0.ã³ã³ãããŒã©ãŒç®¡çãããã¯ãŒã¯ã®çµç¹ã®åå
åŸæ¥ã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã¯ããã¢ã¯ã»ã¹ãã€ã³ããã«åºã¥ããŠæ§ç¯ãããŸããéåžžãããã€ã¹ã¯1ã€ã®Wi-Fiãããã¯ãŒã¯ïŒSSIDïŒã«å¯Ÿå¿ããäžå®ã¬ãã«ã®ã»ãã¥ãªãã£ïŒæ¿èªãæå·åïŒã管çæ§ãããã³æç·ãããã¯ãŒã¯ãšã®éä¿¡ãæäŸããŸãã çŸåšããã®ãããªããã€ã¹ã®äŸ¡æ Œã¯100ãã«æªæºã§ã家åºã§ã®äœ¿çšããŸãã¯åŸæ¥å¡10人ã®ãªãã£ã¹ã§ã®ãã€ã³ã¿ãŒãããã®é åžãã®ã¿ã¹ã¯ã«é©ããŠããŸãã åäžã®ã³ã³ãããŒã«ã»ã³ã¿ãŒãåãã倧èŠæš¡ã·ã¹ãã ã®å¿ èŠæ§ã«ããããæããªãã¢ã¯ã»ã¹ãã€ã³ãã«å¯Ÿå¿ããã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒãç»å ŽããŸããã ãã®ãããªã¹ããŒã ã§ã¯ãã³ã³ãããŒã©ãŒã¯éäžèªèšŒãSSIDãå å ¥è ã®ããŒãã³ã°ãå¶åŸ¡ããã€ãŒãµãŒã®ãé·æãã©ã¡ãŒã¿ãŒãã§ããé»åãåšæ³¢æ°ãç£èŠããæç·ç°å¢ãžã®ãŠãŒã¶ãŒã®ç¡ç·æ¥ç¶ãçµäºããŸãã ã¢ã¯ã»ã¹ãã€ã³ãã¯ãç¡ç·ã§ãã±ãããåä¿¡/éä¿¡ããç¡ç·ããŒã¿ãæå·åããã³ã³ãããŒã©ãŒãšéä¿¡ãããã³ãã«å ã®ãŠãŒã¶ãŒãã©ãã£ãã¯ãéä¿¡ããŸãã ããã«å€§èŠæš¡ãªãããã¯ãŒã¯ã§ã¯ãå°çšã®ã³ã³ãããŒã©ãŒããŒã«ç®¡çããŒã«ãã¢ããªãã£æ å ±ãµããŒããããã³é«åºŠãªèšºæããã³ã¬ããŒãããŒã«ã䜿çšãããŸãã
1.ãžã¥ãããŒãããã¯ãŒã¯ã¹ãæäŸãããã®
ãžã¥ãããŒãããã¯ãŒã¯ã¹ã®ã¯ã€ã€ã¬ã¹ã·ã¹ãã 補åã©ã€ã³ã¯ããŸãã«ãã®æ¹æ³ã§æ§ç¯ãããŠããŸãã
- ã¢ã¯ã»ã¹ãã€ã³ãWLA㯠ã1ã€ãŸãã¯2ã€ã®ç¡ç·ã¢ãžã¥ãŒã«ããµããŒããããç°ãªãæ°ã®MIMOã¹ããªãŒã ãæ倧é床ãå€éšã¢ã³ãããæ¥ç¶ããæ©èœãåãã5ã€ã®ããã€ã¹ã®ã»ããã§è¡šãããŸãã ãããã¯ãç æ¢ç¥åšãã®åœ¢ã§äœãããŠããããªãã£ã¹ã®å€©äºã«èšçœ®ããããã«èšèšãããŠããŸãã WLA632ïŒã¹ããªãŒãããŒãžã§ã³ïŒãé€ãã802.3af PoEãä»ããŠçµŠé»ãããŸãã ã³ã³ãœãŒã«ãã€ã³ã¿ãŒãã§ã€ã¹ããã¿ã³ãæ¥ç¶ããæ©èœã¯ãããŸããã
- ããŒããŠã§ã¢WLCã«ã¯5çš®é¡ã VMwareã«ã¯1 çš®é¡ã®ä»®æ³ããŒããŠã§ã¢ããããããã©ãŒãã³ã¹ïŒæäŸãããã¢ã¯ã»ã¹ãã€ã³ãã®æ°ïŒããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®æ°ãšé床ãããã³2çªç®ã®é»æºã®ååšãç°ãªããŸãã WLAãçŽæ¥æå¹ã«ããããã«èšèšãããå°åã®PoEã¹ã€ãããçµã¿èŸŒãŸããã¢ãã«ããããŸãã ã³ã³ãœãŒã«ããŒãããããã³ãã³ãã©ã€ã³ããèšå®ããŸãã
