No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

WLAN V200R008C10 Typical Configuration Examples

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Example for Configuring Dual-Link HSB in Load Balancing Mode (Traditional Method)

Example for Configuring Dual-Link HSB in Load Balancing Mode (Traditional Method)

Service Requirements

An enterprise deploys a WLAN to provide WLAN services to users. The enterprise requires dual-link HSB to improve data transmission reliability, and load balancing on the active and standby ACs.

Networking Requirements

  • AC networking mode: Layer 2 bypass mode
  • DHCP deployment mode: The router functions as a DHCP server to assign IP addresses to APs and STAs.
  • Service data forwarding mode: direct forwarding
Figure 4-43 Networking diagram for configuring dual-Link HSB in load balancing mode for ACs

Data Planning

Table 4-41 AC data planning
Item Data

Management VLAN for APs

VLAN 100

Service VLAN for STAs

VLAN 101

AC's backup VLAN

VLAN 102

DHCP server

The router functions as a DHCP server to assign IP addresses to APs and STAs.

STAs' gateway: 10.23.101.1/24

APs' gateway: 10.23.100.1/24

IP address pool for APs

10.23.100.4-10.23.100.254/24

IP address pool for STAs

10.23.101.2-10.23.101.254/24

AC's source interface

VLANIF 100

AC1's management IP address

VLANIF 100: 10.23.100.2/24

AC2's management IP address

VLANIF 100: 10.23.100.3/24

Active and standby ACs

AC1 serves as the active AC for AP1 and the standby AC for AP2.

AC2 serves as the active AC for AP2 and the standby AC for AP1.

IP addresses and port numbers for the active and standby channels of AC1

IP address: VLANIF 102, 10.23.102.1/24

Port number: 10241

IP addresses and port numbers for the active and standby channels of AC2

IP address: VLANIF 102, 10.23.102.2/24

Port number: 10241

AP group

ap-group1 on both AC1 and AC2
  • Name: ap-group1

  • Referenced profiles: VAP profile wlan-net and regulatory domain profile default

ap-group2 only on AC2
  • Name: ap-group2

  • Referenced profiles: VAP profile wlan-net, regulatory domain profile default, and AP system profile ap-system1

AP system profile

ap-system1 only on AC2
  • Name: ap-system1

  • Priority: 0

Global priority of AC1

3

Global priority of AC2

5

Regulatory domain profile

  • Name: default
  • Country code: China

SSID profile

  • Name: wlan-net

  • SSID name: wlan-net

Security profile

  • Name: wlan-net

  • Security policy: WPA-WPA2+PSK+AES

  • Password: a1234567

VAP profile

  • Name: wlan-net

  • Forwarding mode: tunnel forwarding

  • Service VLAN: VLAN 101

  • Referenced profiles: SSID profile wlan-net and security profile wlan-net

Configuration Roadmap

  1. Configure network interworking of the AP1, AC2, and other network devices.
  2. Configure the APs to go online and configure basic WLAN services.
  3. Configure dual-link HSB in load balancing mode.
  4. Configure HSB on the ACs so that the WLAN and NAC services on the active AC are backed up to the standby AC in real time and in batches. If the active AC is faulty, the standby AC takes over services of the active AC, ensuring user service continuity.

Configuration Notes

  • No ACK mechanism is provided for multicast packet transmission on air interfaces. In addition, wireless links are unstable. To ensure stable transmission of multicast packets, they are usually sent at low rates. If a large number of such multicast packets are sent from the network side, the air interfaces may be congested. You are advised to configure multicast packet suppression to reduce impact of a large number of low-rate multicast packets on the wireless network. Exercise caution when configuring the rate limit; otherwise, the multicast services may be affected.
    • In direct forwarding mode, you are advised to configure multicast packet suppression on switch interfaces connected to APs.
    • In tunnel forwarding mode, you are advised to configure multicast packet suppression in traffic profiles of the AC.
    For details on how to configure traffic suppression, see How Do I Configure Multicast Packet Suppression to Reduce Impact of a Large Number of Low-Rate Multicast Packets on the Wireless Network?.
  • Configure port isolation on the interfaces of the device directly connected to APs. If port isolation is not configured and direct forwarding is used, a large number of unnecessary broadcast packets may be generated in the VLAN, blocking the network and degrading user experience.

  • In tunnel forwarding mode, the management VLAN and service VLAN cannot be the same. Only packets from the management VLAN are transmitted between the AC and APs. Packets from the service VLAN are not allowed between the AC and APs.

