使能CAPWAP服务。huawei(config)#sysman service capwap enable
配置完成后,可通过如下命令查询服务使能后的配置是否正确。huawei(config)#display interface loopback 0huawei(config)#display ip vpn-instancehuawei(config)#display sysman service statehuawei(config)#display sysman server source capwap
配置SSID模板。设置SSID模板不同安全策略指定Wi-Fi的SSID模板名称、SSID名称以及每个SSID(VAP)允许接入的最大STA数量。huawei(config)#wlan//预共享密钥认证huawei(config-wlan)#ssid-profile name ssid_pskhuawei(config-wlan-ssid-prof-ssid_psk)#ssid ssid_pskhuawei(config-wlan-ssid-prof-ssid_psk)#max-sta-number 64huawei(config-wlan-ssid-prof-ssid_psk)#quit//Portal认证huawei(config-wlan)#ssid-profile name ssid_portalhuawei(config-wlan-ssid-prof-ssid_portal)#ssid ssid_portalhuawei(config-wlan-ssid-prof-ssid_portal)#max-sta-number 64huawei(config-wlan-ssid-prof-ssid_portal)#quit//802.1X认证huawei(config-wlan)#ssid-profile name ssid_dot1xhuawei(config-wlan-ssid-prof-ssid_dot1x)#ssid ssid_dot1xhuawei(config-wlan-ssid-prof-ssid_dot1x)#max-sta-number 64huawei(config-wlan-ssid-prof-ssid_dot1x)#quit
//预共享密钥认证huawei(config-wlan)#security-profile name sec_pskhuawei(config-wlan-sec-prof-sec_psk)#security wpa2 psk pass-phrase aesPlease configure the key(8-63): Warning: This action may cause service interruption. Continue?(y/n) [n]:y Info: This operation may take a few seconds, please wait.done. huawei(config-wlan-sec-prof-sec_psk)#quit//Portal认证huawei(config-wlan)#security-profile name sec_portalhuawei(config-wlan-sec-prof-sec_portal)#securityopenhuawei(config-wlan-sec-prof-sec_portal)#quit//802.1X认证huawei(config-wlan)#security-profile name sec_dot1xhuawei(config-wlan-sec-prof-sec_dot1x)#security wpa2 dot1x aes-tkip 10.11.100.1 1812huawei(config-wlan-sec-prof-sec_dot1x)#quit
配置VAP模板。
将VAP模板分别与SSID模板、安全模板关联,同时指定SSID对应的业务VLAN。
//预共享密钥认证huawei(config-wlan)#vap-profile name vap_pskhuawei(config-wlan-vap-prof-vap_psk)#ssid-profile ssid_pskhuawei(config-wlan-vap-prof-vap_psk)#security-profile sec_pskhuawei(config-wlan-vap-prof-vap_psk)#service-vlan vlan-id 100huawei(config-wlan-vap-prof-sec_psk)#quit//Portal认证huawei(config-wlan)#vap-profile name vap_portalhuawei(config-wlan-vap-prof-vap_portal)#ssid-profile ssid_portalhuawei(config-wlan-vap-prof-vap_portal)#security-profile sec_portalhuawei(config-wlan-vap-prof-vap_portal)#service-vlan vlan-id 200huawei(config-wlan-vap-prof-vap_portal)#quit//802.1X认证huawei(config-wlan)#vap-profile name vap_dot1xhuawei(config-wlan-vap-prof-vap_dot1x)#ssid-profile ssid_dot1xhuawei(config-wlan-vap-prof-vap_dot1x)#security-profile sec_dot1xhuawei(config-wlan-vap-prof-vap_dot1x)#service-vlan vlan-id 300huawei(config-wlan-vap-prof-vap_dot1x)#quit
(可选)配置空口扫描模板。huawei(config-wlan)#air-scan-profile name w826e_airscanhuawei(config-wlan-air-scan-prof-w826e_airscan)#undo scan-disablehuawei(config-wlan-air-scan-prof-w826e_airscan)#scan-period 60huawei(config-wlan-air-scan-prof-w826e_airscan)#scan-interval 180000huawei(config-wlan-air-scan-prof-w826e_airscan)#quit
配置AP组。在AP组中添加VAP模板,并指定VAP对应的射频(2.4G/5G)。huawei(config-wlan)#ap-group name ap_group1Info: This operation may take a few seconds. Please wait for a moment.done. huawei(config-wlan-ap-group-ap_group1)#radio-2g-profile w826e_2g radio 0huawei(config-wlan-ap-group-ap_group1)#radio-5g-profile w826e_5g radio 1huawei(config-wlan-ap-group-ap_group1)#regulatory-domain-profile CNhuawei(config-wlan-ap-group-ap_group1)#radio 0 channel 20mhz 6huawei(config-wlan-ap-group-ap_group1)#radio 0 power-level 100huawei(config-wlan-ap-group-ap_group1)#radio 1 channel 20mhz 64huawei(config-wlan-ap-group-ap_group1)#radio 1 power-level 100//预共享密钥认证huawei(config-wlan-ap-group-ap_group1)#vap-profile vap_psk wlan 1 radio all//Portal认证huawei(config-wlan-ap-group-ap_group1)#vap-profile vap_portal wlan 2 radio all//802.1X认证huawei(config-wlan-ap-group-ap_group1)#vap-profile vap_dot1x wlan 3 radio allhuawei(config-wlan-ap-group-ap_group1)#quit
添加AP到AP组。//添加ONT_1(ap1)huawei(config-wlan)#ap-id 0 ap-sn 485754431D005288huawei(config-wlan)#ap-group name ap_group1huawei(config-wlan-ap-group-ap_group1)#ap-name ap1huawei(config-wlan-ap-0)#quit//添加ONT_2(ap2)huawei(config-wlan)#ap-id 1 ap-sn 485754431D005388huawei(config-wlan)#ap-group name ap_group1huawei(config-wlan-ap-group-ap_group1)#ap-name ap2huawei(config-wlan-ap-1)#quit
huawei(config-wlan)#capwap dtls pskPlease configure the DLTS key(16-32): Info: Deliver DTLS PSK to devices using CAPWAP connections. It may take a few minutes. huawei(config-wlan)#capwap sync psk allhuawei(config-wlan)#quit