- GUIãä»ããŠã³ã³ãããŒã©ãŒã®ã»ãããå¶åŸ¡ããã«ã¯ã RingMasterãœãããŠã§ã¢ïŒJavaã¢ããªã±ãŒã·ã§ã³ïŒã䜿çšããŸããããã¯ãWindowsãŸãã¯å¥ã®WLM1200ããã€ã¹ïŒåäžãŠãããã³ã³ãã¥ãŒã¿ãŒïŒã§å®è¡ãããè¿œå ã®SmartPassã²ã¹ãã¢ã¯ã»ã¹ãœãããŠã§ã¢ãå®è¡ã§ããŸãã
2.ãã¹ããããã®
ç§ãèªç±ã«äœ¿ããã®ã¯ïŒ
- 1ã€ã®PSUãåããWLA-8ã³ã³ãããŒã©ãŒïŒå¥åMX-8ïŒ-2å
- ã¢ã¯ã»ã¹ãã€ã³ãWLA532-WW-2å
- SRX240H PoEãã¡ã€ã¢ãŠã©ãŒã«-ã¢ã¯ã»ã¹ãã€ã³ãã®é»æºãšããŠäœ¿çš
ãã®ã»ããã¯ãããŒã¿ããŒãã³ã°ããã©ãŒã«ããã¬ã©ã³ã¹ãå«ãã»ãšãã©ã®ãã¹ãã«ååã§ãã
ã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒã¯ãPowerPCãã©ãããã©ãŒã ã«åºã¥ãã·ã³ã°ã«ããŒãã®å°çšã³ã³ãã¥ãŒã¿ãŒã§ãããLinuxããŒã¹ã®MSSïŒMobility System SoftwareïŒãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããŒãžã§ã³8.0.2.2ãå®è¡ããŸãã WLA-8ã«ã¯ãã¢ã¯ã»ã¹ãã€ã³ããçŽæ¥å«ããããã«ãPoEããµããŒããã2ã€ã®ã¢ãããªã³ã¯ãš6ã€ã®ããŒãããããŸãã
ã¢ã¯ã»ã¹ãã€ã³ãã¯ã€ãŒãµãããã§é§åãããããŒã¯æã«çŽ15ã¯ãããæ¶è²»ããŸãã ãã®äžã«ããMSSå¿çéšããããŒããããã³ã³ãããŒã©ãŒããããŒããããŸãã ããã€ã¹èªäœã¯ééã®ããéå±ããŒã¹ïŒã©ãžãšãŒã¿ãŒã§ããããŸãïŒã«åãä»ãããã空éããŒã¿ã¹ããªãŒã ãäœæããããã«6ã€ã®ã¢ã³ããïŒb / g / nããã³a / nçšã«3ã€ïŒãåããŠããŸãã
å©çšå¯èœãªæ©åšã«åºã¥ããŠãã·ã¹ãã ã®åæåãåæã»ããã¢ããæé ã®åæãããã³ããã€ãã®å žåçãªåé¡ã®è§£æ±ºãè©Šã¿ãŸãã ã³ãã³ãã©ã€ã³ããã³ã³ãããŒã©ãŒãæ§æããŸããã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãããŸããããRingmasterããããŸãã ãããã«ãããããããæºå段éãå¿ èŠã§ãã
3.æºå段é
ç¹°ãè¿ããããããŸããã ããã¯ãèªãã§ãã ããã äœããå§ããåã«èªãã§ãã ããã ãã¡ããããæ¹æ³ã«æ²¿ã£ãŠãå€ãã®ããšãåŠã¶ããšãã§ããŸãããæãããªæãããç¹°ãè¿ããŠåãããšãäœåºŠãããçŽããªãããã«ã補é å ã®ããã¥ã¡ã³ããæåŸãŸã§èªãã§æéãç¯çŽããŠãã ããã ã¡ãŒã«ãŒã®ããã¥ã¡ã³ãã¯ãå®éã«ã¯1ã€ã®å€§ããªæ¬ã«ãŸãšããããŠããŸããããã¯ã Mobility System Software Configuration Guideã§ãã 1000ããŒãžã®åçŽãªããã¹ããèªãã®ãé¢åã§ã¯ãããŸããã
ããã¯ã¹ãéãåã«ã次ã®è³ªåã«å¯Ÿããåçãæºåããå¿ èŠããããŸãã
- èšçœ®ããã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ã®æ°ãèšçœ®å ŽæãLANããŒãã®æ¥ç¶å
