- description ap_guanli
- ip address 10.128.253.1 255.255.255.0
- dhcp select interface
- #
- interface GigabitEthernet0/0/1
- port link-type trunk
- port trunk allow-pass vlan 4001 to 4002
- #
- interface GigabitEthernet0/0/2
- #
- interface GigabitEthernet0/0/3
- #
- interface GigabitEthernet0/0/4
- #
- interface GigabitEthernet0/0/5
- #
- interface GigabitEthernet0/0/6
- #
- interface GigabitEthernet0/0/7
- #
- interface GigabitEthernet0/0/8
- #
- interface Wlan-Ess0
- #
- interface Wlan-Ess1
- port hybrid pvid vlan 1050
- #
- interface NULL0
- #
- ip route-static 0.0.0.0 0.0.0.0 10.128.254.1
- #
- user-interface con 0
- authentication-mode password
- user-interface vty 0 4
- user-interface vty 16 20
- #
- wlan
- wlan ac source interface vlanif4002
- ap-region id 11
- ap id 11 type-id 19 mac 00e0-fcdb-78a0 sn 210235448310966D0D1A
- region-id 11
- ap id 12 type-id 19 mac 00e0-fc4e-6a50 sn 210235448310D117F14C
- region-id 11
- ap id 13 type-id 19 mac 00e0-fc34-4360 sn 2102354483105133DC40
- region-id 11
- ap id 14 type-id 19 mac 00e0-fc9f-1510 sn 210235448310AD4F5774
- region-id 11
- wmm-profile name wmm id 1
- traffic-profile name traffic id 1
- security-profile name security id 1
- security-policy wpa2
- wpa2 authentication-method psk pass-phrase cipher %@%@Ve-_Hs}~.-Vr-YA;TPlTyj7U
- %@%@ encryption-method ccmp
- service-set name MYWIFI1F_1 id 0
- wlan-ess 1
- ssid MYWIFI1F_1
- traffic-profile id 1
- security-profile id 1
- service-vlan 1050
- service-set name kzbdtest id 1
- wlan-ess 1
- ssid MYWIFI1F
- traffic-profile id 1
- security-profile id 1
- service-vlan 1050
- radio-profile name radio id 1
- wmm-profile id 1
- ap 11 radio 0
- radio-profile id 1
- service-set id 0 wlan 1
- service-set id 1 wlan 2
- ap 12 radio 0
- radio-profile id 1
- service-set id 0 wlan 1
- ap 13 radio 0
- radio-profile id 1
- service-set id 0 wlan 1
- ap 14 radio 0
- radio-profile id 1
- service-set id 0 wlan 1
- #
- return
- <AC6005>