CAPWAP
协议简介CAPWAP
协议,即无线接入点的控制和配置协议Control And Provisioning of Wireless Access Point Protocol的缩写,它是一种通用的隧道协议,CAPWAP
协议基于UDP
端口进行传输,用于无线终端接入点(AP)
和无线网络控制器(AC)
之间的通信交互,实现AC
对其所关联的AP
集中管理和控制。该协议的主要功能包括:
AP对AC的自动发现及AP和AC的状态机运行、维护
AC对AP进行管理,业务配置下发
STA数据封装CAPWAP
隧道进行转发
此外,CAPWAP
协议支持两种操作模式:Split MAC
和Local MAC
。在Split MAC
模式下,所有二层的无线数据和管理帧都被CAPWAP
协议封装,在AC
和AP
之间交互。从STA
收到的无线帧,直接封装,转发给AC
。
总的来说,CAPWAP
协议是整个WLAN
的南向接口协议,相当于OpenFlow
协议的角色,用于无线接入点的控制和配置。
为方便阅读,本次无线配置部分,将网络图进行简化,浅色部分暂不配置,配置无线网络控制器、配置核心交换机、配置行政办公大楼汇聚交换机,使AP上线并实现和无线终端连接:
最终实现的功能效果如下,6台
终端接入无线AP
,实现无线连接:
FIT AP wlan
数据规划表WLAN主要数据规划如下表所示:
配置项 | 数据 | 备注 |
---|---|---|
AC管理地址 | VLAN4001,10.10.254.10/24 |
|
AC源接口地址 | VLAN4002,10.10.252.1 |
|
AP的IP地址池 | 10.10.252.2-10.10.252.254/24 |
AC分配 |
STA的IP地址池 | VLAN1010:10.10.10.2-10.10.10.199/24 |
汇聚交换机分配 |
AP组 | 名称:myap-group001 |
|
域管理模板 | mydomain001 |
|
国家代码 | CN |
|
SSID模板名称 | myssid |
|
SSID名称 | myhuaweiwifi |
|
SSID密码 | myhuawei123 |
|
安全模板 | 名称:mysec 加密方式: wpa2 psk |
|
VAP 模板 |
名称:myvap 转发模式:隧道转发 业务 VLAN:1010 |
本仿真实验中,有3台AP,它们的基础信息如下:
设备序号 | 设备SN号 | 设备MAC地址 | 设备型号 | 软件版本 |
---|---|---|---|---|
AP1 |
210235448310EE3ACA47 |
00E0-FC76-32F0 |
AP7050DE |
V200R007C10SPC300 |
AP2 |
2102354483105B748366 |
00E0-FCBF-0EB0 |
AP7050DE |
V200R007C10SPC300 |
AP3 |
210235448310CE562504 |
00E0-FC2F-40E0 |
AP7050DE |
V200R007C10SPC300 |
实际设备的AP
和SN
可以从设备背面信息直接查到,本仿真实验中可以从设置界面中查到:
这里是行政办公大楼汇聚交换机S5700-HJ-001
,AP1、AP2、AP3
分别和其3、4、5
口相连,这3个物理口配置中继,并在交换机上创建VLAN1010
和VLAN4001-VLAN4002
<XZBUILDING>sys
Enter system view, return user view with Ctrl+Z.
[XZBUILDING]sysname S5700-HJ-001 #为便于记忆和识别,这里进行改名
[S5700-HJ-001]
1)创建VLAN
VLAN4001
上次实验已创建过,这里只创建VLAN1010
和VLAN4002
:
[S5700-HJ-001]vlan batch 1010 4002
Info: This operation may take a few seconds. Please wait for a moment...done.