- ã¢ã¯ã»ã¹ãã€ã³ãã¯ããã€ãããŸããïŒ ããããã³ã³ãããŒã©ãŒã®PoEããŒãã«æ¥ç¶ããããLANå ã®æ¢åã®PoEã¹ã€ããã«æ¥ç¶ããŸããïŒ
- TCP / IPã³ã³ãããŒã©ãŒïŒã¢ãã¬ã¹ãVLANçªå·ãDNSåïŒããã³ã¢ã¯ã»ã¹ãã€ã³ãã®ãã©ã¡ãŒã¿ãŒãšã¯
- å±éãããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ãã©ã¡ãŒã¿ãŒ-SSIDãæ¿èªæ¹æ³ãVLANãŠãŒã¶ãŒãã©ãã£ãã¯ãã©ãããããæ¹æ³ãªã©
- ãããã¯ãŒã¯äžã®RADIUSãµãŒããŒã§èªèšŒãååŸããŸããïŒ ãã¡ã€ã³ãéããŠïŒ LDAPçµç±ïŒ
- ãããã¯ãŒã¯ã®ç¡ç·ãã©ã¡ãŒã¿ã¯äœã§ãã-2.4ããã³/ãŸãã¯5 GHz垯åããã£ãã«
- 顧客ã®ããŒãã³ã°ãVoice over Radioã®ãµããŒããªã©ã®èŠä»¶ã¯äœã§ããã
3.ã³ã³ãããŒã©ãŒã®åæå
æåã®èµ·åæããŸãã¯quickstartã³ãã³ãã䜿çšãããšãã³ã³ãããŒã©ãŒã¯æ§æåæåã¢ãŒãã«å ¥ããŸããããã¯ã³ã³ãœãŒã«ããŒãïŒDB9ã9600 / 8 / N / 1ïŒãä»ããŠå¶åŸ¡ã§ããŸãã ããã€ãã®ç°¡åãªè³ªåã«çããå¿ èŠããããŸãã
WLC-1ïŒã¯ã€ãã¯ã¹ã¿ãŒã
ããã«ãããæ¢åã®æ§æãæ¶å»ãããŸãã ç¶è¡ããŸããïŒ [n]ïŒ y
次ã®è³ªåã«çããŠãã ããã ãïŒããå ¥åããŸã å©ããæ±ããŠã ^ãã¬ãŒã¯ã¢ãŠãããC
ã·ã¹ãã å[MX-8]ïŒ WLC-1
åœã³ãŒã[ç±³åœ]ïŒ RU ïŒ åœã³ãŒãã®éžæã«ãããã¢ã¯ã»ã¹ãã€ã³ãã®åäœåšæ³¢æ°ã®èš±å®¹ç¯å²ã決ãŸããŸã-å¿ é ãã©ã¡ãŒã¿ãŒ
ã·ã¹ãã IPã¢ãã¬ã¹[]ïŒ 172.16.130.30
ã·ã¹ãã IPã¢ãã¬ã¹ã®ããããã¹ã¯[]ïŒ 255.255.255.0
ããã©ã«ãã«ãŒã[]ïŒ 172.16.130.1
ããã©ã«ãVLANã§ã®æ¥ç¶ã«802.1Qã¿ã°ä»ãããŒãã䜿çšããå¿ èŠããããŸããïŒ [n]ïŒ n
Webview [y]ãæå¹ã«ããŸãã
管çè ãŠãŒã¶ãŒå[admin]ïŒ ã¢ã³ãã³
管çè ãã¹ã¯ãŒã[å¿ é ]ïŒ ****
æå¹åãã¹ã¯ãŒã[ãªãã·ã§ã³]ïŒ ****
æéãèšå®ããŸããïŒ [y]ïŒ
æ¥ä»ãå ¥åïŒdd / mm / yyïŒ[]ïŒ 03/06/13
æéãå ¥åããŠãã ããïŒhhïŒmmïŒssïŒ[]ïŒ 23:41:00
ã¿ã€ã ãŸãŒã³[]ãå ¥åïŒ MSK
hhïŒmm [0ïŒ0]ïŒ 4ïŒ0ã® 'MSK'ã®GMTããã®ãªãã»ããïŒDSTãªãïŒãå ¥åããŸã
ã¯ã€ã€ã¬ã¹ãæ§æããŸããïŒ [y]ïŒ y ïŒ ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãããã«ã»ããã¢ããããããã«æ±ããããŸã
䜿çšããã¯ãªã¢SSIDãå ¥åããŸãïŒ ssid1 ïŒ ããã¯ãWebãã©ãŒã ãä»ããèªèšŒã«ãããæ¥ç¶çšã«éãããæåã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã§ãã
WebããŒã¿ã«èªèšŒãå¿ èŠã§ããïŒ [y]ïŒ
