题目: 三层无线组网实例

摘要

构建如图1-1所示的三层无线局域网,要求分离AC管理VLAN、AP管理VLAN和业务VLAN。要求实现802.1x认证,所有接人网络的用户账号和密码存放在Radius服务器上。由于eNSP中没有内置的AAA服务器,本实例中采用eNSP提供的Cloud云设备连接本地计算机,在本地计算机上安装一个WinRadius服务器,实现无线网络接人认证。

三层网络架构ip设置方法 三层网络搭建_网络协议


图1-1

三、实验内容

1.构建WinRadius服务器

配置本地计算机的Loopback网卡及IP地址;

配置WinRadius服务器的共享密钥,认证端口和计费端口;

配置测试用户账户和密码;

配置Cloud,实现eNSP连接WinRadius 服务器;

2.AC VLAN配置

配置AC地址源VLAN数据库;

配置AC地址源VLAN接口地址;

配置业务VLAN

3.三层交换机VLAN配置

配置连接AC地址源VLAN数据库;

配置连接AC地址源VLAN接口地址;

配置AP管理VLAN数据库;

配置AP管理VLAN接口地址;

置配置AP管理VLAN地址池;

配置AP管理VLAN地址池的option43选项

配置业务VLAN数据库;

配置业务VLAN接口地址;

配置业务VLAN地址池

4.路由配置

配置AC路由协议;

配置 三层交换机路由协议

5.AP上线配置

配置 AC地址源;

定义 AP组名称为default;

配置 sn-auth 认证上线模式;

配置API名称设置为hist00l;

配置AP2名称设置为hist002;

配置API和AP2加入AP组

6.管理域模板

配置管理域模板名称为default;

配置国家码为CN

7.Radius认证模板

配置Radius服务器模板名为default;

配置Radius服务器共享密钥;

配置Radius服务器认证端口;

配置Radius服务器计费端口;

配置Radius服务器用户名不包含域名

8.AAA认证和计费方案

配置AAA认证方案名称为default;

配置AAA认证模式为Radius;

配置AAA授权方案名称为default;

配置AAA计费模式为Radius;

配置Radius计费方案名称为default;

配置认证域为hist;

引用default认证方案;

引用default计费方案;

引用Radius服务器模板名default;

申明hist为默认主域

9. 802.1X接入模板

定义802.1x接人模板名为default

10.认证模板

配置认证模板名为default;

引用dotlx接人模板;

引用计费模板;

引用授权模板;

引用Radius服务器模板

11.射频模板

配置2.4G网络射频模板名称default;

配置2.4G网络射频类型为802.11n;

配置5G网络射频模板名称default;

配置5G网络射频类型为802.11ac;

12.SSID模板

配置2.4G网络的SSID模板为hist24g;

配置5G网络的SSID模板为hist5g;

配置所有SSID模板名和SSID名相同;

配置2.4G网络的最大接人用户数为32;

配置2.4G网络达到最大接人用户数后,隐藏SSID;

配置5G网络的最大接入用户数为16;

配置5G网络达到最大接人用户数后,隐藏SSID;

13.安全模板

定义网络安全模板为default;

配置WPA2加密和Dotlx认证,加密标准为AES

14.流量模板

定义流量模板为default

15.VAP模板配置

定义两个VAP模板,名称为hist24g和hist5g;

分别引用default流量模板;

分别引用对应SSID模板;

分别引用安全模板;

分别引用流量模板;

设置数据转发方式为直发;

设置服务VLAN为VLAN 1

16.下发VAP配置

配置Radio 0、Radio 1的射频参数:

引用管理域模板;

引用射频模板;

下发VAP配置

四、实验设备

1.eNSP提供Cloud云设备

2.AAA认证服务器WinRadius

3.AC:AC6605 AP:AP4050 交换机S5700

五、实验过程

一.构建Radius认证服务器

Roiun服务原用来提供先无线接人用户的认证过程:由于在eNSP中发有供Radius务器设备,为此在本地计算机上安装Radius服务器,通过eNSP提供的Cloud提供的Radus服务器实现认证过程。本例使用WinRadis服务器作为认证服务器。构建Radius服务器的基本过程如下。