  • Dual-link backup cannot back up DHCP information. When the AC functions as the DHCP server to assign IP addresses to APs and STAs, APs and STAs need to re-obtain IP addresses if the active AC is faulty. It is recommended that Router function as the DHCP server. If the AC must be used as the DHCP server, configure address pools containing different IP addresses on the active and standby ACs to prevent IP address conflicts.

Procedure

  1. Configure the switches and Router.

    # Set the PVID of GE0/0/1 and GE0/0/2 on SwitchA to management VLAN 100, and add the interfaces to VLAN 100 and VLAN 101. Add GE0/0/3 on SwitchA connected to SwitchB to VLAN 100 and VLAN 101.

    <HUAWEI> system-view
    [HUAWEI] sysname SwitchA
    [SwitchA] vlan batch 100 101
    [SwitchA] interface gigabitethernet 0/0/1
    [SwitchA-GigabitEthernet0/0/1] port link-type trunk
    [SwitchA-GigabitEthernet0/0/1] port trunk pvid vlan 100
    [SwitchA-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 101
    [SwitchA-GigabitEthernet0/0/1] port-isolate enable
    [SwitchA-GigabitEthernet0/0/1] quit
    [SwitchA] interface gigabitethernet 0/0/2
    [SwitchA-GigabitEthernet0/0/2] port link-type trunk
    [SwitchA-GigabitEthernet0/0/2] port trunk pvid vlan 100
    [SwitchA-GigabitEthernet0/0/2] port trunk allow-pass vlan 100 101
    [SwitchA-GigabitEthernet0/0/2] port-isolate enable
    [SwitchA-GigabitEthernet0/0/2] quit
    [SwitchA] interface gigabitethernet 0/0/3
    [SwitchA-GigabitEthernet0/0/3] port link-type trunk
    [SwitchA-GigabitEthernet0/0/3] port trunk allow-pass vlan 100 101
    [SwitchA-GigabitEthernet0/0/3] quit
    

    # Add GE0/0/1 on SwitchB connected to SwitchA to VLAN 100 and VLAN 101. Add GE0/0/2 (connected to AC1) and GE0/0/3 (connected to AC2) on SwitchB to VLAN 100 and VLAN 102. Add GE0/0/4 on SwitchB connected to Router to VLAN 100 and VLAN 101.

    <HUAWEI> system-view
    [HUAWEI] sysname SwitchB
    [SwitchB] vlan batch 100 to 102
    [SwitchB] interface gigabitethernet 0/0/1
    [SwitchB-GigabitEthernet0/0/1] port link-type trunk
    [SwitchB-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 101
    [SwitchB-GigabitEthernet0/0/1] quit
    [SwitchB] interface gigabitethernet 0/0/2
    [SwitchB-GigabitEthernet0/0/2] port link-type trunk
    [SwitchB-GigabitEthernet0/0/2] port trunk allow-pass vlan 100 102
    [SwitchB-GigabitEthernet0/0/2] quit
    [SwitchB] interface gigabitethernet 0/0/3
    [SwitchB-GigabitEthernet0/0/3] port link-type trunk
    [SwitchB-GigabitEthernet0/0/3] port trunk allow-pass vlan 100 102
    [SwitchB-GigabitEthernet0/0/3] quit
    [SwitchB] interface gigabitethernet 0/0/4
    [SwitchB-GigabitEthernet0/0/4] port link-type trunk
    [SwitchB-GigabitEthernet0/0/4] port trunk allow-pass vlan 100 101
    [SwitchB-GigabitEthernet0/0/4] quit
    

    # Add GE0/0/1 on Router connected to SwitchB to VLAN 100 and VLAN 101.

    <Huawei> system-view
    [Huawei] sysname Router
    [Router] vlan batch 100 101
    [Router] interface gigabitethernet 0/0/1
    [Router-GigabitEthernet0/0/1] port link-type trunk
    [Router-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 101
    [Router-GigabitEthernet0/0/1] quit
    

