第一篇:65-无线控制器VRRP热备管理AP典型配置举例
无线控制器VRRP热备管理AP典型配置举例
Copyright © 2014杭州华三通信技术有限公司 版权所有,保留一切权利。
非经本公司书面许可,任何单位和个人不得擅自摘抄、复制本文档内容的部分或全部,并不得以任何形式传播。本文档中的信息可能变动,恕不另行通知。
目 录 简介 ······························································································································ 1 2 配置前提 ························································································································ 1 3 配置举例 ························································································································ 1
3.1 组网需求 ····················································································································· 1 3.2 配置思路 ····················································································································· 2 3.3 配置注意事项 ··············································································································· 2 3.4 配置步骤 ····················································································································· 2
3.4.1 AC 1的配置 ········································································································ 2 3.4.2 AC 2的配置 ········································································································ 4 3.4.3 Switch的配置 ······································································································ 6 3.5 验证配置 ····················································································································· 7 3.6 配置文件 ····················································································································· 8 相关资料 ······················································································································ 10
i 简介
本文档介绍了无线控制器VRRP热备管理AP典型配置举例。配置前提
本文档不严格与具体软、硬件版本对应,如果使用过程中与产品实际情况有差异,请参考相关产品手册,或以设备实际情况为准。
本文档中的配置均是在实验室环境下进行的配置和验证,配置前设备的所有参数均采用出厂时的缺省配置。如果您已经对设备进行了配置,为了保证配置效果,请确认现有配置和以下举例中的配置不冲突。
本文档假设您已了解WLAN接入、VRRP热备等特性。配置举例
3.1 组网需求
如图1所示,为了提高网络中AC的可靠性,现要求使用VRRP热备功能,将AC 1和AC 2组成一台虚拟AC,为Client提供无线接入服务。具体要求如下:
AC 1正常工作的情况下,Client通过AC 1访问网络。
当AC 1发生故障时,Client切换至AC 2上,保证业务流量在切换过程中不会中断。
图1 VRRP热备管理AP典型组网图
Vlan-int100:126.100.1.1/24Vlan-int200:126.200.1.1/24Vlan-int100:126.100.1.2/24Vlan-int200:126.200.1.2/24IACTP tunnelAC 1MasterVirtual IP address126.100.1.253/24BackupAC 2SwitchDHCP serverAPClient
3.2 配置思路
为了让AC 1成为VRRP备份组中的Master,需要为AC 1配置较高的优先级。为了避免VRRP备份组中的角色频繁发生变化,可以配置一定的抢占延迟时间。
当备份组中的角色发生变化时,为了保证网络流量不会中断,需要在AC 1和AC 2之间建立IACTP隧道,并通过AP信息备份以及Client备份功能,使AC之间可以同步备份AP和Client的信息。
3.3 配置注意事项
两台AC需保证WLAN相关的特性配置一致,否则可能出现备份失败等问题。
配置AP的序列号时请确保该序列号与AP唯一对应,AP的序列号可以通过AP设备背面的标签获取。