[S5700-HJ-001]
2)配置DHCP
服务
这里在VLANIF 1010
接口上配置DHCP
服务,提供终端接入时获取自动获取IP
地址:
[S5700-HJ-001-GigabitEthernet0/0/3]int vlanif 1010
[S5700-HJ-001-Vlanif1010]ip address 10.10.10.1 255.255.255.0
[S5700-HJ-001-Vlanif1010]dhcp select interface
[S5700-HJ-001-Vlanif1010]dhcp server excluded-ip-address 10.10.10.200 10.10.10.254
[S5700-HJ-001-Vlanif1010]dhcp server dns-list 114.114.114.114 114.114.115.115
[S5700-HJ-001-Vlanif1010]
3)配置中继链路
将行政办公大楼汇聚交换机S5700-HJ-001
上的3-5
口接口进行配置:
[S5700-HJ-001]int g0/0/3
[S5700-HJ-001-GigabitEthernet0/0/3]port link-type trunk
[S5700-HJ-001-GigabitEthernet0/0/3]port trunk pvid vlan 4002
[S5700-HJ-001-GigabitEthernet0/0/3]port trunk allow-pass vlan 1010 4002
[S5700-HJ-001-GigabitEthernet0/0/3]int g0/0/4
[S5700-HJ-001-GigabitEthernet0/0/4]port link-type trunk
[S5700-HJ-001-GigabitEthernet0/0/4]port trunk pvid vlan 4002
[S5700-HJ-001-GigabitEthernet0/0/4]port trunk allow-pass vlan 1010 4002
[S5700-HJ-001-GigabitEthernet0/0/4]int g0/0/5
[S5700-HJ-001-GigabitEthernet0/0/5]port link-type trunk
[S5700-HJ-001-GigabitEthernet0/0/5]port trunk pvid vlan 4002
[S5700-HJ-001-GigabitEthernet0/0/5]port trunk allow-pass vlan 1010 4002
[S5700-HJ-001-GigabitEthernet0/0/5]
同时,检查24号上连端口,并配置如下:
[S5700-HJ-001]int g0/0/24
[S5700-HJ-001-GigabitEthernet0/0/24]dis th
#
interface GigabitEthernet0/0/24
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
return
[S5700-HJ-001-GigabitEthernet0/0/24]
4)路由信息
原配置的路由信息不变,全局配置信息如下:
[S5700-HJ-001]dis th
#
sysname S5700-HJ-001
#
undo info-center enable
#
vlan batch 1001 to 1010 4001 to 4002
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
dhcp enable
#
ip route-static 0.0.0.0 0.0.0.0 10.10.254.1
#
return
[S5700-HJ-001]
机房核心交换机S5700-HXSW
的配置主要是与其GigabitEthernet0/0/1
端口相连的无线网络控制器AC6005
,以及它与行政办公大楼汇聚交换机相连的GigabitEthernet0/0/4
端口的配置、VLAN
创建、路由等配置信息。
1)创建VLAN
创建VLAN4002
:
[S5700-HXSW]vlan b 4002
Info: This operation may take a few seconds. Please wait for a moment...done.
[S5700-HXSW]
2)配置中继链路
GigabitEthernet0/0/1
与AC相连的接口:
[S5700-HXSW]int g0/0/1
[S5700-HXSW-GigabitEthernet0/0/1] port link-type trunk
[S5700-HXSW-GigabitEthernet0/0/1] port trunk allow-pass vlan 4001 to 4002
[S5700-HXSW-GigabitEthernet0/0/1]
GigabitEthernet0/0/4
与行政办公大楼汇聚交换机相连的接口:
[S5700-HXSW]int g0/0/4
[S5700-HXSW-GigabitEthernet0/0/4] port link-type trunk
[S5700-HXSW-GigabitEthernet0/0/4] port trunk allow-pass vlan 2 to 4094
[S5700-HXSW-GigabitEthernet0/0/4]
3)路由配置
[S5700-HXSW]ip route-static 10.10.252.0 255.255.255.0 10.10.254.10
[S5700-HXSW]
这部分是本次仿真实验的重点部分,包括基础配置和无线配置。实际配置之前,应检查AP
的版本和AC
的版本是否一致,如果不一致,需要进行升级。
这里根据前面规划,AC
的管理地址为VLAN4001:10.10.254.10/24
,AC的源接口地址为VLAN4002:10.10.252.1/24
,根据前面的规划信息表进行配置。
1)创建VLAN
[AC6005]vlan batch 1010 4001 4002
Info: This operation may take a few seconds. Please wait for a moment...done.
[AC6005]
2)创建管理地址和源接口地址
[AC6005]interface vlanif 4001
[AC6005-Vlanif4001]ip address 10.10.254.10 255.255.255.0
[AC6005-Vlanif4001]interface vlanif 4002
[AC6005-Vlanif4002]ip address 10.10.252.1 255.255.255.0
[AC6005-Vlanif4002]
3)配置AP
的DHCP
地址池
[AC6005]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[AC6005]int vlanif4002
[AC6005-Vlanif4002]dhcp select interface
[AC6005-Vlanif4002]
4)配置接口
在GigabitEthernet0/0/1
接口上配置线路模式为中继模式,允许VLAN4001
和VLAN4002
通过:
[AC6005]int g0/0/1
[AC6005-GigabitEthernet0/0/1]port link-type trunk
[AC6005-GigabitEthernet0/0/1]port trunk allow-pass vlan 4001 to 4002
[AC6005-GigabitEthernet0/0/1]
5)路由配置
[AC6005]ip route-static 0.0.0.0 0.0.0.0 10.10.254.1
[AC6005]
1)创建AP组
配置项 | 数据 |
---|---|
AP组名称 | myap-group001 |
域管理模板 | mydomain001 |
国家代码 | CN |
[AC6005]wlan
[AC6005-wlan-view]ap-group name myap-group001
Info: This operation may take a few seconds. Please wait for a moment.done.