  2. Configure the communication between AC1, AC2, and Router.

    # Add GE0/0/1 on AC1 to the service VLAN 101 and backup VLAN 102.

    <AC6605> system-view
    [AC6605] sysname AC1
    [AC1] vlan batch 100 to 102
    [AC1] interface vlanif 100
    [AC1-Vlanif100] ip address 10.23.100.2 24
    [AC1-Vlanif100] quit
    [AC1] interface vlanif 102
    [AC1-Vlanif102] ip address 10.23.102.1 24
    [AC1-Vlanif102] quit
    [AC1] interface gigabitethernet 0/0/1
    [AC1-GigabitEthernet0/0/1] port link-type trunk
    [AC1-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 102
    [AC1-GigabitEthernet0/0/1] quit

    # Add GE0/0/1 on AC2 to VLAN 101 and VLAN 102.

    <AC6605> system-view
    [AC6605] sysname AC2
    [AC2] vlan batch 100 to 102
    [AC2] interface vlanif 100
    [AC2-Vlanif100] ip address 10.23.100.3 24
    [AC2-Vlanif100] quit
    [AC2] interface vlanif 102
    [AC2-Vlanif102] ip address 10.23.102.2 24
    [AC2-Vlanif102] quit
    [AC2] interface gigabitethernet 0/0/1
    [AC2-GigabitEthernet0/0/1] port link-type trunk
    [AC2-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 102
    [AC2-GigabitEthernet0/0/1] quit

  3. Configure Router to assign IP addresses to STAs and APs.

    NOTE:
    Configure the DNS server as required. The common methods are as follows:
    • In interface address pool scenarios, run the dhcp server dns-list ip-address &<1-8> command in the VLANIF interface view.
    • In global address pool scenarios, run the dns-list ip-address &<1-8> command in the IP address pool view.
    [Router] dhcp enable
    [Router] ip pool sta
    [Router-ip-pool-sta] network 10.23.101.0 mask 24
    [Router-ip-pool-sta] gateway-list 10.23.101.1
    [Router-ip-pool-sta] quit
    [Router] ip pool ap
    [Router-ip-pool-ap] network 10.23.100.0 mask 24
    [Router-ip-pool-ap] excluded-ip-address 10.23.100.2
    [Router-ip-pool-ap] excluded-ip-address 10.23.100.3
    [Router-ip-pool-ap] gateway-list 10.23.100.1
    [Router-ip-pool-ap] quit
    [Router] interface vlanif 100
    [Router-Vlanif100] ip address 10.23.100.1 24
    [Router-Vlanif100] dhcp select global
    [Router-Vlanif100] quit
    [Router] interface vlanif 101
    [Router-Vlanif101] ip address 10.23.101.1 24
    [Router-Vlanif101] dhcp select global
    [Router-Vlanif101] quit
    

  4. Configure the APs to go online.
    1. Configure AC1.

      # Create the AP group ap-group1.
      [AC1] wlan
      [AC1-wlan-view] ap-group name ap-group1
      [AC1-wlan-ap-group-ap-group1] quit
      
      # Create a regulatory domain profile, configure the country code for AC1 in the profile, and apply the profile to the AP group.
      [AC1-wlan-view] regulatory-domain-profile name default
      [AC1-wlan-regulate-domain-default] country-code cn
      [AC1-wlan-regulate-domain-default] quit
      [AC1-wlan-view] ap-group name ap-group1
      [AC1-wlan-ap-group-ap-group1] regulatory-domain-profile default
      Warning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continu
      e?[Y/N]:y 
      [AC1-wlan-ap-group-ap-group1] quit
      [AC1-wlan-view] quit
      
      # Configure the source interface for AC1.
      [AC1] capwap source interface vlanif 100
      
      # Import AP1 and AP2 offline on AC1, and add the APs to the AP group ap-group1.
      [AC1] wlan
      [AC1-wlan-view] ap auth-mode mac-auth
      [AC1-wlan-view] ap-id 0 ap-mac 60de-4476-e360
      [AC1-wlan-ap-0] ap-name area_1
      Warning: This operation may cause AP reset. Continue? [Y/N]:y 
      [AC1-wlan-ap-0] ap-group ap-group1
      Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configuration
      s of the radio, Whether to continue? [Y/N]:y 
      [AC1-wlan-ap-0] quit
      [AC1-wlan-view] ap-id 1 ap-mac 60de-4476-e380
      [AC1-wlan-ap-1] ap-name area_2
      Warning: This operation may cause AP reset. Continue? [Y/N]:y 
      [AC1-wlan-ap-1] ap-group ap-group1
      Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configuration
      s of the radio, Whether to continue? [Y/N]:y 
      [AC1-wlan-ap-1] quit
      