需要确保在完成VRRP配置、IACTP隧道、开启客户端信息备份功能后,再开启AP信息备份功能。
需要在配置IACTP隧道的源IP地址后才可以开启隧道。
3.4 配置步骤
3.4.1 AC 1的配置
(1)配置AC 1的接口
# 创建VLAN 100及其对应的VLAN接口,并为该接口配置IP地址。AC 1将使用该接口的IP地址与AP建立LWAPP隧道,同时用于与AC 2建立VRRP备份组和IACTP隧道。
[AC1] vlan 200 [AC1-vlan200] quit [AC1] interface vlan-interface 200 [AC1-Vlan-interface200] ip address 126.200.1.1 24 [AC1-Vlan-interface200] quit # 配置AC 1与Switch相连的GigabitEthernet1/0/1接口链路类型为Trunk,PVID为100,允许VLAN 100和VLAN 200的报文通过。
[AC1] interface gigabitethernet 1/0/1 [AC1-GigabitEthernet1/0/1] port link-type trunk [AC1-GigabitEthernet1/0/1] port trunk permit vlan 100 200 [AC1-GigabitEthernet1/0/1] port trunk pvid vlan 100
[AC1-GigabitEthernet1/0/1] quit # 创建WLAN-ESS 1接口
[AC1] interface wlan-ess 1 # 配置WLAN-ESS 1接口链路类型为Hybrid。
[AC1-WLAN-ESS1] port link-type hybrid # 配置当前Hybrid端口的PVID为VLAN 200,允许VLAN 200不带tag通过。
[AC1-WLAN-ESS1] port hybrid vlan 200 untagged [AC1-WLAN-ESS1] port hybrid pvid vlan 200 # 在Hybrid端口上使能MAC VLAN功能。
[AC1-WLAN-ESS1] mac-vlan enable [AC1-WLAN-ESS1] quit(2)配置VRRP功能
# 创建VRRP备份组1,并配置备份组1的虚拟IP地址为126.100.1.253。
[AC1] interface vlan-interface 100 [AC1-Vlan-interface100] vrrp vrid 1 virtual-ip 126.100.1.253 # 设置AC 1在备份组1中的优先级为110。
[AC1-Vlan-interface100] vrrp vrid 1 priority 110 # 设置AC 1工作在抢占模式,抢占延迟时间为6秒。
[AC1-Vlan-interface100] vrrp vrid 1 preempt-mode timer delay 6 [AC1-Vlan-interface100] quit(3)配置IACTP隧道
# 创建IACTP隧道1,并进入其视图。
[AC1] wlan mobility-group 1 # 配置IACTP隧道1的源IP地址为AC 1的IP地址126.100.1.1。
[AC1-wlan-mg-1] source ip 126.100.1.1 # 配置IACTP隧道1的成员IP地址为AC 2的IP地址126.100.1.2。
[AC1-wlan-mg-1] member ip 126.100.1.2 # 开启IACTP隧道。
[AC1-wlan-mg-1] mobility-group enable [AC1-wlan-mg-1] quit # 开启客户端信息备份功能。
[AC1] wlan backup-client enable # 开启AP信息备份功能。
[AC1] wlan backup-ap enable(4)配置无线服务
# 创建clear类型的服务模板1。
[AC1] wlan service-template 1 clear # 设置当前服务模板的SSID为service。
[AC1-wlan-st-1] ssid service # 将WLAN-ESS 1接口绑定到服务模板1。
[AC1-wlan-st-1] bind wlan-ess 1
# 启用无线服务。
[AC1-wlan-st-1] service-template enable [AC1-wlan-st-1] quit(5)配置AP # 创建AP的管理模板,名称为testap,型号名称选择WA2620E-AGN。
[AC1] wlan ap testap model WA2620E-AGN # 设置AP的序列号为21023529G007C000020。
[AC1-wlan-ap-testap] serial-id 21023529G007C000020 # 进入radio 2射频视图。
[AC1-wlan-ap-testap] radio 2 # 将在AC上配置clear类型的服务模板1与射频2进行关联。
[AC1-wlan-ap-testap-radio-2] service-template 1 # 使能AP的radio 2。
[AC1-wlan-ap-testap-radio-2] radio enable [AC1-wlan-ap-testap-radio-2] return 3.4.2 AC 2的配置
(1)配置AC 2的接口
# 创建VLAN 100及其对应的VLAN接口,并为该接口配置IP地址。AC 2将使用该接口的IP地址与AP建立LWAPP隧道,同时用于与AC 1建立VRRP备份组和IACTP隧道。
[AC2] vlan 200 [AC2-vlan200] quit [AC2] interface vlan-interface 200 [AC2-Vlan-interface200] ip address 126.200.1.2 24 [AC2-Vlan-interface200] quit # 配置AC 2与Switch相连的GigabitEthernet1/0/1接口链路类型为Trunk,PVID为100,允许VLAN 100和VLAN 200的报文通过。
