Configuration Roadmap and Data Plan
Configuration Roadmap
The configuration roadmap is as follows:
- Configure a cluster switch system (CSS) for core switches to ensure their reliability. Configure the Virtual Router Redundancy Protocol (VRRP) on the ACs to ensure the reliability of WLAN services.
- Configure MAC address–prioritized Portal authentication and 802.1X authentication. Common guests use MAC address–prioritized Portal authentication to access the enterprise home page. Enterprise employees use employee accounts for network access through 802.1X authentication.
- Configure WLAN services on the ACs to meet wireless access requirements in offices.
- Configure wireless configuration synchronization so that public configurations can be synchronized from the master AC to the backup AC.
- Add the ACs to the Service Manager of Agile Controller-Campus and configure parameters to ensure that Agile Controller-Campus can communicate with the ACs.
- Add an authorization result and authorization rule to grant access control permission to employees after they are successfully authenticated.
Data Planning
Table 4-137 and Table 4-138 describe data required for completing the configuration tasks.
Item |
No. |
Interface Number |
VLAN to Which the Interface Belongs |
IP Address |
Description |
---|---|---|---|---|---|
Access switch S5700_A |
1 |
GE0/0/1 |
VLAN 800 VLAN 700 VLAN 701 |
- |
Connects to AP_1. |
2 |
GE0/0/2 |
VLAN 800 VLAN 700 VLAN 701 |
- |
Connects to AP_2. |
|
3 |
GE0/0/3 |
VLAN 800 VLAN 700 VLAN 701 |
- |
Connects to the aggregation switch S7700. |
|
Aggregation switch S7700 |
13 |
GE1/0/3 |
VLAN 800 VLAN 700 VLAN 701 |
- |
Access switch S5700_A |
17 |
GE1/0/17 |
VLAN 800 VLAN 700 VLAN 701 |
- |
Connects to S12700_A. |
|
18 |
GE2/0/18 |
VLAN 800 VLAN 700 VLAN 701 |
- |
Connects to S12700_B. |
|
S12700_A and S12700_B in a cluster |
19 |
GE1/1/0/19 |
VLAN 800 VLAN 700 VLAN 701 |
- |
Connects to the aggregation switch S7700. |
22 |
GE2/1/0/22 |
VLAN 800 VLAN 700 VLAN701 |
- |
||
20 |
GE1/1/0/20 |
VLAN 800 VLAN 820 VLAN 700 VLAN 701 |
- |
Connects to AC_1. |
|
23 |
GE2/1/0/23 |
VLAN 800 VLAN 820 VLAN 700 VLAN 701 |
- |
Connects to AC_2. |
|
21 |
GE1/1/0/21 |
VLAN 820 VLAN 700 VLAN 701 |
- |
Connects to the router. |
|
24 |
GE2/1/0/18 |
VLAN 820 VLAN 700 VLAN 701 |
- |
Connects to the router. |
|
AC_1 |
25 |
GE0/0/24 |
VLAN 800 VLAN 820 VLAN 700 VLAN 701 |
VLANIF 800: 10.128.1.2/24 VLANIF 820: 172.16.1.2/24 |
Connects to S12700_A. |
26 |
GE0/0/23 |
VLAN 810 |
VLANIF 810: 10.1.1.253/30 |
Connects to AC_2. |
|
AC_2 |
27 |
GE0/0/24 |
VLAN 800 VLAN 820 VLAN 700 VLAN 701 |
VLANIF 800: 10.128.1.3/24 VLANIF 820: 172.16.1.3/24 |
Connects to S12700_B. |
28 |
GE0/0/23 |
VLAN 810 |
VLANIF 810: 10.1.1.254/30 |
Connects to AC_1. |
|
Router |
29 |
- |
- |
- |
Connects to S12700_A. |
30 |
- |
- |
- |
Connects to S12700_B. |
Item |
Description |
---|---|
Management VLAN for APs |
VLAN800 |
Service VLANs |
VLAN 700 and VLAN 701 |
HSB channel VLAN |
VLAN 810 |
VLAN used for communication with servers |
VLAN 820 |
VRRP group |
|
|
|
DHCP server |
|
IP address pool for APs |
10.128.1.4–10.128.1.254/24 |
IP address pool for STAs |
VLAN 700: 10.129.0.1–10.129.15.254/20 VLAN 701: 10.130.0.1–10.130.15.254/20 |
Authentication, authorization, and accounting (AAA) parameters |
Authentication scheme:
Accounting scheme:
|
RADIUS parameters |
RADIUS server template name: radius_huawei
RADIUS authorization server:
|
Portal server template |
|
URL template |
|
Portal access profile |
|
802.1X access profile |
|
MAC access profile |
|
Authentication-free rule profile |
|
Portal authentication profile |
|
802.1X authentication profile |
|
DNS server |
IP address: 172.16.1.253 |
AP group |
|
SSID profile |
|
Security profile |
|
Traffic profile |
|
VAP profile wlan_net_portal_auth |
|
VAP profile wlan_net_dot1x_auth |
|
2G radio profile |
|
5G radio profile |
|
Agile Controller-Campus |
|