当前位置:网站首页>Huawei wireless device configuration wpa2-802.1x-aes security policy
Huawei wireless device configuration wpa2-802.1x-aes security policy
2022-07-25 07:19:00 【Tony_ long7483】

To configure LSW and AC, send AP And AC Can transmit between CAPWAP message
[LSW1]vlan batch 100
[LSW1-GigabitEthernet0/0/1]port link-type trunk
[LSW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
[LSW1-GigabitEthernet0/0/2]port link-type trunk
[LSW1-GigabitEthernet0/0/2]port trunk allow-pass vlan 100
[LSW1-GigabitEthernet0/0/2]port trunk pvid vlan 100
[AC1]vlan batch 100
[AC1-GigabitEthernet0/0/1]port link-type trunk
[AC1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100To configure AC Interworking with the upper network equipment
[AC1]vlan batch 101 102 103
[AC1-Vlanif101]ip add 10.1.101.1 24
[AC1-Vlanif102]ip add 10.1.102.1 24
[AC1-Vlanif103]ip add 10.1.103.1 24
[AC1-GigabitEthernet0/0/2]port link-type access
[AC1-GigabitEthernet0/0/2]port default vlan 102
[AC1-GigabitEthernet0/0/3]port link-type trunk
[AC1-GigabitEthernet0/0/3]port trunk allow-pass vlan 103
[AC1-GigabitEthernet0/0/3]port trunk pvid vlan 103
[AC1]ip route-static 0.0.0.0 0.0.0.0 10.1.102.2To configure AC to AP Distribute IP Address ,AR to STA Distribute IP Address
[AC1]dhcp enable
[AC1-Vlanif100]ip add 10.1.100.1 24
[AC1-Vlanif100]dhcp select interface
[AC1-Vlanif101]dhcp select relay
[AC1-Vlanif101]dhcp relay server-ip 10.1.102.2
[AR1]dhcp enable
[AR1-ip-pool-sta]gateway-list 10.1.101.1
[AR1-ip-pool-sta]dns-list 8.8.8.8
[AR1-ip-pool-sta]network 10.1.101.0 mask 24
[AR1-GigabitEthernet0/0/0]ip add 10.1.102.2 24
[AR1-GigabitEthernet0/0/0]dhcp select global
[AR1]ip route-static 10.1.101.0 24 10.23.102.1To configure RADIUS Certification parameters
establish RADIUS Server template
[AC1]radius-server template radius1
[AC1-radius-radius1]radius-server authentication 10.1.103.2 1812
[AC1-radius-radius1]radius-server shared-key cipher [email protected]
establish RADIUS Way of authentication
[AC1]aaa
[AC1-aaa]authentication-scheme radius1
[AC1-aaa-authen-radius1]authentication-mode radius
establish AAA Domain and configure the RADIUS Server template and authentication scheme
[AC1-aaa]domain 123.com
[AC1-aaa-domain-123.com]radius-server radius1
[AC1-aaa-domain-123.com]authentication-scheme radius1To configure 802.1X Access template , management 802.1X Access control parameters
establish 802.1X Access template
[AC1]dot1x-access-profile name wlan-dot1x
The configuration authentication method is EAP Relay mode
[AC1-dot1x-access-profile-wlan-dot1x]dot1x authentication-method eapCreate an authentication template , binding 802.1X Access template , And configure the user mandatory domain
[AC1]authentication-profile name wlan-authentication
[AC1-authentication-profile-wlan-authentication]dot1x-access-profile wlan-dot1x
[AC1-authentication-profile-wlan-authentication]access-domain 123.com dot1x forceTo configure AP go online
establish AP Group
[AC1]wlan
[AC1-wlan-view]ap-group name ap-group1
Create domain management template , Configure... Under the domain management template AC Country code and in AP Reference domain management template under group
[AC1-wlan-view]regulatory-domain-profile name domain1
[AC1-wlan-regulate-domain-domain1]country-code cn
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]regulatory-domain-profile domain1
[AC1]capwap source interface Vlanif 100
stay AC Import online and offline AP, And will AP Join in AP Group
[AC1-wlan-view]ap auth-mode mac-auth
[AC1-wlan-view]ap-id 0 ap-mac 00e0-fc19-7cf0
[AC1-wlan-ap-0]ap-name ap1
[AC1-wlan-ap-0]ap-group ap-group1
To configure WLAN Business parameters
Create a security template , And configure the security policy
[AC1]wlan
[AC1-wlan-view]security-profile name wlan-security
[AC1-wlan-sec-prof-wlan-security]security wpa2 dot1x aes
establish SSID Templates , And configuration SSID name
[AC1-wlan-view]ssid-profile name wlan-ssid
[AC1-wlan-ssid-prof-wlan-ssid]ssid wlan-net
establish VAP Templates , Configure business data forwarding mode 、 Business VLAN, And reference the security template 、 Certification templates and SSID Templates
[AC1-wlan-view]vap-profile name wlan-vap
[AC1-wlan-vap-prof-wlan-vap]forward-mode tunnel
[AC1-wlan-vap-prof-wlan-vap]service-vlan vlan-id 101
[AC1-wlan-vap-prof-wlan-vap]security-profile wlan-security
[AC1-wlan-vap-prof-wlan-vap]authentication-profile wlan-authentication
[AC1-wlan-vap-prof-wlan-vap]ssid-profile wlan-ssid
To configure AP Group reference VAP Templates ,AP RF on 0 And RF 1 All use VAP Template configuration
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]vap-profile wlan-vap wlan 1 radio 0
[AC1-wlan-ap-group-ap-group1]vap-profile wlan-vap wlan 1 radio 1To configure AP RF channel and power
Turn off the RF channel and power auto tuning function
[AC1-wlan-view]rrm-profile name default
[AC1-wlan-rrm-prof-default]calibrate auto-channel-select disable
[AC1-wlan-rrm-prof-default]calibrate auto-txpower-select disable
To configure AP RF channel and power
[AC1-wlan-view]ap-id 0
[AC1-wlan-ap-0]radio 0
[AC1-wlan-radio-0/0]channel 20mhz 6
[AC1-wlan-radio-0/0]eirp 127
[AC1-wlan-ap-0]radio 1
[AC1-wlan-radio-0/1]channel 20mhz 149
[AC1-wlan-radio-0/1]eirp 127
边栏推荐
- Statistical learning -- naive Bayesian method
- 【程序员2公务员】四、常见问题
- Rust standard library - implement a TCP service, and rust uses sockets
- [computer explanation] NVIDIA released geforce RTX Super Series graphics cards, and the benefits of game players are coming!
- New tea, start "fighting in groups"
- Octopus network community call 1 starts Octopus Dao construction
- Ideal L9, can't cross a pit on the road?
- 【电脑讲解】去电脑维修店修电脑需要注意什么?
- RPC communication principle and project technology selection
- 【电脑讲解】NVIDIA发布GeForce RTX SUPER系列显卡,游戏玩家福利来了!
猜你喜欢