[AC2] interface gigabitethernet 1/0/1 [AC2-GigabitEthernet1/0/1] port link-type trunk [AC2-GigabitEthernet1/0/1] port trunk permit vlan 100 200 [AC2-GigabitEthernet1/0/1] port trunk pvid vlan 100 [AC2-GigabitEthernet1/0/1] quit # 创建WLAN-ESS 1接口
[AC2] interface wlan-ess 1
# 配置WLAN-ESS 1接口链路类型为Hybrid。
[AC2-WLAN-ESS1] port link-type hybrid # 配置当前Hybrid端口的PVID为VLAN 200,允许VLAN 200不带tag通过。
[AC2-WLAN-ESS1] port hybrid vlan 200 untagged [AC2-WLAN-ESS1] port hybrid pvid vlan 200 # 在Hybrid端口上使能MAC VLAN功能。
[AC2-WLAN-ESS1] mac-vlan enable [AC2-WLAN-ESS1] quit(2)配置VRRP # 创建VRRP备份组1,并配置备份组1的虚拟IP地址为126.100.1.253,AC 2在备份组1中的优先级取缺省值100。
[AC2] interface vlan-interface 100 [AC2-Vlan-interface100] vrrp vrid 1 virtual-ip 126.100.1.253 # 设置AC 2工作在抢占方式,抢占延迟时间为6秒。
[AC2-Vlan-interface100] vrrp vrid 1 preempt-mode timer delay 6 [AC2-Vlan-interface100] quit(3)配置IACTP隧道
# 创建IACTP隧道1,并进入其视图。
[AC2] wlan mobility-group 1 # 配置IACTP隧道1的源IP地址为AC 2的IP地址126.100.1.2。
[AC2-wlan-mg-1] source ip 126.100.1.2 # 配置配置IACTP隧道1的成员IP地址为AC 1的IP地址126.100.1.1。
[AC2-wlan-mg-1] member ip 126.100.1.1 # 开启IACTP隧道。
[AC2-wlan-mg-1] mobility-group enable [AC2-wlan-mg-1] quit # 开启客户端信息备份功能。
[AC2] wlan backup-client enable # 开启AP信息备份功能。
[AC2] wlan backup-ap enable(4)配置无线服务
# 创建clear类型的服务模板1。
[AC2] wlan service-template 1 clear # 设置当前服务模板的SSID为service。
[AC2-wlan-st-1] ssid service # 将WLAN-ESS 1接口绑定到服务模板1。
[AC2-wlan-st-1] bind wlan-ess 1 # 启用无线服务。
[AC2-wlan-st-1] service-template enable [AC2-wlan-st-1] quit(5)配置AP
# 创建AP的管理模板,名称为testap,型号名称选择WA2620E-AGN。
[AC2] wlan ap testap model WA2620E-AGN # 设置AP的序列号为21023529G007C000020。
[AC2-wlan-ap-testap] serial-id 21023529G007C000020 # 进入radio 2射频视图。
[AC2-wlan-ap-testap] radio 2 # 将在AC上配置clear类型的服务模板1与射频2进行关联。
[AC2-wlan-ap-testap-radio-2] service-template 1 # 使能AP的radio 2。
[AC2-wlan-ap-testap-radio-2] radio enable [AC2-wlan-ap-testap-radio-2] return 3.4.3 Switch的配置
# 创建VLAN 100和VLAN 200,其中VLAN 100用于转发AC和AP间LWAPP隧道内的流量,VLAN 200为无线客户端接入的VLAN。
[Switch] interface gigabitethernet 1/0/1 [Switch-GigabitEthernet1/0/1] port link-type trunk [Switch-GigabitEthernet1/0/1] port trunk permit vlan 100 [Switch-GigabitEthernet1/0/1] port trunk pvid vlan 100 [Switch-GigabitEthernet1/0/1] quit # 配置Switch与AC 2相连的GigabitEthernet1/0/2接口属性Trunk,PVID为100,允许VLAN 100通过。
[Switch] interface gigabitethernet 1/0/2 [Switch-GigabitEthernet1/0/2] port link-type trunk [Switch-GigabitEthernet1/0/2] port trunk permit vlan 100 [Switch-GigabitEthernet1/0/2] port trunk pvid vlan 100 [Switch-GigabitEthernet1/0/2] quit # 配置Switch与DHCP server相连的GigabitEthernet1/0/3接口属性为Access,并允许VLAN 100通过。
