...
Полная конфигурация WLC-1
| Раскрыть |
|---|
| Блок кода |
|---|
| #!/usr/bin/clish |
object-group service airtune |
object-group service dhcp_client |
object-group service dhcp_server |
object-group service netconf |
object-group service radius_auth |
object-group service sync |
object-group service softgre_controller |
syslog file tmpsys:syslog/default |
key ascii-text encrypted 8CB5107EA7005AFF |
exit nas local key
exit
nas local
key ascii-text encrypted 8CB5107EA7005AFF |
exit domain default user test password
exit
domain default
user test
password ascii-text encrypted CDE65039E5591FA3 |
exit exit
exit
exit
virtual-server default |
enable exit enable exit
enable
exit
enable
exit
radius-server host 127.0.0.1 |
key ascii-text encrypted 8CB5107EA7005AFF |
aaa radius-profile default_radius |
radius-server host 127.0.0.1 |
ip address 192.168.1.2/24 |
vrrp timers garp refresh 60 |
vrrp no
ip address 192.168.2.2/24 |
vrrp timers garp refresh 60 |
vrrp no
interface gigabitethernet 1/0/1 |
interface gigabitethernet 1/0/2 |
switchport trunk allowed vlan add 3,2449 |
interface gigabitethernet 1/0/3 |
interface gigabitethernet 1/0/4 |
interface tengigabitethernet 1/0/1 |
interface tengigabitethernet 1/0/2 |
local address 192.168.1.1 |
local-address 192.168.1.2 |
remote-address 192.168.1.3 |
security zone-pair trusted self |
match destination-port object-group ssh |
enable exit rule 11 action permit match protocol vrrp enable exit rule 12 action permit match protocol tcp match destination-port object-group softgre_controller enable exit rule 13 action permit match protocol tcp match destination-port object-group sync enable exit rule 20 action permit match protocol icmp enable exit rule 30 action permit match protocol udp match source-port object-group dhcp_client match destination-port object-group dhcp_server enable exit rule 40 action permit match protocol udp match destination-port object-group ntp enable exit rule 50 action permit match protocol tcp match destination-port object-group dns enable exit rule 60 action permit match protocol udp match destination-port object-group dns enable exit rule 70 action permit match protocol tcp match destination-port object-group netconf enable exit rule 80 action permit match protocol tcp match destination-port object-group sa enable exit rule 90 action permit match protocol udp match destination-port object-group radius_auth enable exit rule 100 action permit match protocol gre enable exit rule 110 action permit match protocol tcp match destination-port object-group airtune enable exit exit security zone-pair trusted trusted rule 1 action permit enable exit exit security zone-pair trusted untrusted rule 1 action permit enable exit exit security zone-pair untrusted self rule 1 action permit match protocol udp match source-port object-group dhcp_server match destination-port object-group dhcp_client enable exit exit security zone-pair users self rule 10 action permit match protocol icmp enable exit rule 11 action permit match protocol vrrp enable exit rule 20 action permit match protocol udp match source-port object-group dhcp_client match destination-port object-group dhcp_server enable exit rule 30 action permit match protocol tcp match destination-port object-group dns enable exit rule 40 action permit match protocol udp match destination-port object-group dns enable exit exit security zone-pair users untrusted rule 1 action permit enable exit exitsecurity passwords default-expired nat source ruleset factory to zone untrusted rule 10 description "replace 'source ip' by outgoing interface ip address" action source-nat interface enable exit exit exit ip dhcp-server ip dhcp-server pool ap-pool network
enable
exit
rule 11
action permit
match protocol vrrp
enable
exit
rule 12
action permit
match protocol tcp
match destination-port object-group softgre_controller
enable
exit
rule 13
action permit
match protocol tcp
match destination-port object-group sync
enable
exit
rule 20
action permit
match protocol icmp
enable
exit
rule 30
action permit
match protocol udp
match source-port object-group dhcp_client
match destination-port object-group dhcp_server
enable
exit
rule 40
action permit
match protocol udp
match destination-port object-group ntp
enable
exit
rule 50
action permit
match protocol tcp
match destination-port object-group dns
enable
exit
rule 60
action permit
match protocol udp
match destination-port object-group dns
enable
exit
rule 70
action permit
match protocol tcp
match destination-port object-group netconf
enable
exit
rule 80
action permit
match protocol tcp
match destination-port object-group sa
enable
exit
rule 90
action permit
match protocol udp
match destination-port object-group radius_auth
enable
exit
rule 100
action permit
match protocol gre
enable
exit
rule 110
action permit
match protocol tcp
match destination-port object-group airtune
enable
exit
exit
security zone-pair trusted trusted
rule 1
action permit
enable
exit
exit
security zone-pair trusted untrusted
rule 1
action permit
enable
exit
exit
security zone-pair untrusted self
rule 1
action permit
match protocol udp
match source-port object-group dhcp_server
match destination-port object-group dhcp_client
enable
exit
exit
security zone-pair users self
rule 10
action permit
match protocol icmp
enable
exit
rule 11
action permit
match protocol vrrp
enable
exit
rule 20
action permit
match protocol udp
match source-port object-group dhcp_client
match destination-port object-group dhcp_server
enable
exit
rule 30
action permit
match protocol tcp
match destination-port object-group dns
enable
exit
rule 40
action permit
match protocol udp
match destination-port object-group dns
enable
exit
exit
security zone-pair users untrusted
rule 1
action permit
enable
exit
exit
security passwords default-expired
nat source
ruleset factory
to zone untrusted
rule 10
description "replace 'source ip' by outgoing interface ip address"
action source-nat interface
enable
exit
exit
exit
ip dhcp-server
ip dhcp-server pool ap-pool
network 192.168.1.0/24 |
address-range 192.168.1.4-192.168.1.254 |
default-router 192.168.1.1 |
option 42 ip-address 192.168.1.1 |
suboption 12 ascii-text "192.168.1.1" |
suboption 15 ascii-text "https://192.168.1.1:8043" |
ip dhcp-server pool users-pool |
address-range 192.168.2.4-192.168.2.254 |
default-router 192.168.2.1 |
failover
failover
data-tunnel configuration wlc |
aaa radius-profile default_radius |
wlc
wlc
outside-address 192.168.1.1 |
exit airtune enable exit failover
exit
airtune
enable
exit
failover
ap-location default-location |
description "default-location" |
ssid-profile default-ssid |
exit
exit
ssid-profile default-ssid |
description "default-ssid" |
radius-profile default-radius |
enable exit
enable
exit
ap-profile default-ap |
password ascii-text encrypted 8CB5107EA7005AFF |
exit
exit
radius-profile default-radius |
auth-password ascii-text encrypted 8CB5107EA7005AFF |
exit
exit
ip-pool default-ip-pool |
description "default-ip-pool" |
ap-location default-location |
exit enable exitip ssh server ntp enable ntp server
exit
enable
exit
ip ssh server
ntp enable
ntp server 100.110.0.65 |
|
Пример настройки WLC-2
Подключаемся к WLC и переходим в режим конфигурирования:
...