      # After the APs are powered on, run the display ap all command to check the AP states. If the State field displays nor, the APs have gone online.
      [AC1-wlan-view] display ap all
      Total AP information:
      nor  : normal          [2]
      -------------------------------------------------------------------------------------
      ID   MAC            Name   Group     IP            Type            State STA Uptime
      -------------------------------------------------------------------------------------
      0    60de-4476-e360 area_1 ap-group1 10.23.100.254 AP5030DN        nor   0   31S
      1    60de-4476-e380 area_2 ap-group1 10.23.100.253 AP5030DN        nor   0   10S
      -------------------------------------------------------------------------------------
      Total: 2

    2. Configure AC2.

      # Create AP groups ap-group1 and ap-group2.
      [AC2] wlan
      [AC2-wlan-view] ap-group name ap-group1
      [AC2-wlan-ap-group-ap-group1] quit
      [AC2-wlan-view] ap-group name ap-group2
      [AC2-wlan-ap-group-ap-group2] quit
      
      # Create a regulatory domain profile, configure the country code for AC2 in the profile, and apply the profile to the AP group.
      [AC2-wlan-view] regulatory-domain-profile name default
      [AC2-wlan-regulate-domain-default] country-code cn
      [AC2-wlan-regulate-domain-default] quit
      [AC2-wlan-view] ap-group name ap-group1
      [AC2-wlan-ap-group-ap-group1] regulatory-domain-profile default
      Warning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continu
      e?[Y/N]:y 
      [AC2-wlan-ap-group-ap-group1] quit
      [AC2-wlan-view] ap-group name ap-group2
      [AC2-wlan-ap-group-ap-group2] regulatory-domain-profile default
      Warning: Modifying the country code will clear channel, power and antenna gain configurations of the radio and reset the AP. Continu
      e?[Y/N]:y 
      [AC2-wlan-ap-group-ap-group2] quit
      [AC2-wlan-view] quit
      
      # Configure the source interface for AC2.
      [AC2] capwap source interface vlanif 100
      
      # Import AP1 and AP2 offline on AC2, and add AP1 to the AP group ap-group1 and AP2 to the AP group ap-group2.
      [AC2] wlan
      [AC2-wlan-view] ap auth-mode mac-auth
      [AC2-wlan-view] ap-id 0 ap-mac 60de-4476-e360
      [AC2-wlan-ap-0] ap-name area_1
      Warning: This operation may cause AP reset. Continue? [Y/N]:y 
      [AC2-wlan-ap-0] ap-group ap-group1
      Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configuration
      s of the radio, Whether to continue? [Y/N]:y 
      [AC2-wlan-ap-0] quit
      [AC2-wlan-view] ap-id 1 ap-mac 60de-4476-e380
      [AC2-wlan-ap-1] ap-name area_2
      Warning: This operation may cause AP reset. Continue? [Y/N]:y 
      [AC2-wlan-ap-1] ap-group ap-group2
      Warning: This operation may cause AP reset. If the country code changes, it will clear channel, power and antenna gain configuration
      s of the radio, Whether to continue? [Y/N]:y 
      [AC2-wlan-ap-1] quit
      

  5. Configure WLAN service parameters.
    1. Configure AC1.

      # Create security profile wlan-net and set the security policy in the profile.
      NOTE:

      In this example, the security policy is set to WPA-WPA2+PSK+AES and password to a1234567. In actual situations, the security policy must be configured according to service requirements.

      [AC1-wlan-view] security-profile name wlan-net
      [AC1-wlan-sec-prof-wlan-net] security wpa-wpa2 psk pass-phrase a1234567 aes
      [AC1-wlan-sec-prof-wlan-net] quit
      

      # Create SSID profile wlan-net and set the SSID name to wlan-net.

      [AC1-wlan-view] ssid-profile name wlan-net
      [AC1-wlan-ssid-prof-wlan-net] ssid wlan-net
      Warning: This action may cause service interruption. Continue?[Y/N]y
      [AC1-wlan-ssid-prof-wlan-net] quit
      

      # Create VAP profile wlan-net, set the data forwarding mode and service VLAN, and apply the security profile and SSID profile to the VAP profile.