[Switch] interface gigabitethernet 1/0/3 [Switch-GigabitEthernet1/0/3] port link-type access [Switch-GigabitEthernet1/0/3] port access vlan 100 [Switch-GigabitEthernet1/0/3] quit # 配置Switch与AP相连的GigabitEthernet1/0/4接口属性为Access,并允许VLAN 100通过,并使能PoE功能。
[Switch] interface gigabitethernet 1/0/4
[Switch-GigabitEthernet1/0/4] port link-type access [Switch-GigabitEthernet1/0/4] port access vlan 100 [Switch-GigabitEthernet1/0/4] poe enable [Switch-GigabitEthernet1/0/4] quit 3.5 验证配置
(1)当MAC地址为001f-3b03-781f的Client通过SSID为service的无线服务上线时,在AC 1上通过display wlan ap all命令可以查看AP和Client的信息。
# wlan backup-ap enable # wlan backup-client enable # vlan 100 # vlan 200 # wlan service-template 1 clear ssid service bind WLAN-ESS 1 service-template enable # interface Vlan-interface100 ip address 126.100.1.1 255.255.255.0 vrrp vrid 1 virtual-ip 126.100.1.253 vrrp vrid 1 priority 110 vrrp vrid 1 preempt-mode timer delay 6 # interface Vlan-interface200 ip address 126.200.1.1 255.255.255.0 # interface GigabitEthernet1/0/1 port link-type trunk port trunk permit vlan 100 200 port trunk pvid vlan 100 # interface WLAN-ESS1 port link-type hybrid port hybrid vlan 1 200 untagged port hybrid pvid vlan 200 mac-vlan enable # wlan ap testap model WA2620E-AGN id 1 AC 1:
serial-id 21023529G007C000020 radio 1 radio 2 service-template 1 radio enable # wlan mobility-group 1 member ip 126.100.1.2 source ip 126.100.1.1 mobility-group enable #
# AC 2:
wlan backup-ap enable # wlan backup-client enable # vlan 100 # vlan 200 # wlan service-template 1 clear ssid service bind WLAN-ESS 1 service-template enable # interface Vlan-interface100 ip address 126.100.1.2 255.255.255.0 vrrp vrid 1 virtual-ip 126.100.1.253 vrrp vrid 1 preempt-mode timer delay 6 # interface Vlan-interface200 ip address 126.200.1.2 255.255.255.0 # interface GigabitEthernet1/0/1 port link-type trunk port trunk permit vlan 100 200 port trunk pvid vlan 100 # interface WLAN-ESS1 port link-type hybrid port hybrid vlan 1 200 untagged port hybrid pvid vlan 200 mac-vlan enable # wlan ap testap model WA2620E-AGN id 1 serial-id 21023529G007C000020 radio 1
radio 2 service-template 1 radio enable # wlan mobility-group 1 member ip 126.100.1.1 source ip 126.100.1.2 mobility-group enable #
# Switch:
vlan 100 # vlan 200 # interface GigabitEthernet1/0/1 port link-type trunk port trunk permit vlan 100 port trunk pvid vlan 100 # interface GigabitEthernet1/0/2 port link-type trunk port trunk permit vlan 100 port trunk pvid vlan 100 # interface GigabitEthernet1/0/3 port link-type access port access vlan 100 # interface GigabitEthernet1/0/4 port link-type access port access vlan 100 poe enable # 4 相关资料
《H3C WX系列无线控制器产品配置指导》“WLAN配置指导”。《H3C WX系列无线控制器产品命令参考》“WLAN命令参考”。《H3C WX系列无线控制器产品配置指导》“可靠性配置指导”。《H3C WX系列无线控制器产品配置指导》“可靠性命令参考”。