Web Portalã§äœ¿çšãããŠãŒã¶ãŒåãå ¥åããŠãçµäºããŸãïŒ test
ãã¹ãçšã®ãã¹ã¯ãŒããå ¥åããŠãã ããïŒ ***
Web Portalã§äœ¿çšãããŠãŒã¶ãŒåãå ¥åããŠãçµäºããŸãã
802.1xããã³PEAP-MSCHAPv2ãå®è¡ããŸããïŒ [y]ïŒ
䜿çšããæå·SSIDãå ¥åããŸãïŒ ssid2 ïŒ ãã®2çªç®ã®ãããã¯ãŒã¯ãæ¥ç¶èš±å¯ä»ã
PEAP-MSCHAPv2ãå®è¡ããããã®ãŠãŒã¶ãŒåãå ¥åããŠçµäºããŸã ïŒ test2
test2ã®ãã¹ã¯ãŒããå ¥åããŠãã ããïŒ ***
PEAP-MSCHAPv2ãå®è¡ããããã®ãŠãŒã¶ãŒåãå ¥åããŠçµäºããŸãã
ã¢ã¯ã»ã¹ãã€ã³ããèšå®ããŸããïŒ [y] ïŒïŒ ããã§ãããŒã«ã«ã¢ã¯ã»ã¹ãã€ã³ããããã«èšå®ããããã«æ±ããããŸã
APãååšããããŒãçªå·[1-6]ãå ¥åããŠãçµäºããŸãïŒ 5 ïŒ ã³ã³ãããŒã©ãŒã®ã©ã®ããŒãããã€ã³ãã«æ¥ç¶ãããŠããã
ããŒã5ã§APã¢ãã«ãå ¥åïŒ WLA532-WW
APãååšããããŒãçªå·[1-6]ãå ¥åããŠãçµäºããŸãã
åæ£ã¢ã¯ã»ã¹ãã€ã³ããæ§æããŸããïŒ [y]ïŒ n ïŒ ããã§ã¯ãLANã«æ¥ç¶ãããã¢ã¯ã»ã¹ãã€ã³ããèšå®ããããã«æ±ããããŸããããã¯åŸã§è¡ããŸã
æåïŒsshã®ããŒãã¢ãäœæ
successïŒãsave configããšå ¥åããŠæ§æãä¿åããŸã
æåïŒå€æŽãåãå ¥ããããŸããã
* WLC-1ïŒ èšå®ãä¿å
æåïŒèšå®ãä¿åãããŸããã
WLC-1ïŒ
ããã€ã¹åã®åã®ã * ãã¯ãçŸåšã®æ§æã«æªä¿åã®å€æŽãããããšãæå³ããŸãã
ãã®ãããªãåºæ¬ã»ããã¢ãããã®åŸãã³ã³ãããŒã©ãŒã¯æ©èœããã¢ã¯ã»ã¹ãã€ã³ããæ©èœãããŠãŒã¶ãŒã¯ïŒssid1ããã³ssid2ãããã¯ãŒã¯çµç±ã§ïŒæ¥ç¶ã§ããŸãã é©ããããšã«ãã³ã³ãããŒã©ã«çŽæ¥æ¥ç¶ãããã¢ã¯ã»ã¹ãã€ã³ãã¯ãIPã¢ãã¬ã¹ãå²ãåœãŠãã«æ©èœããŸãïŒç¬èªã®IPã¢ãã¬ã¹ãèšå®ãããŸãïŒã
ã³ã³ãããŒã©ãŒã®èšå®ã¯éåžžã«ç°¡åã§ãã ã€ããŒãã«ã¢ãŒããéå§ãããšã set ã clear ã showã® 3çš®é¡ã®ã³ãã³ãããããŸãã JunOSã®ããã«ãã³ãããæäœããããŸããã
åæã»ããã¢ãããŠã£ã¶ãŒãã®å®äºåŸããã«ãè¿œå ã®ãã©ã¡ãŒã¿ãŒã»ãããèšå®ããããšããå§ãããŸãïŒãã¡ã€ã³åãšDNSãµãŒããŒã¢ãã¬ã¹ãsyslogãµãŒããŒã¢ãã¬ã¹ãNTPãSNMPãæå¹ã«ããŠã³ãã¥ããã£ãã€ã³ã¹ããŒã«ããã¢ããªãã£ãã¡ã€ã³åïŒè€æ°ã®ã³ã³ãããŒã©ãŒãããå Žåã¯ããŒãã³ã°çšïŒãšã¢ãã¬ã¹ãèšå®ããŸãã¢ããªãã£ã°ã«ãŒãã®åæããã€ã¹ïŒã·ãŒãïŒã
4.ã¢ã¯ã»ã¹ãã€ã³ãã®æ¥ç¶
çŽ æŽããããã³ã³ãããŒã©ãŒãæ§æãããsshãä»ããŠCLIã«ç§»åããŸãïŒããŒã«ã«ã³ã³ãœãŒã«ã¯å¿ èŠãªããªããŸããïŒã
