hncys 发表于 2018-7-11 06:14:55

cisco胖AP虚拟多个SSID-rocky

  明天将要是重要的日子,养育了我的外婆80大寿,因为工作的需要只能在远方城市祝福外婆生日快乐,感谢您!您辛苦了,祝您身体健康,天天快乐!
  心情高兴分享一些自己的心得,希望对大家有所帮助。。。
  配置如下,并有说明。。。
  ap#show run
  ap#show running-config
  Building configuration...
  Current configuration : 3135 bytes
  !
  version 12.4
  no service pad
  service timestamps debug datetime msec
  service timestamps log datetime msec
  service password-encryption
  !
  hostname ap
  !
  enable secret 5 $1$6Ixe$d7.U41oSqslxqZlSngGIX0
  !
  no aaa new-model
  clock timezone sz 8
  !
  !
  dot11 vlan-name green vlan 20   //定义2个vlan 10,20命名分别为red green
  dot11 vlan-name red vlan 10
  !
  dot11 ssid green               // green 属于vlan 20
  vlan 20
  authentication open
  authentication key-management wpa   //采用wpa 认证
  mbssid guest-mode                   //多ssid模式
  wpa-psk ascii 7 00051105005E0D0107// 定义WPA的密码
  !
  dot11 ssid red
  vlan 10
  authentication open
  authentication key-management wpa version 2//采用WPA2版本认证
  mbssid guest-mode
  wpa-psk ascii 7 151A1E0D0A2D3C2121
  !
  power inline negotiation prestandard source
  !
  !
  username Cisco password 7 00071A150754
  !
  bridge irb
  !
  !
  interface Dot11Radio0
  no ip address
  no ip route-cache
  !
  encryption mode wep mandatory
  !
  encryption vlan 20 mode ciphers aes-ccm tkip    //wpa认证的加密配置(需要先定义)
  !
  encryption vlan 10 mode ciphers aes-ccm tkip
  !
  ssid green    // 将SSID应用到接口
  !
  ssid red
  !
  mbssid      // 启用多ssid功能   (这个功能很重要,开启多SSID 模式)
  channel 2412   //频道选择1 = 2412
  station-role root access-point
  !
  interface Dot11Radio0.1
  encapsulation dot1Q 1 native
  no ip route-cache
  bridge-group 1
  bridge-group 1 subscriber-loop-control
  bridge-group 1 block-unknown-source
  no bridge-group 1 source-learning
  no bridge-group 1 unicast-flooding
  bridge-group 1 spanning-disabled
  !
  interface Dot11Radio0.10
  encapsulation dot1Q 10
  no ip route-cache
  bridge-group 10
  bridge-group 10 subscriber-loop-control
  bridge-group 10 block-unknown-source
  no bridge-group 10 source-learning
  no bridge-group 10 unicast-flooding
  bridge-group 10 spanning-disabled
  !
  interface Dot11Radio0.20
  encapsulation dot1Q 20
  no ip route-cache
  bridge-group 20
  bridge-group 20 subscriber-loop-control
  bridge-group 20 block-unknown-source
  no bridge-group 20 source-learning
  no bridge-group 20 unicast-flooding
  bridge-group 20 spanning-disabled
  !
  interface Dot11Radio1
  no ip address
  no ip route-cache
  shutdown
  !

  encryption key 1>  encryption mode wep mandatory
  station-role root
  bridge-group 1
  bridge-group 1 subscriber-loop-control
  bridge-group 1 block-unknown-source
  no bridge-group 1 source-learning
  no bridge-group 1 unicast-flooding
  bridge-group 1 spanning-disabled
  !
  interface FastEthernet0
  no ip address
  no ip route-cache
  duplex auto
  speed auto
  !
  interface FastEthernet0.1
  encapsulation dot1Q 1 native
  no ip route-cache
  bridge-group 1
  no bridge-group 1 source-learning
  bridge-group 1 spanning-disabled
  !
  interface FastEthernet0.10
  encapsulation dot1Q 10
  no ip route-cache
  bridge-group 10
  no bridge-group 10 source-learning
  bridge-group 10 spanning-disabled
  !
  interface FastEthernet0.20
  encapsulation dot1Q 20
  no ip route-cache
  bridge-group 20
  no bridge-group 20 source-learning
  bridge-group 20 spanning-disabled
  !
  interface BVI1
  ip address 172.23.188.211 255.255.255.0
  no ip route-cache
  !
  ip default-gateway 172.23.188.5
  ip http server
  ip http authentication local
  no ip http secure-server
  ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
  bridge 1 route ip
  !
  !
  !
  line con 0
  line vty 0 4
  login local
  !
  end
页: [1]
查看完整版本: cisco胖AP虚拟多个SSID-rocky