1.安装环路自测网卡

eNSP通过Cloud连接本地网卡,考虑到不影响实际网络使用,先在本地计算机上安装一块虚拟网卡。

(1)打开“运行”输人hdwwiz命令,弹出“添加硬件”窗口,单击“下一步”按钮,在弹出的窗口中选择“安装我手动从列表选择的硬件(高级)”选项,如图4-1所示。

(2)单击“下一步”按钮,在弹出的选择硬件类型窗口中选择“网络适配器”选项,如图4-2所示。

(3)单击“下一步"按钮,在弹出的窗口左边厂商处选择Microsoft,在右边型号处选择"Microsoft KM-TEST环回适配器”,操作如图4-3所示。

三层网络架构ip设置方法 三层网络搭建_三层网络架构ip设置方法_02


4-1

三层网络架构ip设置方法 三层网络搭建_三层网络架构ip设置方法_03

4-2

三层网络架构ip设置方法 三层网络搭建_无线网_04

4-3

(4) 单击“下一步”按钮,弹出确认安装窗口,确认无误后,继续单击“下一步”按钮,系比开始安装该环路测试网卡,完成后弹出如图4-4所示的“正在完成添加硬件向导”窗口小击“完成”按钮,成功安装该虚拟网卡。

三层网络架构ip设置方法 三层网络搭建_无线网_05

4-4
2.配置虚拟网卡地址
(1)在“运行“中输人ncpa.cpl命令,弹出如图4-5所示的“网络连接”窗口,可以看到信虚拟网卡已经正常安装,即图4-5中的“以太网3”适配器.

三层网络架构ip设置方法 三层网络搭建_网络协议_06

4-5

(2) 右击“以太网3”适配器,在弹出的菜单中选择“属性"命令,弹出如图4-5所示的适配器属性窗口。

(3)双击图4-6上的“Internet协议版本4(TCP/IPv4)”选项,弹出如图4-7所示的设其印地址窗口,输人IP地址为192.168.40.254,子网掩码为255.255.255.0,完成后依次单封确定”按钮退出该配置窗口。

三层网络架构ip设置方法 三层网络搭建_数据库_07


4-6

三层网络架构ip设置方法 三层网络搭建_三层网络架构ip设置方法_08


4-73.安装配置WinRadius服务器

WinRadius 是基于标准Radius协议的认证、记账、计费软件,支持PPP PPPVPN.VoIP、WLAN多种业务模式。

(1)安装该软件后,打开主界面,选择“操作”“添加账号”命令,在弹出的窗口中添加认证账号和密码等项目,完成后单击“确定”按钮,如图4-8所示。

三层网络架构ip设置方法 三层网络搭建_三层网络架构ip设置方法_09


4-8

(2)选择“设置”“系统”命令,弹出“系统设置”窗口,在该窗口中设置NAS密钥、认证端口和计费端口,操作如图4-9所示。

三层网络架构ip设置方法 三层网络搭建_三层网络架构ip设置方法_10


4-9

WinRadius服务器是非常便捷的Radius服务器产品,其他参数选项采用默认设置即可,完成上述操作后,将该软件窗口最小化,该软件将为后期无线接人提供认证用户功能。

4.加载WinRadius服务器

WinRadius服务器配置后通过在本地计算机上安装的环路自测网卡来连接eNSP的Cloud设备。这样,WinRadius就可以为构建的无线仿真实验提供认证功能。

(1)在eNSP的Cloud设备上右击,选择“设置”命令,弹出如图4-10所示的Cloud配置窗口,在“绑定信息”下拉框中依次选择UDP和“以太网3-IP:192.168.40.254”,然后在“常口映射设置"将本地环路自测端口(即2号端口)设置为人端口,将UDP端口设置为出端口。

三层网络架构ip设置方法 三层网络搭建_网络安全_11


4-10

(2)完成绑定后,可以在eNSP上添加一台计算机,配置的IP地址在192. 168.40.0网段,该计算机连接Cloud设备,通过ping 命令可以测试绑定是否成功。如图4-11所示,是构建的测试拓扑。设置的测试PC地址为192.168.40.250。

三层网络架构ip设置方法 三层网络搭建_网络协议_12


4-11

(3) 在该计算机上采用ping命令测试WinRadius服务器,可以看到能正常连接,如图4-12所示。

三层网络架构ip设置方法 三层网络搭建_网络协议_13


4-12

(4)由于绑定的Cloud是双向的,也可以在本地主机上采用ping命令连接eNSP上建立的虚拟设备,如图4-13是本地计算机测试192.168.40.250这台虚拟机的显示,可以看到也能实现正常通信。

三层网络架构ip设置方法 三层网络搭建_三层网络架构ip设置方法_14


4-13

eNSP的Cloud设备可以提供通过本地计算机访问eNSP虚拟设备的重要途径。华为的eNSP设备下加载的是真实的华为系统平台防火墙等很多设备都提供了浏览器接人访问配置,采用Cloud绑定可以方便地在本地计算机上实现基于Web的系统配置。到此,WinRadius服务器的构建完成。

另外,需要注意的是,其他的Radius服务器也可以采用Cloud进行绑定使用,由于WinRadius安装配置简单,因此本例采用该服务器。实际上,可以在本地安装虚拟机(如VMware或Virtual Box),在虚拟机上安装例如Cisco ACS或者Windows Server 2012等服务器软件实现AAA服务器功能。

5.6.3三层网络配置

构建认证服务器和整个网络拓扑后,通过配置AC和三层交换机来实现三层无线网络功能。

1.交换机的网络配置

交换机的主要配置包括设置对应VLAN数据库,将对应接口设置为Trunk模式,配置数据库对应接口,基于对应接口构建DHCP地址池和配置路由协议等步骤。交换机的配置过程详细代码见附录1.

