一、组网图
二、WX3024配置步骤:
# 配置ssl服务策略
[AC]ssl server-policy 1 [AC-ssl-server-policy-1] pki-domain do [AC-ssl-server-policy-1] ciphersuite rsa_rc4_128_sha [AC-ssl-server-policy-1] handshake timeout 180 [AC-ssl-server-policy-1] close-mode wait [AC-ssl-server-policy-1] session cachesize 1000
# 应用ssl服务策略、开启https服务
[AC]ip https ssl-server-policy 1 [AC]ip https enable
# 配置PKI实体和域
[AC]pki entity en [AC-pki-entity-en]common-name portal [AC-pki-entity-en]organization portal_server [AC-pki-entity-en]pki domain do [AC-pki-domain-do]certificate request entity en [AC-pki-domain-do]crl check disable
# 将证书文件拷贝到AC Flash中:

# 将证书文件导入AC Flash中(如果已经导入过证书,可先销毁:public-key local destroy rsa):
[AC]pki import-certificate ca domain do der filename certnew.cer [AC]pki import-certificate local domain do p12 filename server_ssl.pfx 输入密码:123
# 配置认证策略
[AC]radius scheme cams [AC-radius-cams]server-type extended [AC-radius-cams]primary authentication 192.168.1.10 [AC-radius-cams]primary accounting 192.168.1.10 [AC-radius-cams]key authentication h3c [AC-radius-cams]key accounting h3c [AC-radius-cams] nas-ip 192.168.1.254
# 配置认证域
[AC]domain cams [AC-isp-cams]authentication portal radius-scheme cams [AC-isp-cams]authorization portal radius-scheme cams [AC-isp-cams]accounting portal radius-scheme cams
# 配置无线服务模板
[AC]wlan service-template 2 clear [AC-wlan-st-2]ssid lopo [AC-wlan-st-2]bind WLAN-ESS 2 [AC-wlan-st-2]service-template enable
# 配置无线口,将无线口添加到起Portal的vlan
[AC]interface WLAN-BSS 2 [AC-WLAN-BSS2] port access vlan 2
# 在AC下绑定无线服务模板
[AC-wlan-ap-ap_001] wlan ap ap_001 model WA2220E-AG [AC-wlan-ap-ap_001] serial-id 210235A22W0073000002 [AC-wlan-ap-ap_001] radio 2 [AC-wlan-ap-ap_001 -radio-2] service-template 1 [AC-wlan-ap-ap_001 -radio-2] radio enable
# 配置Portal Server和免认证规则
[AC]portal server local ip 192.168.1.254 url https://192.168.1.254/portal [AC]portal free-rule 0 source interface GigabitEthernet1/0/1 destination any [AC]portal local-server https server-policy 1 [AC]interface Vlan-interface 2 [AC-Vlan-interface1]ip address 192.168.2.254 24 [AC-Vlan-interface1]portal server local method direct
三、完整配置信息,以及验证结果。
请自行下载文档查阅:http://pan.baidu.com/s/1xfNys