BOM overview

QT6 with vs Code: compiling source code and basic configuration

Can interface debugging still play like this?

Hierarchical reinforcement learning: a comprehensive survey

CTF Crypto---RSA KCS1_ Oaep mode

knapsack problem
![[cloud native] the ribbon is no longer used at the bottom of openfeign, which started in 2020.0.x](/img/7e/1d27e3f1856ab8c6cbfc5221c717bb.png)
[cloud native] the ribbon is no longer used at the bottom of openfeign, which started in 2020.0.x

MATLAB自编程系列(1)---角分布函数

【terminal】x86 Native Tools Command Prompt for VS 2017

js无法获取headers中Content-Disposition
随机推荐
Flinkcdc2.0 uses flinksql to collect MySQL
Price reduction, game, bitterness, etc., vc/pe rushed to queue up and quit in 2022
北京内推 | 微软STCA招聘NLP/IR/DL方向研究型实习生(可远程)
Rambus announces ddr5 memory interface chip portfolio for data centers and PCs
When providing digital talent services, Xi Zhi quickly opened its own digital school for each organization
【电脑讲解】去电脑维修店修电脑需要注意什么?
Lidar construction map (overlay grid construction map)
【程序员2公务员】一、基本认知
When importing data in batches, you always prompt "failure reason: SQL parsing failure: parsing file failure:: null". What's the matter?
Traffic is not the most important thing for the metauniverse. Whether it can really change the traditional way of life and production is the most important
A domestic open source redis visualization tool that is super easy to use, with a high-value UI, which is really fragrant!!
Leetcode 115. different subsequences
New tea, start "fighting in groups"
Scavenging vultures or woodpeckers? How to correctly understand short selling
Vscode saves setting configuration parameters to the difference between users and workspaces
Rust标准库-实现一个TCP服务、Rust使用套接字
Yolov7 model reasoning and training its own data set
《游戏机图鉴》:一份献给游戏玩家的回忆录
9 best engineering construction project management systems
diagramscene工程难点分析