ã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ãã€ã³ãã¯ãããŒã«ã«ã¢ãŒãïŒã³ã³ãããŒã©ãŒããŒãïŒãŸãã¯åæ£ã¢ãŒãïŒIPçµç±ïŒã§æ¥ç¶ãããŸãã 2çªç®ã®ã±ãŒã¹ã§ã¯ãDHCPãµãŒããŒããããã¯ãŒã¯äžã§æ§æããå¿ èŠããããŸããDHCPãµãŒããŒã¯ãã¢ãã¬ã¹ã«å ããŠããªãã·ã§ã³43ãã³ã³ãããŒã©ãŒã®ã¢ãã¬ã¹ãšãšãã«æäŸããŸãïŒãã®åœ¢åŒã¯ãã·ã¹ã³ã®ãã®ãšã¯ç°ãªããŸãããç¬èªã®ãã®ã§ãïŒã ããã®ãŸãŸãã¢ã¯ã»ã¹ãã€ã³ããèšå®ããã¿ã¹ã¯ã容æã«ããããã«ïŒã³ã³ãœãŒã«ããŒããšãã¿ã³ããªãããšãæãåºããŠãã ããïŒãæ¥ç¶ãèŠæ±ããŠããããã€ã¹ããããã¯ã¢ããã ããset ap auto mode enableã³ãã³ãããããŸãã ãæçŽãïŒã±ãŒã¹ã®ã¹ããã«ãŒã«èšèŒãããŠããïŒã䜿çšããŠããã€ã³ãèšå®ãæåã§èšå®ããããšãã§ããŸãã
set ap 2 serial-id mg0211508096ã¢ãã«WLA532-WW
ap 2 name WLA-2ãèšå®ããŸã
ap 2ç¹æ» ãæå¹ã«ãã
ap 2æçŽãèšå®1aïŒfbïŒ2eïŒd2ïŒabïŒe0ïŒ59ïŒ87ïŒa7ïŒ3cïŒ2aïŒ20ïŒecïŒ2aïŒ9bïŒcc
AP 2ç¡ç·1ã¢ãŒããæå¹ã«ããŸã
AP 2ç¡ç·2ã¢ãŒããæå¹ã«ããŸã
èªåçã«èšå®ãããã¢ã¯ã»ã¹ãã€ã³ãã¯ãåŸã§ååãå€æŽããŠçªå·ãå€æŽã§ããŸãã æ¥ç¶ãããŠããã¢ã¯ã»ã¹ãã€ã³ãã®ãªã¹ãã確èªã§ããŸãã
WLC-1ïŒ show ap status
ãã©ã°ïŒo =æäœå¯èœ[1]ãc =æ§æ[0]ãd =ããŠã³ããŒã[0]ãb =ããŒã[0] a =èªåAPãm =ã¡ãã·ã¥APãp / P =ã¡ãã·ã¥ããŒã¿ã«ïŒena / actvïŒãr =åé·[0] z =åæ¢äžã®ãªã¢ãŒãAPãi / I =å®å šã§ãªãïŒå¶åŸ¡/å¶åŸ¡+ããŒã¿ïŒ u =æå·åãããŠããªããe / E =æå·åãããŠããïŒå¶åŸ¡/å¶åŸ¡+ããŒã¿ïŒ ç¡ç·ïŒE =æå¹-20MHzãã£ãã«ãS =æ©ryãs =ã¹ãã¯ãã«ããŒã¿ W / w =æå¹-40MHzã¯ã€ããã£ãã«ïŒHTplus / HTminusïŒ D =管çãç¡å¹ãU =ã¡ãã·ã¥ã¢ãããªã³ã¯ IPã¢ãã¬ã¹ïŒ* = NATã®èåŸã®AP APãã©ã°IPã¢ãã¬ã¹ã¢ãã«MACã¢ãã¬ã¹ç¡ç·1ç¡ç·2ã¢ããã¿ã€ã ---- ---- --------------- ------------ --------------- -------- ------- ------ 5 o-uããŒã5 WLA532-WW 78ïŒ19ïŒf7ïŒ7cïŒ6aïŒ40 E 11/13 w112 / 18 02h34m 2 o-e 172.16.130.110 WLA532-WW 78ïŒ19ïŒf7ïŒ75ïŒ5fïŒ80 E 6/13 w136 / 21 02h30m
5.ãµãŒãã¹ãããã¡ã€ã«ã®æ§æ
ç¡ç·ãæ©èœãããããç¡ç·ãããã¯ãŒã¯ïŒSSIDïŒã決å®ããå¿ èŠããããŸãã 圌女ã®ååãæå·åãã©ã¡ãŒã¿ãŒãèš±å¯ãæå®ããå¿ èŠããããŸãã
ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess ssid-name WiFiAccessãèšå®ããŸãã ããªãã®ãããã¯ãŒã¯å
ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess auth-fallthruã©ã¹ããªãŸãŒããèšå®ããŸãã
ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess psk-phrase 12345678ãèšå®ããŸãã ãã¹ã¯ãŒãïŒããŒïŒ-æ§æãã¡ã€ã«ã§æå·åãããŸã
ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess wpa-ie auth-dot1x disableãèšå®ããŸãã 802.1xã䜿çšããªãïŒRADIUSãµãŒããŒçµç±ïŒ
ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess rsn-ie cipher-ccmp enableãèšå®ããŸãã AES / CCMPãå¥åWPA2
ãµãŒãã¹ãããã¡ã€ã«ã®èšå®sp-WiFiAccess rsn-ie auth-psk enable
ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess rsn-ie auth-dot1x disableãèšå®ããŸã
ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess rsn-ieãæå¹ã«ãã
ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess attr vlan-name defaultãèšå®ããŸã ã ã¯ã©ã€ã¢ã³ããé 眮ãããããã¯ãŒã¯ïŒVLANïŒ
å¯èœãªãªãã·ã§ã³ã¯ãã¹ãŠããã¥ã¡ã³ãã«èšèŒãããŠããŸãã è€æ°ã®ã³ã³ãããŒã©ã§åããããã¯ãŒã¯ïŒãã¡ããåãèšå®ïŒã䜿çšããå ŽåããµãŒãã¹ãããã¡ã€ã«ã»ã°ã¡ã³ããšç¡ç·ãããã¡ã€ã«ã»ã°ã¡ã³ãããä¹ç®ãããå¿ èŠããããŸãã
6.ç¡ç·ãããã¡ã€ã«ãæ§æãã
次ã«ãç¡ç·èšå®ãèšå®ããå¿ èŠããããŸã-åšæ³¢æ°ãã£ã³ãã«ãç¯å²ã決å®ããŸãã ããã©ã«ãã®èšå®ã§ååã«éå§ã§ããããã¥ã¡ã³ãã§ã¯ãã䟿å©ã§ãã
ç¡ç·ãããã¡ã€ã«ã®ããã©ã«ãèšå®auto-tune power-config enable
次ã«ããµãŒãã¹ãããã¡ã€ã«ãç¡ç·ãããã¡ã€ã«ã«é©çšããå¿ èŠããããŸãã
ç¡ç·ãããã¡ã€ã«ã®ããã©ã«ãã®ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccessãèšå®ããŸã
ãã¹ã¯ãŒã12345678㧠WiFiAccessã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ïŒWPA2-PSKïŒãžã®ã¯ã©ã€ã¢ã³ãæ¥ç¶ãè©Šè¡ããŸãã
WLC-1ïŒ ã»ãã·ã§ã³ã»ãã·ã§ã³ãããã¯ãŒã¯ã瀺ããŠäžãã
ãŠãŒã¶ãŒåSessIDã¿ã€ãã¢ãã¬ã¹VLAN AP / Rdo --------------------- ------ ----- ------------------ --------------- ------- LR-WiFiAccess-0 2 *ãªãŒãã³172.16.130.112ããã©ã«ã5/2
ããŸãããïŒ
å®å
šãªã³ã³ãããŒã©ãŒæ§æã¯æ¬¡ã®ãšããã§ã
