Example for Configuring Inter-AC Layer 3 Roaming
Service Requirements
Enterprise users can access the network through WLANs, which is the basic requirement of mobile office. To differentiate department management, employees are assigned different subnets by department. Furthermore, users' services are not affected during roaming in the coverage area.
Networking Requirement
- AC networking mode: AC_1 and AC_2 in a mobility group
- DHCP deployment mode:
AC_1 functions as a DHCP server to assign IP addresses to APs and STAs connected to it.
AC_2 functions as a DHCP server to assign IP addresses to APs and STAs connected to it.
- Service data forwarding mode: direct forwarding
Data Planning
Item |
Data |
---|---|
DHCP server |
AC_1 functions as a DHCP server to assign IP addresses to STAs and APs connected to it. AC_2 functions as a DHCP server to assign IP addresses to STAs and APs connected to it. |
IP address pool for APs |
10.23.100.2-10.23.100.254/24 10.23.200.2-10.23.200.254/24 |
IP address pool for STAs |
10.23.101.2-10.23.101.254/24 10.23.102.2-10.23.102.254/24 |
AC_1's source interface address |
VLANIF 100: 10.23.100.1/24 |
AC_2's source interface address |
VLANIF 200: 10.23.200.1/24 |
AP group |
AC_1:
|
AC_2:
|
|
Regulatory domain profile |
|
SSID profile |
|
Security profile |
|
VAP profile |
AC_1:
|
AC_2:
|
|
Air scan profile |
|
RRM profile |
|
2G radio profile |
|
5G radio profile |
|
Mobility group |
|
Configuration Roadmap
- Configure network interworking of the AC, APs, and other network devices.
- Select Config Wizard to configure system parameters for the AC.
- Select Config Wizard to configure the APs to go online on the AC.
- Select Config Wizard to configure WLAN services on the AC.
- Deliver the WLAN services to the APs and verify the configuration.
- Configure WLAN roaming on AC_1 and AC_2 to implement inter-AC roaming.
During AP deployment, you can manually specify the working channels of the APs according to network planning or configure the radio calibration function to enable the APs to automatically select the optimal channels.
Configuration Notes
- No ACK mechanism is provided for multicast packet transmission on air interfaces. In addition, wireless links are unstable. To ensure stable transmission of multicast packets, they are usually sent at low rates. If a large number of such multicast packets are sent from the network side, the air interfaces may be congested. You are advised to configure multicast packet suppression to reduce impact of a large number of low-rate multicast packets on the wireless network. Exercise caution when configuring the rate limit; otherwise, the multicast services may be affected.
- In direct forwarding mode, you are advised to configure multicast packet suppression on switch interfaces connected to APs.
- In tunnel forwarding mode, you are advised to configure multicast packet suppression in traffic profiles of the AC.
Configure port isolation on the interfaces of the device directly connected to APs. If port isolation is not configured and direct forwarding is used, a large number of unnecessary broadcast packets may be generated in the VLAN, blocking the network and degrading user experience.
In tunnel forwarding mode, the management VLAN and service VLAN cannot be the same. Only packets from the management VLAN are transmitted between the AC and APs. Packets from the service VLAN are not allowed between the AC and APs.
Procedure
- Configure the network devices.# Add GE0/0/1 and GE0/0/2 on Switch_1 to VLAN 100 and VLAN 101. The default VLAN of GE0/0/1 is VLAN 100.
<HUAWEI> system-view [HUAWEI] sysname Switch_1 [Switch_1] vlan batch 100 101 [Switch_1] interface GigabitEthernet 0/0/1 [Switch_1-GigabitEthernet0/0/1] port link-type trunk [Switch_1-GigabitEthernet0/0/1] port trunk pvid vlan 100 [Switch_1-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 101 [Switch_1-GigabitEthernet0/0/1] quit [Switch_1] interface gigabitethernet 0/0/2 [Switch_1-GigabitEthernet0/0/2] port link-type trunk [Switch_1-GigabitEthernet0/0/2] port trunk allow-pass vlan 100 101 [Switch_1-GigabitEthernet0/0/2] quit
# Add GE0/0/1 and GE0/0/2 on Switch_2 to VLAN 200 and VLAN 102. The default VLAN of GE0/0/1 is VLAN 200.<HUAWEI> system-view [HUAWEI] sysname Switch_2 [Switch_2] vlan batch 200 102 [Switch_2] interface gigabitethernet 0/0/1 [Switch_2-GigabitEthernet0/0/1] port link-type trunk [Switch_2-GigabitEthernet0/0/1] port trunk pvid vlan 200 [Switch_2-GigabitEthernet0/0/1] port trunk allow-pass vlan 200 102 [Switch_2-GigabitEthernet0/0/1] quit [Switch_2] interface gigabitethernet 0/0/2 [Switch_2-GigabitEthernet0/0/2] port link-type trunk [Switch_2-GigabitEthernet0/0/2] port trunk allow-pass vlan 200 102 [Switch_2-GigabitEthernet0/0/2] quit
# Configure Router.<HUAWEI> system-view [HUAWEI] sysname Router [Router] interface gigabitethernet 0/0/1 [Router-GigabitEthernet0/0/1] ip address 10.23.100.2 255.255.255.0 [Router-GigabitEthernet0/0/1] quit [Router] interface gigabitethernet 0/0/2 [Router-GigabitEthernet0/0/2] ip address 10.23.200.2 255.255.255.0 [Router-GigabitEthernet0/0/2] quit
- Configure system parameters for AC_1.
- Configure system parameters for AC_2.Configure AC_2 according to the configuration of AC_1. The following lists configuration differences between AC_1 and AC_2.
- Create VLAN 200 and VLAN 102 on AC_2 and add GigabitEthernet0/0/1 to the two VLANs in tagged mode.
- Add GigabitEthernet0/0/2 to VLAN 200 in tagged mode.
- Set the IP addresses of VLANIF 200 and VLANIF 102 to 10.23.200.1/24 and 10.23.102.1/24 respectively.
- Configure an IP address pool on VLANIF 200 and VLANIF 102.
- Configure the route between AC_2 and AC_1 on AC_2 with the destination address 10.23.100.0/24 and next-hop address 10.23.200.2.
- Configure an AP to go online on AC_1.
- Configure an AP to go online on AC_2.
Configure the AP to go online on AC_2 according to the configuration of AC_1. The following lists configuration differences between AC_1 and AC_2:
Add an AP (MAC address dcd2-fc04-b500 and SN 210235554710CB000078) on AC_2, set the AP name to area_2, and add the AP to the AP group ap-group2.
- Configure WLAN services on AC_1.
# Click Create. The Basic Information page is displayed.
# Set SSID Name to wlan-net, Forwarding mode to Direct, Service VLAN to Single VLAN, and Service VLAN ID to 101.
Click Next. The Security Authentication page is displayed.
# Set Security settings to Key (applicable to personnel networks) and set the key.
# Click Next. The Access Control page is displayed.
# Set Binding the AP group to ap-group1.
Click Finish.
- Configure WLAN services on AC_2.
Configure WLAN services on AC_2 according to the configuration of AC_1. The following lists the configuration difference between AC_1 and AC_2:
In the VAP profile wlan-net, set the service VLAN to VLAN 102.
- Enable radio calibration to allow APs to automatically select the optimal channels and power.
- Configure WLAN roaming on AC_1.
- Configure WLAN roaming on AC_2.
The configuration is similar to that of AC_1 and is not mentioned here.
- Verify the configuration.