1、网络拓扑
做这个实验有很多前置条件,需要大家先提前准备才能做。
(1)vAC使用R5482(最新的镜像有),was4300.ipe在5群里有,找不到可以问下版主。

(2)这里使用SW02是真机S5320,原因是该型号支持POE供电,如果有AP电源适配器,可以不用这样桥接
(3)本来也打算做一下本地转发的实验,结果发现本地网卡不支持透传带vlan tag的报文,最终以集中转发定稿,如果小伙伴们可以解决这个疑问问题,我可以再出一稿。


2、设备配置
(1)PE01
#
sysname PE01
#
ip unreachables enable
ip ttl-expires enable
#
acl number 2000
rule 0 permit source 192.168.1.0 0.0.0.255
#
interface GigabitEthernet1/0
port link-mode route
ip address 172.16.0.1 255.255.255.252
#
interface GigabitEthernet2/0
port link-mode route
ip address dhcp-alloc
nat outbound 2000
#
ip route-static 192.168.1.0 24 172.16.0.2
(2)AC01
#
sysname AC01
#
wlan global-configuration
region-code CN
y
#
ip unreachables enable
ip ttl-expires enable
#
dhcp enable
#
vlan 10 100
#
dhcp server ip-pool ap
gateway-list 172.16.100.254
network 172.16.100.0 mask 255.255.255.0
forbidden-ip 172.16.100.254
#
dhcp server ip-pool user
gateway-list 192.168.1.254
network 192.168.1.0 mask 255.255.255.0
dns-list 218.85.152.99
forbidden-ip 192.168.1.254
#
radius session-control enable
#
radius scheme h3c
primary authentication 10.1.5.100 key cipher pass@800
primary accounting 10.1.5.100 key cipher pass@800
timer realtime-accounting 1
user-name-format without-domain
nas-ip 172.16.100.254
#
domain h3c
authorization-attribute idle-cut 2 1024
authentication portal radius-scheme h3c
authorization portal radius-scheme h3c
accounting portal radius-scheme h3c
#
portal free-rule 0 destination ip 10.1.5.100 255.255.255.255
portal free-rule 1 destination ip 218.85.152.99 255.255.255.255
#
portal web-server h3c
url http://10.1.5.100:8080/portal
url-parameter ssid ssid
url-parameter wlanacname value AC
url-parameter wlanuserip source-address
#
portal server h3c
ip 10.1.5.100 key cipher pass@800
service-type imc
#
wlan service-template h3c
ssid h3c-wifi
vlan 10
portal enable method direct
portal domain h3c
portal bas-ip 172.16.100.254
portal apply web-server h3c
service-template enable
#
wlan ap ap01 model WA4320-ACN-SI
mac-address 741f-4a36-c540
map-configuration flash:/apcfg.txt
vlan 1
radio 1
radio enable
service-template h3c
radio 2
radio enable
service-template h3c
#
interface Vlan-interface10
ip address 192.168.1.254 255.255.255.0
#
interface Vlan-interface100
ip address 172.16.100.254 255.255.255.0
#
interface GigabitEthernet1/0
port link-mode bridge
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 100
#
interface GigabitEthernet2/0
port link-mode route
ip address 192.168.11.1 255.255.255.0
#
ip route-static 0.0.0.0 0 172.16.100.253
#
local-user admin class manage
password simple h3c@123456
service-type ssh telnet http https
authorization-attribute user-role network-admin
(3)SW01
#
sysname SW01
#
interface Vlan-interface100
description thg
ip address 172.16.100.253 255.255.255.0
#
interface GigabitEthernet1/0
port link-mode route
ip address 172.16.0.2 255.255.255.252
#
interface GigabitEthernet2/0
port link-mode bridge
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 100
#
interface GigabitEthernet3/0
port link-mode route
ip address 10.1.5.254 255.255.255.0
#
interface GigabitEthernet4/0
port link-mode bridge
port link-type trunk
port trunk permit vlan 1 10 100
port trunk pvid vlan 100
#
ip route-static 0.0.0.0 0 172.16.0.1
ip route-static 192.168.1.0 24 172.16.100.254
(4)SW02
#
sysname SW02
#
vlan 4001
#
interface GigabitEthernet0/0/19
port link-type access
port default vlan 4001
stp edged-port enable
#
interface GigabitEthernet0/0/20
port link-type access
port default vlan 4001
stp edged-port enable
3、Agile Controller配置略


=============================================
认证规则

授权结果

授权规则


4、实验结果
(1)AP正常上线。

(2)PC能够获取到正确的地址,且portal端口和DNS能通


(3)可以正常推送portal界面,且认证成功。




5、视频演示一下portal第一次上线后,网卡异常断开,是否可以免认证直接上线。