[AC6005-wlan-ap-group-myap-group001]quit
[AC6005-wlan-view]regulatory-domain-profile name mydomain001
[AC6005-wlan-regulate-domain-mydomain001]country-code CN
Info: The current country code is same with the input country code.
[AC6005-wlan-regulate-domain-mydomain001]quit
[AC6005-wlan-view]
上面分别为创建AP组名称,创建域模板,设置国家代码信息,然后进入AP组,应用域管理模板:
[AC6005-wlan-view]ap-group name myap-group001
[AC6005-wlan-ap-group-myap-group001]dis th
#
return
[AC6005-wlan-ap-group-myap-group001]regulatory-domain-profile mydomain001
Warning: Modifying the country code will clear channel, power and antenna gain c
onfigurations of the radio and reset the AP. Continue?[Y/N]:y
[AC6005-wlan-ap-group-myap-group001]quit
[AC6005-wlan-view]quit
[AC6005]
2)配置AC源接口
[AC6005]capwap source interface vlanif4002
[AC6005]
3)将AP绑定到AP组中
分别添加AP:
[AC6005]wlan
[AC6005-wlan-view]ap auth-mode mac-auth #配置为MAC认证方式
[AC6005-wlan-view]ap-id 0 ap-mac 00E0-FC77-2080
[AC6005-wlan-ap-0]ap-id 1 ap-mac 00E0-FCBF-0EB0
[AC6005-wlan-ap-1]ap-id 2 ap-mac 00E0-FC2F-40E0
[AC6005-wlan-ap-2]
根据MAC地址添加后,然后将其分别绑定到AP组并修改AP名称:
[AC6005-wlan-ap-2]quit
[AC6005-wlan-view]ap-id 0
[AC6005-wlan-ap-0]ap-name QHD_XZ_5F_001 #第1个AP的名称为:QHD_XZ_5F_001
[AC6005-wlan-ap-0]ap-group myap-group001
Warning: This operation may cause AP reset. If the country code changes, it will
clear channel, power and antenna gain configurations of the radio, Whether to c
ontinue? [Y/N]:y
Info: This operation may take a few seconds. Please wait for a moment.. done.
[AC6005-wlan-ap-0]ap-id 1
[AC6005-wlan-ap-1]ap-name QHD_XZ_5F_002 #第2个AP的名称为:QHD_XZ_5F_002
[AC6005-wlan-ap-1]ap-group myap-group001
Warning: This operation may cause AP reset. If the country code changes, it will
clear channel, power and antenna gain configurations of the radio, Whether to c
ontinue? [Y/N]:
Error: Please choose 'YES' or 'NO' first before pressing 'Enter'. [Y/N]:y
Info: This operation may take a few seconds. Please wait for a moment.. done.
[AC6005-wlan-ap-1]ap-id 2
[AC6005-wlan-ap-2]ap-name QHD_XZ_5F_003 #第3个AP的名称为:QHD_XZ_5F_003
[AC6005-wlan-ap-2]ap-group myap-group001
Warning: This operation may cause AP reset. If the country code changes, it will
clear channel, power and antenna gain configurations of the radio, Whether to c
ontinue? [Y/N]:
Error: Please choose 'YES' or 'NO' first before pressing 'Enter'. [Y/N]:y
Info: This operation may take a few seconds. Please wait for a moment.. done.
[AC6005-wlan-ap-2]dis th
#
ap-name QHD_XZ_5F_003
ap-group myap-group001
#
return
[AC6005-wlan-ap-2]quit
[AC6005-wlan-view]quit
[AC6005]
下面开始配置WLAN业务参数:
4)配置安全模板
创建安全配置文件名为mysec
,认证类型为wpa2
,无线密码为:myhuawei123
,如下:
[AC6005]wlan
[AC6005-wlan-view]security-profile name mysec
[AC6005-wlan-sec-prof-mysec]security wpa2 psk pass-phrase myhuawei123 aes
[AC6005-wlan-sec-prof-mysec]quit
[AC6005-wlan-view]
5)创建SSID
模板
创建ssid
模板名称为myssid
,无线网络名称为myhuaweiwifi
:
[AC6005-wlan-view]ssid-profile name myssid
[AC6005-wlan-ssid-prof-myssid]ssid myhuaweiwifi
Info: This operation may take a few seconds, please wait.done.