set ip route default 172.16.130.1 1 set ip dns domain k18.netams.com set ip dns enable set ip dns server 8.8.8.8ãã©ã€ã㪠ãã°ãµãŒããŒã®èšå®172.16.130.100é倧床ãšã©ãŒ ã·ã¹ãã åWLC-1ãèšå®ããŸã set system ip-address 172.16.130.30 ã·ã¹ãã ã®åœã³ãŒãRUãèšå®ããŸã ã¿ã€ã ãŸãŒã³MSK 4 0ãèšå® ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccessã®èšå®ssid-name WiFiAccess ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess auth-fallthruã©ã¹ããªãŸãŒããèšå®ããŸãã ãµãŒãã¹ãããã¡ã€ã«ãèšå®ããŸãsp-WiFiAccess keep-initial-vlan enable ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess psk-encrypted fffffffffffffffffffffffffãèšå®ãã ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess wpa-ie auth-dot1xãç¡å¹ã«èšå® ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess rsn-ie cipher-ccmp enableãèšå®ããŸã ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess rsn-ie cipher-tkip enableãèšå®ããŸã ãµãŒãã¹ãããã¡ã€ã«ã®èšå®sp-WiFiAccess rsn-ie auth-psk enable ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess rsn-ie auth-dot1x disableãèšå®ããŸã ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess rsn-ieãæå¹ã«ãã ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccess attr vlan-name defaultãèšå®ããŸã enablepassãã¹ã¯ãŒããèšå®ããŸãfffffffffffffffffffffff ç¡ç·ãããã¡ã€ã«ã®ããã©ã«ãèšå®auto-tune power-config enable ç¡ç·ãããã¡ã€ã«ã®ããã©ã«ããèšå®ããŸã11n channel-width-na 20MHz ç¡ç·ãããã¡ã€ã«ã®ããã©ã«ãã®ãµãŒãã¹ãããã¡ã€ã«sp-WiFiAccessãèšå®ããŸã apèªåã¢ãŒããæå¹ã«ããŸã set ap 2 serial-id mg0211508096ã¢ãã«WLA532-WW ap 2 name WLA-2ãèšå®ããŸã ap 2ç¹æ» ãæå¹ã«ãã ap 2æçŽãèšå®1aïŒfbïŒ2eïŒd2ïŒabïŒe0ïŒ59ïŒ87ïŒa7ïŒ3cïŒ2aïŒ20ïŒecïŒ2aïŒ9bïŒcc AP 2ç¡ç·1ã¢ãŒããæå¹ã«ããŸã AP 2ç¡ç·2ã¢ãŒããæå¹ã«ããŸã AP 5ããŒã5ã¢ãã«WLA532-WWãèšå® AP 5ç¡ç·1ã¢ãŒããæå¹ã«ããŸã AP 