      [AC1-wlan-view] vap-profile name wlan-net
      [AC1-wlan-vap-prof-wlan-net] forward-mode direct-forward
      [AC1-wlan-vap-prof-wlan-net] service-vlan vlan-id 101
      [AC1-wlan-vap-prof-wlan-net] security-profile wlan-net
      [AC1-wlan-vap-prof-wlan-net] ssid-profile wlan-net
      [AC1-wlan-vap-prof-wlan-net] quit
      

      # Bind VAP profile wlan-net to the AP group, and apply the profile to radio 0 and radio 1 of the AP.

      [AC1-wlan-view] ap-group name ap-group1
      [AC1-wlan-ap-group-ap-group1] vap-profile wlan-net wlan 1 radio 0
      [AC1-wlan-ap-group-ap-group1] vap-profile wlan-net wlan 1 radio 1
      [AC1-wlan-ap-group-ap-group1] quit
      

    2. Configure AC2.

      # Create security profile wlan-net and set the security policy in the profile.

      [AC2-wlan-view] security-profile name wlan-net
      [AC2-wlan-sec-prof-wlan-net] security wpa-wpa2 psk pass-phrase a1234567 aes
      [AC2-wlan-sec-prof-wlan-net] quit
      

      # Create SSID profile wlan-net and set the SSID name to wlan-net.

      [AC2-wlan-view] ssid-profile name wlan-net
      [AC2-wlan-ssid-prof-wlan-net] ssid wlan-net
      Warning: This action may cause service interruption. Continue?[Y/N]y
      [AC2-wlan-ssid-prof-wlan-net] quit
      

      # Create VAP profile wlan-net, set the data forwarding mode and service VLAN, and apply the security profile and SSID profile to the VAP profile.

      [AC2-wlan-view] vap-profile name wlan-net
      [AC2-wlan-vap-prof-wlan-net] forward-mode direct-forward
      [AC2-wlan-vap-prof-wlan-net] service-vlan vlan-id 101
      [AC2-wlan-vap-prof-wlan-net] security-profile wlan-net
      [AC2-wlan-vap-prof-wlan-net] ssid-profile wlan-net
      [AC2-wlan-vap-prof-wlan-net] quit
      

      # Bind VAP profile wlan-net to the AP group, and apply the profile to radio 0 and radio 1 of the AP.

      [AC2-wlan-view] ap-group name ap-group1
      [AC2-wlan-ap-group-ap-group1] vap-profile wlan-net wlan 1 radio 0
      [AC2-wlan-ap-group-ap-group1] vap-profile wlan-net wlan 1 radio 1
      [AC2-wlan-ap-group-ap-group1] quit
      [AC2-wlan-view] ap-group name ap-group2
      [AC2-wlan-ap-group-ap-group2] vap-profile wlan-net wlan 1 radio 0
      [AC2-wlan-ap-group-ap-group2] vap-profile wlan-net wlan 1 radio 1
      [AC2-wlan-ap-group-ap-group2] quit
      

  6. Configure dual-link HSB in load balancing mode on AC1 and AC2.

    # Configure the AC1 priority and AC2 IP address in the WLAN view of AC1.
    [AC1-wlan-view] ac protect enable
    Warning: This operation maybe cause AP reset, continue?[Y/N]:y
    [AC1-wlan-view] ac protect protect-ac 10.23.100.3 priority 3
    

    # Configure the AC2 priority and AC1 IP address on AC2 in the WLAN view and AP system profile view of AC2.

    [AC2-wlan-view] ac protect enable
    Warning: This operation maybe cause AP reset, continue?[Y/N]:y
    [AC2-wlan-view] ac protect protect-ac 10.23.100.2 priority 5
    [AC2-wlan-view] ap-system-profile name ap-system1
    [AC2-wlan-ap-system-prof-ap-system1] protect-ac ip-address 10.23.100.2 priority 0
    [AC2-wlan-ap-system-prof-ap-system1] quit
    [AC2-wlan-view] ap-group name ap-group2
    [AC2-wlan-ap-group-ap-group2] ap-system-profile ap-system1
    [AC2-wlan-ap-group-ap-group2] quit
    

    # Restart the APs on AC1 and AC2, and deliver the dual-link HSB configuration to the APs.

    [AC1-wlan-view] ap-reset all
    Warning: Reset AP(s), continue?[Y/N]:y
    [AC1-wlan-view] quit
    [AC2-wlan-view] ap-reset all
    Warning: Reset AP(s), continue?[Y/N]:y
    [AC2-wlan-view] quit