[AC6005-wlan-ssid-prof-myssid]quit
[AC6005-wlan-view]
6)创建并配置VAP
模板
创建vap
模板名称为myvap
,配置业务数据转发模式为隧道转发,配置业务VLAN ID
为1010
,并且引用安全模板mysec
和SSID
模板myssid
:
[AC6005-wlan-view]vap-profile name myvap
[AC6005-wlan-vap-prof-myvap]forward-mode tunnel
Info: This operation may take a few seconds, please wait.done.
[AC6005-wlan-vap-prof-myvap]service-vlan vlan-id 1010
Info: This operation may take a few seconds, please wait.done.
[AC6005-wlan-vap-prof-myvap]security-profile mysec
Info: This operation may take a few seconds, please wait.done.
[AC6005-wlan-vap-prof-myvap]ssid-profile myssid
Info: This operation may take a few seconds, please wait.done.
[AC6005-wlan-vap-prof-myvap]quit
[AC6005-wlan-view]
7)配置AP组引用VAP
模板
[AC6005-wlan-view]ap-group name myap-group001
[AC6005-wlan-ap-group-myap-group001]vap-profile myvap wlan 1 radio all
Info: This operation may take a few seconds, please wait...done.
[AC6005-wlan-ap-group-myap-group001]dis th
#
regulatory-domain-profile mydomain001
radio 0
vap-profile myvap wlan 1
radio 1
vap-profile myvap wlan 1
radio 2
vap-profile myvap wlan 1
#
return
[AC6005-wlan-ap-group-myap-group001]
8)保存退出
[AC6005]quit
<AC6005>sa
The current configuration will be written to the device.
Are you sure to continue? (y/n)[n]:y
It will take several minutes to save configuration file, please wait.......
Configuration file has been saved successfully
Note: The configuration file will take effect after being activated
<AC6005>
如下图,随便找一个终端,然后查看VAP
列表,发现有2.4G
和5G
的无线信号,根据前面设置的密码进行连接:
VAP
射频信号状态在无线网络控制器AC6005
上查看VAP
是否成功创建:
<AC6005>dis vap ssid myhuaweiwifi
Info: This operation may take a few seconds, please wait.
WID : WLAN ID
------------------------------------------------------------------------------------
AP ID AP name RfID WID BSSID Status Auth type STA SSID
------------------------------------------------------------------------------------
0 QHD_XZ_5F_001 0 1 00E0-FC77-2080 ON WPA2-PSK 2 myhuaweiwifi
0 QHD_XZ_5F_001 1 1 00E0-FC77-2090 ON WPA2-PSK 0 myhuaweiwifi
1 QHD_XZ_5F_002 0 1 00E0-FCBF-0EB0 ON WPA2-PSK 3 myhuaweiwifi
1 QHD_XZ_5F_002 1 1 00E0-FCBF-0EC0 ON WPA2-PSK 0 myhuaweiwifi
2 QHD_XZ_5F_003 0 1 00E0-FC2F-40E0 ON WPA2-PSK 2 myhuaweiwifi
2 QHD_XZ_5F_003 1 1 00E0-FC2F-40F0 ON WPA2-PSK 0 myhuaweiwifi
------------------------------------------------------------------------------------
Total: 6
<AC6005>
也可以直接查看所有AP的状态:
<AC6005>dis ap all
Info: This operation may take a few seconds. Please wait for a moment.done.
Total AP information:
nor : normal [3]
----------------------------------------------------------------------------------------------------------
ID MAC Name Group IP Type St
ate STA Uptime
----------------------------------------------------------------------------------------------------------
0 00e0-fc77-2080 QHD_XZ_5F_001 myap-group001 10.10.252.168 AP6050DN no
r 2 10M:39S
1 00e0-fcbf-0eb0 QHD_XZ_5F_002 myap-group001 10.10.252.139 AP7050DE no
r 3 10M:28S
2 00e0-fc2f-40e0 QHD_XZ_5F_003 myap-group001 10.10.252.115 AP7050DE no
r 2 10M:40S
----------------------------------------------------------------------------------------------------------
Total: 3
<AC6005>
网站声明:如果转载,请联系本站管理员。否则一切后果自行承担。
加入交流群
请使用微信扫一扫!