2. AC的网络配置

AC的网络配置相对较少,主要包括配置连接三层交换机的AC VLAN数据库、业务数据库,配置AC地址源(AC VLAN数据库接口)以及配置路由协议等步骤。AC的配置过程见附录2.

3. 三层无线配置

网络配置完成后,测试AP、AC以及三层交换机的连通性。如果通信正常则直接在AC上配置无线参数即可,交换机上不再需要执行任何配置。其主要配置见附录3.

六、实验结果

三层无线配置测试

完成上面的配置后,整个三层无线就可以启动运行,如图4-14所示是显示运行后的结果。

双击无线客户端,在弹出的窗口中选择对应无线进行连接,此时就会弹出用户认证窗口,输人在WinRadius上添加的对应用户账户和密码,就能实现连接,如果用户或者密码错误就不能连接到该无线网络,可以看到这种认证方式非常灵活。

连接成功后,打开无线终端的“命令行”窗口.输入ipconfig 命令查看给无线客户端分配的IP地址,可以看到已经成功分配了业务VLAN段的IP地址。

接着可以进行信道调整等操作。到此,三层无线的配置基本完成。

三层网络架构ip设置方法 三层网络搭建_数据库_15


4-14

七、实验心得
通过本次实验,了解了无线网络技术,熟悉了eNSP的基本知识。知道了一些基础实验的实现方法。熟悉对组网典型应用的编程和相关的设置。能够正确做出三层无线组网配置。我对无线网络技术有了更深层次的了解,对三层无线的组网也有了进一步的认识,与此同时通过该次实验还培养了我理论联系实际的能力,提高了我分析问题和解决问题的能力,增强了独立工作的能力。培养了我与其他同学的团队合作、共同探讨、共同前进的精神。

