Got it

AP Authentication and WLAN Configuration Roadmap

Latest reply: Nov 19, 2021 08:47:40 837 20 21 0 1

AP Authentication and WLAN Configuration Roadmap

Hello everyone,


Today I would like to present a practical method of how to perform authentication, profile and roadmap settings on a Huawei access controller using the eNSP simulator.

Learning Objectives:

• Configure AP authentcation;
• Undestand WLAN configuration profile;
• Undestand WLAN configuration roadmap;
• Configure open system authentication.

Topology:

00


Experiment Task:

Let's carry out the configurations in stages:


Step 1 Configuring a Switch and AC.

For the next step it is necessary that the switch and AC settings are ready, you will find in this other topic:

https://forum.huawei.com/enterprise/en/ac-configuration-initialization/thread/783703-869

Step 2 Creating an AP Group

Below is the AP Group configuration for the example:

[AC1] wlan
[AC1-wlan-view] ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1] quit


01a


Step 3 Configuring AP Online Parameters

Enable DHCP on the AC. Assign IP addresses to the STA and AP, configure the Option 43 parameters.


Below is the DHCP and IP Pool configuration:

01b

02


Enable DHCP over all VLAINF interfaces on the AC.

03


Configure regulatory domain profile domain1.

22


Configure the AC source interface.

16


Getting information from APs:


For our example we will perform authentication via MAC.

AP1:

06

06a

O AP1 tem o MAC Address: 00e0-fc78-4b80



AP2:


07

07a




O AP1 tem o MAC Address: 00e0-fc3e-2170


Configure AP authentication.

AP authentication has three modes. By default, MAC authentication is used. Manually add APs based on MAC addresses.

[AC1] wlan
[AC1-wlan-view] ap auth-mode mac-auth


Import the AP offline to the AC and two APs to AP group ap-group1. Name the two APs AP1 and AP2.

[AC1-wlan-view] ap-mac 00e0-fc78-4b80 ap-id 0
[AC1-wlan-view-ap-0] ap-group ap-group1
[AC1-wlan-view-ap-0] ap-name ap1
[AC1-wlan-view] ap-mac 00e0-fc3e-2170 ap-id 1
[AC1-wlan-view-ap-1] ap-group ap-group1
[AC1-wlan-view-ap-1] ap-name ap2


Below the AP import configuration


21


After APs are added, their status will change from fault to config, and then to normal. If the AP status does not change to normal serveral minutes after the AP is added, check the configuration of VLAN, DHCP, and AP authenticatin.

01


Step 4 Configuring WLAN Service Parameters

Configure SSID Profile.

Create SSID profiles employee1, voice1 and guest1, and set SSIDs to employee1, voice1 and guest1, respectively.

18


Create VAP profiles employee1, voice1 and guest1. Set the data forwarding mode for employee1 and voice1 to direct forwarding, and that for guest1 to tunnel forwarding. Configure the service VLAN and bind the profile to the SSID profile.

19


Configure AP groups to use the regulatory domain profile and VAP profile. When AP group ap-group1 uses VAP profile employee1, set VAP ID to 1. When AP group ap-group1 uses VAP profile voice1, set VAP ID to 2. When AP group ap-group1 uses VAP profile guest1, set VAP ID to 3. Radios 0 and 1 on the AP use the configuration of the VAP profile.

20


Verification

Checking the VAP Status


The AC automatically delivers WLAN service configurations to APs. After the service configuration is complete, run the display vap ssid guest1 and display vap ssid employee1 commands. If the value of Status in the command output is ON, the have been created on AP radios.

08

09

10


Terminal Connection Test

12a

In the example we are going to connect to SSID voice1 in order to exemplify.


Connect STAs to the WLANs with SSIDs employee1, voice1 and guest1. Run the display station all commands on the AC. The command output shows that the STAs are connected to the WLANs.

11


On the wireless terminal, ping the IP address of the simulated public network interface on the switch.

13



-END-

Reference:
HCIA-WLAN_V2.0_Experiment_Guide(CLI-based)

Very good share my friend
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Oct 25, 2021 16:13:47 (0) (0)
you're welcome  
Thanks for your sharing!
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Oct 25, 2021 16:13:58 (0) (0)
you're welcome master  
zaheernew
MVE Author Created Oct 25, 2021 04:11:55

Awesome bro must required lab for all begineers.


View more
  • x
  • convention:

Serges_armel
Serges_armel Created Oct 25, 2021 18:21:05 (0) (0)
 
IndianKid
Moderator Author Created Oct 25, 2021 05:52:11

all good content. thanks
View more
  • x
  • convention:

Well done, thanks my friend
View more
  • x
  • convention:

Good post. Thank you!
View more
  • x
  • convention:

Very good! Thanks for your sharing!
View more
  • x
  • convention:

Great post. Thanks for sharing...
View more
  • x
  • convention:

bruno.guedes
HCIE MVE Author Created Oct 25, 2021 15:09:14

Great post, Anderson! It's very interesting that people also can see the difference between tunnel and direct mode observing the packets in the Wireshark if they want.
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Oct 25, 2021 16:15:29 (0) (0)
great ideia!  
12
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.