  7. Configure the HSB function.

    # Create HSB service 0 on AC1 and configure the IP addresses and port numbers for the active and standby channels.

    [AC1] hsb-service 0
    [AC1-hsb-service-0] service-ip-port local-ip 10.23.102.1 peer-ip 10.23.102.2 local-data-port 10241 peer-data-port 10241
    [AC1-hsb-service-0] quit

    # Bind the WLAN and NAC services to AC1.

    [AC1] hsb-service-type ap hsb-service 0
    [AC1] hsb-service-type access-user hsb-service 0

    # Create HSB service 0 on AC2 and configure the IP addresses and port numbers for the active and standby channels.

    [AC2] hsb-service 0
    [AC2-hsb-service-0] service-ip-port local-ip 10.23.102.2 peer-ip 10.23.102.1 local-data-port 10241 peer-data-port 10241
    [AC2-hsb-service-0] quit

    # Bind the WLAN and NAC services to AC2.

    [AC2] hsb-service-type ap hsb-service 0
    [AC2] hsb-service-type access-user hsb-service 0

  8. Verify the configuration.

    # Run the display ac protect command on AC1 and AC2 to view dual-link HSB information.

    [AC1] display ac protect
    ------------------------------------------------------------
    Protect state             : enable
    Protect AC                : 10.23.100.3
    Priority                  : 3
    Protect restore           : enable
    ...
    ------------------------------------------------------------ 
    [AC2] display ac protect
    ------------------------------------------------------------
    Protect state             : enable
    Protect AC                : 10.23.100.2
    Priority                  : 5
    Protect restore           : enable
    ...
    ------------------------------------------------------------ 

    # Run the display ap-system-profile name ap-system1 command on AC2 to view information about the active and standby ACs.

    [AC2] display ap-system-profile name ap-system1
    ------------------------------------------------------------
    AC priority                   : 0
    Protect AC IP address         : 10.23.100.2
    ...
    ------------------------------------------------------------ 
    

    # Run the display hsb-service 0 command on AC1 and AC2 to check the HSB service status. The value of the Service State field is Connected, which indicates that the HSB channels are set up.

    [AC1] display hsb-service 0
    Hot Standby Service Information:
    ----------------------------------------------------------
      Local IP Address       : 10.23.102.1
      Peer IP Address        : 10.23.102.2
      Source Port            : 10241
      Destination Port       : 10241
      Keep Alive Times       : 5
      Keep Alive Interval    : 3
      Service State          : Connected
      Service Batch Modules  : AP
                               Access-user
      Shared-key             : -
    ----------------------------------------------------------
    
    [AC2] display hsb-service 0
    Hot Standby Service Information:
    ----------------------------------------------------------
      Local IP Address       : 10.23.102.2
      Peer IP Address        : 10.23.102.1
      Source Port            : 10241
      Destination Port       : 10241
      Keep Alive Times       : 5
      Keep Alive Interval    : 3
      Service State          : Connected
      Service Batch Modules  : AP
                               Access-user
      Shared-key             : -
    ----------------------------------------------------------
    

    The WLAN with SSID wlan-net is available for STAs connected to AP1, and these STAs can connect to the WLAN.

    If the APs are disconnected from AC1, STAs associated with the APs do not go offline.

Configuration Files

  • SwitchA configuration file

    #
    sysname SwitchA
    #
    vlan batch 100 to 101
    #
    interface GigabitEthernet0/0/1
     port link-type trunk
     port trunk pvid vlan 100
     port trunk allow-pass vlan 100 to 101
     port-isolate enable group 1
    #
    interface GigabitEthernet0/0/2
     port link-type trunk
     port trunk pvid vlan 100
     port trunk allow-pass vlan 100 to 101
     port-isolate enable group 1
    #
    interface GigabitEthernet0/0/3
     port link-type trunk
     port trunk allow-pass vlan 100 to 101
    #
    return
  • SwitchB configuration file

    #
    sysname SwitchB
    #
    vlan batch 100 to 102
    #
    interface GigabitEthernet0/0/1
     port link-type trunk
     port trunk allow-pass vlan 100 to 101
    #
    interface GigabitEthernet0/0/2
     port link-type trunk
     port trunk allow-pass vlan 100 102
    #
    interface GigabitEthernet0/0/3
     port link-type trunk
     port trunk allow-pass vlan 100 102
    #
    interface GigabitEthernet0/0/4
     port link-type trunk
     port trunk allow-pass vlan 100 to 101
    #
    return
  • Router configuration file