附录
1.交换机的网络配置

The device is running!
 sys
 Enter system view, return user view with Ctrl+Z.
 [Huawei]dhcp enable
 Info: The operation may take a few seconds. Please wait for a moment.done.
 [Huawei]
 Nov 22 2020 11:50:55-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 4, th
 e change loop count is 0, and the maximum number of records is 4095.
 [Huawei]vl 
 [Huawei]vlan ba 
 [Huawei]vlan batch 10 20 30 40
 Info: This operation may take a few seconds. Please wait for a moment…done.
 [Huawei]
 Nov 22 2020 11:51:15-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 5, th
 e change loop count is 0, and the maximum number of records is 4095.
 [Huawei]int 
 [Huawei]interface v 
 [Huawei]interface Vlanif 10
 [Huawei-Vlanif10]ip add 
 [Huawei-Vlanif10]ip address 192.168.10.253 24
 [Huawei-Vlanif10]
 Nov 22 2020 11:52:35-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 6, th
 e change loop count is 0, and the maximum number of records is 4095.
 [Huawei-Vlanif10]q
 [Huawei]
 [Huawei]interface Vlanif 40
 [Huawei-Vlanif40]ip address 192.168.40.253 24
 [Huawei-Vlanif40]
 Nov 22 2020 11:53:05-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 7, th
 e change loop count is 0, and the maximum number of records is 4095.
 [Huawei-Vlanif40]q
 [Huawei]interface Vlanif 20
 [Huawei-Vlanif20]ip address 192.168.20.254 24
 [Huawei-Vlanif20]
 Nov 22 2020 11:53:55-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 8, th
 e change loop count is 0, and the maximum number of records is 4095.
 [Huawei-Vlanif20]dh 
 [Huawei-Vlanif20]dhcp se 
 [Huawei-Vlanif20]dhcp select int 
 [Huawei-Vlanif20]dhcp select interface
 [Huawei-Vlanif20]
 Nov 22 2020 11:54:05-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 9, th
 e change loop count is 0, and the maximum number of records is 4095.
 [Huawei-Vlanif20]dhcp server option 43 sub-option 3 ascii 192.168.10.254
 [Huawei-Vlanif20]
 Nov 22 2020 11:54:45-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 10, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-Vlanif20]q
 [Huawei]vl 
 [Huawei]interface Vlanif 30
 [Huawei-Vlanif30]ip address 192.168.30.254 24
 [Huawei-Vlanif30]
 Nov 22 2020 11:55:15-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 11, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-Vlanif30]dhcp select interface
 [Huawei-Vlanif30]
 Nov 22 2020 11:55:25-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 12, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-Vlanif30]dh 
 [Huawei-Vlanif30]dhcp server dns-list 114.114.114.114
 [Huawei-Vlanif30]
 Nov 22 2020 11:55:55-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 13, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-Vlanif30]q
 [Huawei]interface GigabitEthernet 0/0/1
 [Huawei-GigabitEthernet0/0/1]port link-type trunk
 [Huawei-GigabitEthernet0/0/1]
 Nov 22 2020 11:56:25-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 14, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/1]port trunk pvid vlan 10
 [Huawei-GigabitEthernet0/0/1]
 Nov 22 2020 11:56:55-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 15, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan all
 [Huawei-GigabitEthernet0/0/1]
 Nov 22 2020 11:57:13-08:00 Huawei %%01IFNET/4/IF_STATE(l)[0]:Interface Vlanif10
 has turned into UP state.
 Nov 22 2020 11:57:13-08:00 Huawei %%01IFNET/4/LINK_STATE(l)[1]:The line protocol
 IP on the interface Vlanif10 has entered the UP state.
 Nov 22 2020 11:57:13-08:00 Huawei %%01IFNET/4/IF_STATE(l)[2]:Interface Vlanif20
 has turned into UP state.
 Nov 22 2020 11:57:13-08:00 Huawei %%01IFNET/4/LINK_STATE(l)[3]:The line protocol
 IP on the interface Vlanif20 has entered the UP state.
 Nov 22 2020 11:57:13-08:00 Huawei %%01IFNET/4/IF_STATE(l)[4]:Interface Vlanif30
 has turned into UP state.
 Nov 22 2020 11:57:13-08:00 Huawei %%01IFNET/4/LINK_STATE(l)[5]:The line protocol
 IP on the interface Vlanif30 has entered the UP state.
 Nov 22 2020 11:57:13-08:00 Huawei %%01IFNET/4/IF_STATE(l)[6]:Interface Vlanif40
 has turned into UP state.
 Nov 22 2020 11:57:13-08:00 Huawei %%01IFNET/4/LINK_STATE(l)[7]:The line protocol
 IP on the interface Vlanif40 has entered the UP state.
 Nov 22 2020 11:57:15-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 16, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/1]q
