zone private
network dhcp
ip subnet 0.0.0.0/0 interface vlan1
network lan
ip subnet 192.168.1.0/24
host ap
ip address 192.168.1.101
ip address 192.168.1.102
ip address 192.168.1.103
network wireless_user
ip subnet 192.168.10.0/24
ip subnet 192.168.20.0/24
外部ネットワークを表すゾーン「public」を作成します。
zone public
network wan
ip subnet 0.0.0.0/0 interface ppp0
host ppp0
ip address dynamic interface ppp0
firewall
rule 10 permit dhcp from private.dhcp to private.dhcp
rule 20 permit any from private.lan to private.lan
rule 30 permit any from private to public
rule 40 permit dns from public.wan.ppp0 to public.wan
rule 50 deny any from private.wireless_user to private.lan.ap
protect
ip dhcp pool pool1
network 192.168.10.0/24
range 192.168.10.201 192.168.10.210
default-router 192.168.10.1
subnet-mask 255.255.255.0
ip dhcp pool pool2
network 192.168.20.0/24
range 192.168.20.201 192.168.20.210
default-router 192.168.20.1
subnet-mask 255.255.255.0
awplus#show wireless channel-blanket ap status ↓
AP: 1
Last Update Time: 2019-10-25 16:43:56
Number of CB member: 3
AP MAC Address
----- --------------
1 0000.5e00.5301
2 0000.5e00.5302
3 0000.5e00.5303
AP: 2
Last Update Time: 2019-10-25 16:43:35
Number of CB member: 3
AP MAC Address
----- --------------
1 0000.5e00.5301
2 0000.5e00.5302
3 0000.5e00.5303
AP: 3
Last Update Time: 2019-10-25 16:42:36
Number of CB member: 3
AP MAC Address
----- --------------
1 0000.5e00.5301
2 0000.5e00.5302
3 0000.5e00.5303
!
interface vlan1
ip address 192.168.1.1/24
!
vlan database
vlan 10 name cb_user
vlan 20 name cell_user
!
interface vlan10
ip address 192.168.10.1/24
interface vlan20
ip address 192.168.20.1/24
!
ntp server 10.110.110.1
!
no spanning-tree rstp enable
!
interface eth1
encapsulation ppp 0
!
interface ppp0
keepalive
ip address negotiated
ppp username user@isp
ppp password isppasswd
ip tcp adjust-mss pmtu
!
zone private
network dhcp
ip subnet 0.0.0.0/0 interface vlan1
network lan
ip subnet 192.168.1.0/24
host ap
ip address 192.168.1.101
ip address 192.168.1.102
ip address 192.168.1.103
network wireless_user
ip subnet 192.168.10.0/24
ip subnet 192.168.20.0/24
!
zone public
network wan
ip subnet 0.0.0.0/0 interface ppp0
host ppp0
ip address dynamic interface ppp0
!
application dhcp
protocol udp
dport 67 to 68
!
firewall
rule 10 permit dhcp from private.dhcp to private.dhcp
rule 20 permit any from private.lan to private.lan
rule 30 permit any from private to public
rule 40 permit dns from public.wan.ppp0 to public.wan
rule 50 deny any from private.wireless_user to private.lan.ap
protect
!
nat
rule 10 masq any from private to public
enable
!
ip name-server 10.100.100.100
!
ip dns forwarding
!
ip route 0.0.0.0/0 ppp0
!
ip dhcp pool pool1
network 192.168.10.0/24
range 192.168.10.201 192.168.10.210
default-router 192.168.10.1
subnet-mask 255.255.255.0
ip dhcp pool pool2
network 192.168.20.0/24
range 192.168.20.201 192.168.20.210
default-router 192.168.20.1
subnet-mask 255.255.255.0
!
service dhcp-server
!
wireless
management address 192.168.1.1
enable
!
radius-server local
nas 192.168.1.101 key nas123456
nas 192.168.1.102 key nas123456
nas 192.168.1.103 key nas123456
server enable
!
radius-server host 192.168.1.1 key nas123456
aaa group server radius wpa4login
server 192.168.1.1
!
wireless
security 1 mode wpa-personal
key passphrase_for_wnet
!
security 2 mode wpa-enterprise
radius authentication group wpa4login
radius accounting group wpa4login
no dynamic-vlan enable
!
network 1
vlan 10
ssid wnet10
security 1
network 2
vlan 20
ssid wnet20
security 2
!
ap-profile 1
hwtype at-tq5403
radio 1
enable
vap 0 network 1 channel-blanket
radio 2
enable
vap 0 network 2
channel-blanket
control-vlan 100
designated-ap 1
cb-channel radio 1 channel 5
!
ap 1
enable
profile 1
ip-address 192.168.1.101
mac-address 0000.5e00.5301
ap 2
enable
profile 1
ip-address 192.168.1.102
mac-address 0000.5e00.5302
ap 3
enable
profile 1
ip-address 192.168.1.103
mac-address 0000.5e00.5303
!
task 1
time 15:00
type power-channel ap all calculate
enable
!
task 2
time 03:00
type power-channel ap all apply
enable
!
interface port1.0.1
switchport mode trunk
switchport trunk allowed vlan add 10,20
!
end