    #
     sysname Router
    #
    vlan batch 100 to 101
    #
    dhcp enable
    #
    ip pool sta
     gateway-list 10.23.101.1
     network 10.23.101.0 mask 255.255.255.0
    #
    ip pool ap
     gateway-list 10.23.100.1
     network 10.23.100.0 mask 255.255.255.0
     excluded-ip-address 10.23.100.2 10.23.100.3      
    #
    interface Vlanif100
     ip address 10.23.100.1 255.255.255.0
     dhcp select global
    #
    interface Vlanif101
     ip address 10.23.101.1 255.255.255.0
     dhcp select global
    #
    interface GigabitEthernet0/0/1
     port link-type trunk
     port trunk allow-pass vlan 100 to 101
    #
    return
  • AC1 configuration file

    #
     sysname AC1
    #
    vlan batch 100 to 102
    #
    interface Vlanif100
     ip address 10.23.100.2 255.255.255.0
    #
    interface Vlanif102
     ip address 10.23.102.1 255.255.255.0
    #
    interface GigabitEthernet0/0/1
     port link-type trunk
     port trunk allow-pass vlan 100 102
    #
    capwap source interface vlanif100
    #
    hsb-service 0
     service-ip-port local-ip 10.23.102.1 peer-ip 10.23.102.2 local-data-port 10241 peer-data-port 10241
    #
    hsb-service-type access-user hsb-service 0
    #
    hsb-service-type ap hsb-service 0
    #
    wlan
     ac protect enable protect-ac 10.23.100.3 priority 3
     security-profile name wlan-net
      security wpa-wpa2 psk pass-phrase %^%#.9{"H[]w$ROvD%7)hQAT>')_;/mL+~Y;b`7P"s](%^%# aes
     ssid-profile name wlan-net
      ssid wlan-net
     vap-profile name wlan-net
      service-vlan vlan-id 101
      ssid-profile wlan-net
      security-profile wlan-net
     regulatory-domain-profile name default
     ap-group name ap-group1
      radio 0
       vap-profile wlan-net wlan 1 
      radio 1
       vap-profile wlan-net wlan 1
     ap-id 0 ap-mac 60de-4476-e360 ap-sn 210235554710CB000042
      ap-name area_1
      ap-group ap-group1
     ap-id 1 ap-mac 60de-4476-e380 ap-sn 210235554710CB000043
      ap-name area_2
      ap-group ap-group1
    #
    return
  • AC2 configuration file

    #
     sysname AC2
    #
    vlan batch 100 to 102
    #
    interface Vlanif100
     ip address 10.23.100.3 255.255.255.0
    #
    interface Vlanif102
     ip address 10.23.102.2 255.255.255.0
    #
    interface GigabitEthernet0/0/1
     port link-type trunk
     port trunk allow-pass vlan 100 102
    #
    capwap source interface vlanif100
    #
    hsb-service 0
     service-ip-port local-ip 10.23.102.2 peer-ip 10.23.102.1 local-data-port 10241 peer-data-port 10241
    #
    hsb-service-type access-user hsb-service 0
    #
    hsb-service-type ap hsb-service 0
    #
    wlan
     ac protect enable protect-ac 10.23.100.2 priority 5
     security-profile name wlan-net
      security wpa-wpa2 psk pass-phrase %^%#0zxk;0s^'OXs-]Q,SM7BL"@t:J=AV8x!hG!\,fI.%^%# aes
     ssid-profile name wlan-net
      ssid wlan-net
     vap-profile name wlan-net
      service-vlan vlan-id 101
      ssid-profile wlan-net
      security-profile wlan-net
     regulatory-domain-profile name default
     ap-system-profile name ap-system1
      priority 0
      protect-ac ip-address 10.23.100.2
     ap-group name ap-group1
      radio 0
       vap-profile wlan-net wlan 1 
      radio 1
       vap-profile wlan-net wlan 1
     ap-group name ap-group2
      ap-system-profile ap-system1
      radio 0
       vap-profile wlan-net wlan 1 
      radio 1
       vap-profile wlan-net wlan 1
     ap-id 0 ap-mac 60de-4476-e360 ap-sn 210235554710CB000042
      ap-name area_1
      ap-group ap-group1
     ap-id 1 ap-mac 60de-4476-e380 ap-sn 210235554710CB000043
      ap-name area_2
      ap-group ap-group2
    #
    return
Translation
Download
Updated: 2019-03-30

Document ID: EDOC1000184389

Views: 94578

Downloads: 548

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next