 [Huawei]
 [Huawei]interface GigabitEthernet 0/0/2
 [Huawei-GigabitEthernet0/0/2]port link-type trunk
 [Huawei-GigabitEthernet0/0/2]
 Nov 22 2020 11:57:35-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 17, t
 he change loop count is 0, and the maximum number of records is 4095.pipip
 [Huawei-GigabitEthernet0/0/2]port trunk pvid vlan 40
 [Huawei-GigabitEthernet0/0/2]
 Nov 22 2020 11:57:55-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 18, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/2]
 [Huawei-GigabitEthernet0/0/2]
 [Huawei-GigabitEthernet0/0/2]port trunk allow-pass vlan all
 [Huawei-GigabitEthernet0/0/2]
 Nov 22 2020 11:58:15-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 19, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/2]
 [Huawei-GigabitEthernet0/0/2]
 [Huawei-GigabitEthernet0/0/2]q
 [Huawei]
 [Huawei]
 [Huawei]interface GigabitEthernet 0/0/3
 [Huawei-GigabitEthernet0/0/3]
 [Huawei-GigabitEthernet0/0/3]port link-type trunk
 [Huawei-GigabitEthernet0/0/3]
 Nov 22 2020 11:58:55-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 20, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/3]port trunk pvid vlan 20
 [Huawei-GigabitEthernet0/0/3]
 Nov 22 2020 11:59:05-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 21, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/3]port trunk allow-pass vlan all
 [Huawei-GigabitEthernet0/0/3]
 Nov 22 2020 11:59:15-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 22, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/3]q
 [Huawei]interface GigabitEthernet 0/0/4
 [Huawei-GigabitEthernet0/0/4]port link-type trunk
 [Huawei-GigabitEthernet0/0/4]
 Nov 22 2020 11:59:35-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 23, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/4]port trunk pvid vlan 20
 [Huawei-GigabitEthernet0/0/4]
 Nov 22 2020 11:59:45-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 24, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/4]port trunk allow-pass vlan all
 [Huawei-GigabitEthernet0/0/4]
 Nov 22 2020 11:59:55-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 25, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-GigabitEthernet0/0/4]q
 [Huawei]
 [Huawei]rip 1
 [Huawei-rip-1]
 Nov 22 2020 12:00:05-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 26, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-rip-1]ve 
 [Huawei-rip-1]ver 
 [Huawei-rip-1]verify-source 
 [Huawei-rip-1]version 2
 [Huawei-rip-1]
 Nov 22 2020 12:00:15-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 27, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-rip-1]net 
 [Huawei-rip-1]network 192.168.10.0
 [Huawei-rip-1]network 192.168.10
 Nov 22 2020 12:00:35-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 28, t
 he change loop count is 0, and the maximum number o
 [Huawei-rip-1]
 [Huawei-rip-1]network 192.168.20.0
 [Huawei-rip-1]
 Nov 22 2020 12:00:45-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 29, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-rip-1]network 192.168.30.0
 [Huawei-rip-1]
 Nov 22 2020 12:00:55-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 30, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-rip-1]network 192.168.40.0
 [Huawei-rip-1]
 Nov 22 2020 12:01:05-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 31, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-rip-1]un 
 [Huawei-rip-1]undo su 
 [Huawei-rip-1]undo summary
 [Huawei-rip-1]
 Nov 22 2020 12:01:15-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
 .25.191.3.1 configurations have been changed. The current change number is 32, t
 he change loop count is 0, and the maximum number of records is 4095.
 [Huawei-rip-1]q
 [Huawei]2.AC的网络配置
 The device is running!
 sys
 Enter system view, return user view with Ctrl+Z.
 [AC6605]vlan ba 
 [AC6605]vlan batch 10 30
 Info: This operation may take a few seconds. Please wait for a moment…done.
 [AC6605]
 [AC6605]int 
 [AC6605]interface v 
 [AC6605]interface Vlanif 10
 [AC6605-Vlanif10]ip add 
 [AC6605-Vlanif10]ip address 192.168.10.254 24
 [AC6605-Vlanif10]q
 [AC6605]int 
 [AC6605]interface G 
 [AC6605]interface GigabitEthernet 0/0/1
 [AC6605-GigabitEthernet0/0/1]po 
 [AC6605-GigabitEthernet0/0/1]por 
