一、组网需求
WA2110、WX5002、交换机(S36)、CAMS服务器(安装有portal组件)、便携机(安装有11b/g无线网卡和Windows无线客户端),DHCP服务器(Windows 2003 server的DHCP组件)
二、组网图
无线客户端采用动态获得地址方式,接入无线网络而未进行portal认证时获得192.168.1.0/24网段的地址,即子地址段。Portal认证通过后,动态获得主地址,即192.168.2.0/24,实现二次地址分配。
CAMS服务器的IP地址为192.168.0.100,网关为192.168.0.99
WA2110动态获得192.168.0.0/24网段的地址。
SSID的名称为h3c-clear
三、WX的主要配置命令
1)配置无线接口[H3C] int WLAN-ESS 3 [H3C-WLAN-ESS3]port access vlan 2
2)配置服务模板
[H3C]wlan service-template 3 clear [H3C-wlan-st-3]ssid h3c-clear [H3C-wlan-st-3]bind WLAN-ESS 3 [H3C-wlan-st-3] authentication-method open-system [H3C-wlan-st-3]service-template enable
3)配置AP1
[H3C] wlan ap ap1 model WA2100 [H3C-wlan-ap-ap1] serial-id 210235A22W0074000003
4)配置AP射频
[H3C-wlan-ap-ap1] radio 1 type 11g [H3C-wlan-ap-ap1-radio-1] max-power 10 [H3C-wlan-ap-ap1-radio-1] service-template 3
5)使能所有射频
[H3C] wlan radio enable all
6)配置radius scheme
[H3C]radius scheme ias [H3C-radius-ias] server-type extended [H3C-radius-ias] primary authentication 192.168.0.100 [H3C-radius-ias] primary accounting 192.168.0.100 [H3C-radius-ias] key authentication h3c [H3C-radius-ias] key accounting h3c [H3C-radius-ias]user-name-format without-domain
7)配置domain
[H3C]domain portal [H3C-isp-portal] authentication portal radius-scheme ias [H3C-isp-portal] authorization portal radius-scheme ias [H3C-isp-portal] accounting portal radius-scheme ias [H3C]domain default enable portal8)配置portal认证
[H3C] portal server h3c ip 192.168.0.100 key h3c url http://192.168.0.100/portal
这里注意需完整以下几点:
>Name: h3cportal
>IP address: 192.168.0.100
>Key: h3c
>Port number: 50100
>URL: http://192.168.0.100/portal.
然后客户端对应的vlan接口上使能portal认证功能:
[H3C] interface Vlan-interface2 [H3C-Vlan-interface2] ip address 192.168.2.1 255.255.255.0 [H3C-Vlan-interface2] ip address 192.168.1.1 255.255.255.0 sub [H3C-Vlan-interface2] portal server h3c method redhcp service-type normal
注:此处采用portal认证方式为redhcp认证方式。
9)配置DHCP
relayPortal认证采用二次地址分配时,WX5002必须配置成DHCP relay方式,采用外置DHCP server进行动态地址分配。在Windows 2003 server的DHCP组件配置中,配置两个地址段192.168.2.0/24,网关192.168.2.1和192.168.1.0/24,网关192.168.1.1。
[H3C]dhcp relay server-group 1 ip 192.168.0.10 [H3C] interface Vlan-interface2 [H3C-Vlan-interface2] dhcp select relay [H3C-Vlan-interface2] dhcp relay server-select 1 [H3C-Vlan-interface2] dhcp relay address-check enable
配置了以上wx,另外还需要配置S3600交换机,以及CMAS的配置,完整配置你可以下载参考:
http://pan.baidu.com/s/1DtBrM