 [AC6605-GigabitEthernet0/0/1]port-auto-sleep
 [AC6605-GigabitEthernet0/0/1]port-down
 [AC6605-GigabitEthernet0/0/1]port-isolate
 [AC6605-GigabitEthernet0/0/1]port-security
 [AC6605-GigabitEthernet0/0/1]port li 
 [AC6605-GigabitEthernet0/0/1]port link-type t 
 [AC6605-GigabitEthernet0/0/1]port link-type trunk
 [AC6605-GigabitEthernet0/0/1]po 
 [AC6605-GigabitEthernet0/0/1]port trunk pvid vlan 10
 [AC6605-GigabitEthernet0/0/1]port trunk allow-pass vlan all
 [AC6605-GigabitEthernet0/0/1]q
 [AC6605]
 [AC6605]rip 1
 [AC6605-rip-1]ve 
 [AC6605-rip-1]verify-source
 [AC6605-rip-1]version 2
 [AC6605-rip-1]network 192.168.10.0 
 [AC6605-rip-1]undo summary
 [AC6605-rip-1]q
 [AC6605]3.三层的无线配置
 sys
 Enter system view, return user view with Ctrl+Z.
 [AC6605]capw 
 [AC6605]capwap sou 
 [AC6605]capwap source interface Vlanif 10
 [AC6605]wl 
 [AC6605]wlan
 [AC6605-wlan-view]ap-gr 
 [AC6605-wlan-view]ap-group na 
 [AC6605-wlan-view]ap-group name default
 [AC6605-wlan-ap-group-default]q
 [AC6605-wlan-view]ap au 
 [AC6605-wlan-view]ap auth-mode sn-au 
 [AC6605-wlan-view]ap auth-mode sn-auth
 [AC6605-wlan-view]ap-id 0 ap-s 
 [AC6605-wlan-view]ap-id 0 ap-sn 2102354483105A54402D
 [AC6605-wlan-ap-0]ap-n 
 [AC6605-wlan-ap-0]ap-name hist001
 [AC6605-wlan-ap-0]ap-gr 
 [AC6605-wlan-ap-0]ap-group default
 Warning: This operation may cause AP reset. If the country code changes, it will
 clear channel, power and antenna gain configurations of the radio, Whether to c
 ontinue? [Y/N]:y
 Info: This operation may take a few seconds. Please wait for a moment… done.
 [AC6605-wlan-ap-0]q
 [AC6605-wlan-view]ap-i 
 [AC6605-wlan-view]ap-id 1 ap-s 
 [AC6605-wlan-view]ap-id 1 ap-sn 210235448310BA154839
 [AC6605-wlan-ap-1]ap-na 
 [AC6605-wlan-ap-1]ap-name hist002
 [AC6605-wlan-ap-1]ap-gr 
 [AC6605-wlan-ap-1]ap-group default
 Warning: This operation may cause AP reset. If the country code changes, it will
 clear channel, power and antenna gain configurations of the radio, Whether to c
 ontinue? [Y/N]:y
 Info: This operation may take a few seconds. Please wait for a moment… done.
 [AC6605-wlan-ap-1]q
 [AC6605-wlan-view]
 [AC6605-wlan-view]regulatory-domain-profile na 
 [AC6605-wlan-view]regulatory-domain-profile name default
 [AC6605-wlan-regulate-domain-default]coun 
 [AC6605-wlan-regulate-domain-default]country-code cn
 Info: The current country code is same with the input country code.
 [AC6605-wlan-regulate-domain-default]q
 [AC6605-wlan-view]
 [AC6605-wlan-view]q
 [AC6605]
 [AC6605]ra 
 [AC6605]radius-server te 
 [AC6605]radius-server template default
 [AC6605-radius-default]rad 
 [AC6605-radius-default]radius-attribute
 [AC6605-radius-default]radius-server sh 
 [AC6605-radius-default]radius-server shared-key ci 
 [AC6605-radius-default]radius-server shared-key cipher hist1234
 [AC6605-radius-default]ra 
 [AC6605-radius-default]radius-attribute
 [AC6605-radius-default]radius-server au 
 [AC6605-radius-default]radius-server authentication 192.168.40.254 1812
 [AC6605-radius-default]rad 
 [AC6605-radius-default]radius-attribute
 [AC6605-radius-default]radius-server au 
 [AC6605-radius-default]radius-server authentication
 [AC6605-radius-default]radius-server acc 
 [AC6605-radius-default]radius-server accounting 192.168.40.254 1813
 [AC6605-radius-default]und 
 [AC6605-radius-default]undo ra 
 [AC6605-radius-default]undo radius-attribute
 [AC6605-radius-default]undo radius-server us 
 [AC6605-radius-default]undo radius-server user-name do 
 [AC6605-radius-default]undo radius-server user-name domain-included
 [AC6605-radius-default]q
 [AC6605]
 [AC6605]aaa
 [AC6605-aaa]auth 
 [AC6605-aaa]authentication-scheme default
 [AC6605-aaa-authen-default]aut 
 [AC6605-aaa-authen-default]authentication-mode ra 
 [AC6605-aaa-authen-default]authentication-mode radius
 [AC6605-aaa-authen-default]q
 [AC6605-aaa]acc 
 [AC6605-aaa]accounting-scheme default
 [AC6605-aaa-accounting-default]acc 
 [AC6605-aaa-accounting-default]accounting- 
 [AC6605-aaa-accounting-default]accounting-mode ra 
 [AC6605-aaa-accounting-default]accounting-mode radius
 [AC6605-aaa-accounting-default]q
 [AC6605-aaa]auth 
 [AC6605-aaa]authentication-scheme default
 [AC6605-aaa-authen-default]au 
 [AC6605-aaa-authen-default]authentication-mode no 
 [AC6605-aaa-authen-default]authentication-mode none
 Warning: The configured authentication modes include none authentication, and so
 security risks exist. Continue?[Y/N]y
 [AC6605-aaa-authen-default]
 [AC6605-aaa-authen-default]q
 [AC6605-aaa]do 
 [AC6605-aaa]domain hi 
 [AC6605-aaa]domain hist
 Info: Success to create a new domain.
 [AC6605-aaa-domain-hist]au 
 [AC6605-aaa-domain-hist]authorization-scheme default
 [AC6605-aaa-domain-hist]acc 
 [AC6605-aaa-domain-hist]accounting-scheme default
 [AC6605-aaa-domain-hist]ra 
 [AC6605-aaa-domain-hist]radius-server default
 [AC6605-aaa-domain-hist]q
 [AC6605-aaa]q
 [AC6605]do 
 [AC6605]domain hist admin
 Info: Set the default domain success.
 [AC6605]do 
 [AC6605]dot1x-acc 
 [AC6605]dot1x-access-profile na 
 [AC6605]dot1x-access-profile name default
 [AC6605-dot1x-access-profile-default]q
 [AC6605]
 [AC6605]au 
 [AC6605]authentication- 
 [AC6605]authentication-profile na 
 [AC6605]authentication-profile name default
 [AC6605-authentication-profile-default]do 
 [AC6605-authentication-profile-default]dot 
 [AC6605-authentication-profile-default]dot1x-access-profile default
 Info: This operation may take a few minutes, please wait…
 Authentication profile default : done.
 [AC6605-authentication-profile-default]aut 
 [AC6605-authentication-profile-default]authentication-s 
 [AC6605-authentication-profile-default]authentication-scheme default
 Info: This configuration will make the access domain and permit domain configura
 tion in the authentication profile ineffective.
 [AC6605-authentication-profile-default]acc 
 [AC6605-authentication-profile-default]access-domain
 [AC6605-authentication-profile-default]accounting-scheme default
 Info: This configuration will make the access domain and permit domain configura
 tion in the authentication profile ineffective.
 [AC6605-authentication-profile-default]ra 
 [AC6605-authentication-profile-default]radius-server default
 Info: This configuration will make the access domain and permit domain configura
 tion in the authentication profile ineffective.
 [AC6605-authentication-profile-default]aut 
 [AC6605-authentication-profile-default]authentication-s 
 [AC6605-authentication-profile-default]authentication-scheme default
 Info: This configuration will make the access domain and permit domain configura
 tion in the authentication profile ineffective.
 [AC6605-authentication-profile-default]q
 [AC6605]
 [AC6605]wlan
 [AC6605-wlan-view]ra 
 [AC6605-wlan-view]radio-2g-profile na 
 [AC6605-wlan-view]radio-2g-profile name default
 [AC6605-wlan-radio-2g-prof-default]ra 
 [AC6605-wlan-radio-2g-prof-default]radio-type do 
 [AC6605-wlan-radio-2g-prof-default]radio-type dot11n
 [AC6605-wlan-radio-2g-prof-default]q
 [AC6605-wlan-view]
 [AC6605-wlan-view]ra 
 [AC6605-wlan-view]radio-5g-profile na 
 [AC6605-wlan-view]radio-5g-profile name default
 [AC6605-wlan-radio-5g-prof-default]ra 
 [AC6605-wlan-radio-5g-prof-default]radio-type do 
 [AC6605-wlan-radio-5g-prof-default]radio-type dot11ac
 [AC6605-wlan-radio-5g-prof-default]q
 [AC6605-wlan-view]
 [AC6605-wlan-view]ssi 
 [AC6605-wlan-view]ssid-profile na 
 [AC6605-wlan-view]ssid-profile name his 
 [AC6605-wlan-view]ssid-profile name hist24g
 [AC6605-wlan-ssid-prof-hist24g]ssi 
 [AC6605-wlan-ssid-prof-hist24g]ssid his 
 [AC6605-wlan-ssid-prof-hist24g]ssid hist24g
 Info: This operation may take a few seconds, please wait.done.
 [AC6605-wlan-ssid-prof-hist24g]
 [AC6605-wlan-ssid-prof-hist24g]max 
 [AC6605-wlan-ssid-prof-hist24g]max-sta-number 32
 Warning: This action may cause service interruption. Continue?[Y/N]y
 [AC6605-wlan-ssid-prof-hist24g]re 
 [AC6605-wlan-ssid-prof-hist24g]reach-max-sta his 
 [AC6605-wlan-ssid-prof-hist24g]reach-max-sta hi 
 [AC6605-wlan-ssid-prof-hist24g]reach-max-sta hide-ssid dis 
 [AC6605-wlan-ssid-prof-hist24g]reach-max-sta hide-ssid disable
 [AC6605-wlan-ssid-prof-hist24g]q
 [AC6605-wlan-view]nam 
 [AC6605-wlan-view]ssi 
 [AC6605-wlan-view]ssid-profile na 
 [AC6605-wlan-view]ssid-profile name hist5g
 [AC6605-wlan-ssid-prof-hist5g]ssi 
 [AC6605-wlan-ssid-prof-hist5g]ssid hist5g
 Info: This operation may take a few seconds, please wait.done.
 [AC6605-wlan-ssid-prof-hist5g]max 
 [AC6605-wlan-ssid-prof-hist5g]max-sta-number 16
 Warning: This action may cause service interruption. Continue?[Y/N]y
 [AC6605-wlan-ssid-prof-hist5g]und 
 [AC6605-wlan-ssid-prof-hist5g]undo re 
 [AC6605-wlan-ssid-prof-hist5g]undo reach-max-sta hi 
 [AC6605-wlan-ssid-prof-hist5g]undo reach-max-sta hide-ssid dis 
 [AC6605-wlan-ssid-prof-hist5g]undo reach-max-sta hide-ssid disable
 [AC6605-wlan-ssid-prof-hist5g]q
 [AC6605-wlan-view]se 
 [AC6605-wlan-view]security-profilena 
 [AC6605-wlan-view]security-profile na 
 [AC6605-wlan-view]security-profile name default
 [AC6605-wlan-sec-prof-default]sec 
 [AC6605-wlan-sec-prof-default]security wa 
 [AC6605-wlan-sec-prof-default]security wap2 
 [AC6605-wlan-sec-prof-default]security wap2 do 
 [AC6605-wlan-sec-prof-default]security wpa2 do 
 [AC6605-wlan-sec-prof-default]security wpa2 dot1x a 
 [AC6605-wlan-sec-prof-default]security wpa2 dot1x aes
 Warning: This action may cause service interruption. Continue?[Y/N]y
 Info: This operation may take a few seconds, please wait.done.
 [AC6605-wlan-sec-prof-default]q
 [AC6605-wlan-view]
 [AC6605-wlan-view]vap 
 [AC6605-wlan-view]vap-profile na 
 [AC6605-wlan-view]vap-profile name hist24g
 [AC6605-wlan-vap-prof-hist24g]ssi 
 [AC6605-wlan-vap-prof-hist24g]ssid-profile hist24g
 Info: This operation may take a few seconds, please wait.done.
 [AC6605-wlan-vap-prof-hist24g]sec 
 [AC6605-wlan-vap-prof-hist24g]security-profile default
 [AC6605-wlan-vap-prof-hist24g]au 
 [AC6605-wlan-vap-prof-hist24g]authentication-profile default
 Info: This operation may take a few seconds, please wait.done.
 [AC6605-wlan-vap-prof-hist24g]tr 
 [AC6605-wlan-vap-prof-hist24g]traffic-profile default
 [AC6605-wlan-vap-prof-hist24g]ser 
 [AC6605-wlan-vap-prof-hist24g]service-mode
 [AC6605-wlan-vap-prof-hist24g]service-vlan v 
 [AC6605-wlan-vap-prof-hist24g]service-vlan vlan 30
 Info: This operation may take a few seconds, please wait.done.
 [AC6605-wlan-vap-prof-hist24g]for 
 [AC6605-wlan-vap-prof-hist24g]forward-mode di 
 [AC6605-wlan-vap-prof-hist24g]forward-mode direct-forward
 [AC6605-wlan-vap-prof-hist24g]q
 [AC6605-wlan-view]vap- 
 [AC6605-wlan-view]vap-profile na 
 [AC6605-wlan-view]vap-profile name hist5g
 [AC6605-wlan-vap-prof-hist5g]sec 
 [AC6605-wlan-vap-prof-hist5g]security-profile his 
 [AC6605-wlan-vap-prof-hist5g]security-profile hist5g
 Error: The security profile does not exist.
 [AC6605-wlan-vap-prof-hist5g]sec 
 [AC6605-wlan-vap-prof-hist5g]security-profile default
 [AC6605-wlan-vap-prof-hist5g]au 
 [AC6605-wlan-vap-prof-hist5g]authentication-profile default
 Info: This operation may take a few seconds, please wait.done.
 [AC6605-wlan-vap-prof-hist5g]tr 
 [AC6605-wlan-vap-prof-hist5g]traffic-profile default
 [AC6605-wlan-vap-prof-hist5g]ser 
 [AC6605-wlan-vap-prof-hist5g]service-mode
 [AC6605-wlan-vap-prof-hist5g]service-vlan v 
 [AC6605-wlan-vap-prof-hist5g]service-vlan vlan 30
 Info: This operation may take a few seconds, please wait.done.
 [AC6605-wlan-vap-prof-hist5g]for 
 [AC6605-wlan-vap-prof-hist5g]forward-mode dir 
 [AC6605-wlan-vap-prof-hist5g]forward-mode direct-forward
 [AC6605-wlan-vap-prof-hist5g]q
 [AC6605-wlan-view]ap-gr 
 [AC6605-wlan-view]ap-group na 
 [AC6605-wlan-view]ap-group name default
 [AC6605-wlan-ap-group-default]ra 
 [AC6605-wlan-ap-group-default]radio 0
 [AC6605-wlan-group-radio-default/0]ch 
 [AC6605-wlan-group-radio-default/0]channel 20 
 [AC6605-wlan-group-radio-default/0]channel 20mhz 6
 Warning: This action may cause service interruption. Continue?[Y/N]y
 [AC6605-wlan-group-radio-default/0]q
 [AC6605-wlan-ap-group-default]ra 
 [AC6605-wlan-ap-group-default]radio 1
 [AC6605-wlan-group-radio-default/1]cha 
 [AC6605-wlan-group-radio-default/1]channel 160 
 [AC6605-wlan-group-radio-default/1]channel 160mhz 64
 Warning: This action may cause service interruption. Continue?[Y/N]y
 [AC6605-wlan-group-radio-default/1]q
 [AC6605-wlan-ap-group-default]vap-p 
 [AC6605-wlan-ap-group-default]vap-profile hi 
 [AC6605-wlan-ap-group-default]vap-profile hist24g wl 
 [AC6605-wlan-ap-group-default]vap-profile hist24g wlan 1 ra 
 [AC6605-wlan-ap-group-default]vap-profile hist24g wlan 1 radio 0
 Info: This operation may take a few seconds, please wait…done.
 [AC6605-wlan-ap-group-default]vap-profile hist5g wlan 2 radio 1
 Info: This operation may take a few seconds, please wait…done.
 [AC6605-wlan-ap-group-default]q
 [AC6605-wlan-view]q