5ç¡ç·2ã¢ãŒããæå¹ã«ããŸã ip snmp server enableãèšå®ããŸã ããŒãpoe 5ãæå¹ã«èšå® SNMPãããã³ã«v1ãç¡å¹ã«ãã SNMPãããã³ã«v2cãæå¹ã«ãã VLAN 1ããŒã1ãèšå® VLAN 1ããŒã2ãèšå® VLAN 1ããŒã3ãèšå® VLAN 1ããŒã4ãèšå® VLAN 1ããŒã6ãèšå® VLAN 1ããŒã7ãèšå® VLAN 1ããŒã8ãèšå® ã€ã³ã¿ãŒãã§ã€ã¹1ã®èšå®ip 172.16.130.30 255.255.255.0 snmpã³ãã¥ããã£åCommunityROã¢ã¯ã»ã¹ãèªã¿åãå°çšã«èšå®ããŸã ã¢ããªãã£ãã¡ã€ã³ã¢ãŒãã·ãŒããã¡ã€ã³åLocalMobilityDomainãèšå®ããŸã ã¢ããªãã£ãã¡ã€ã³ã¡ã³ããŒ172.16.130.31ãèšå®ããŸã ã»ãã¥ãªãã£ACLãèšå®ããŸãportalacl permit udp 0.0.0.0 255.255.255.255 eq 68 0.0.0.0 255.255.255.255 eq 67 ã»ãã¥ãªãã£ACLåãèšå®ããŸãportalacl deny 0.0.0.0 255.255.255.255 capture ã»ãã¥ãªãã£acl portalaclãã³ããããã ntpãæå¹ã«ãã ntpãµãŒããŒãèšå®83.143.51.50
7. 802.1xã«ããæ¿èª
äŒæ¥ã§äœ¿çšããå Žåãæ¿èªã¯WPA2-PSKããå®å šã§ã¯ãããŸãããWPA2-PSKã¯ã1ã€ã®æ¢ç¥ã®ããŒïŒãã¹ã¯ãŒãïŒã§ä¿è·ãããŠããŸããã802.1xãããã³ã«ãä»ããŠRADIUSãµãŒããŒãšå€éšããŒã¿ããŒã¹ã䜿çšããŠæ¬æ Œçã§ãã ãã®ãããFreeRADIUSã䜿çšããŸããããã¯ãNETAMS 4.0課éã·ã¹ãã ãšé£åããŸã ã
ãµãŒãã¹ãããã¡ã€ã«Secure-DOT1Xã®èšå®ssid-name DOT1X ãµãŒãã¹ãããã¡ã€ã«Secure-DOT1X 11n short-guard-interval disableãèšå®ããŸã ãµãŒãã¹ãããã¡ã€ã«ãèšå®Secure-DOT1X rsn-ie cipher-ccmp enable ãµãŒãã¹ãããã¡ã€ã«Secure-DOT1X rsn-ieãæå¹ã«ãã service-profile Secure-DOT1X attr vlan-name defaultãèšå®ããŸã RADIUSãµãŒããŒã®èšå®debian64ã¢ãã¬ã¹172.16.130.13ã¿ã€ã ã¢ãŠã5åéä¿¡3ãããã¿ã€ã 5æå·åããŒ0832494d1b1c11 radius server debian64 mac-addr-formatã³ãã³ãèšå®ããŸã ç¡ç·ãããã¡ã€ã«ã®ããã©ã«ãã®ãµãŒãã¹ãããã¡ã€ã«Secure-DOT1Xãèšå®ãã ãµãŒããŒã°ã«ãŒãdebian64-groupã¡ã³ããŒdebian64ãèšå®ããŸã ã¢ã«ãŠã³ãã£ã³ã°dot1x ssid DOT1Xãèšå®** start-stop debian64-group èªèšŒdot1x ssid DOT1Xãèšå®**ãã¹ã¹ã«ãŒdebian64-group
ãµãŒãã¹ã®æå¹ãªãµãã¹ã¯ãªãã·ã§ã³ã䜿çšããŠèª²éã·ã¹ãã ã§èª²éããããŠãŒã¶ãŒã¯ãæ£ããåå¥ã®ãã°ã€ã³ãã¹ã¯ãŒããå ¥åããããšã§æ£åžžã«æ¥ç¶ããŸãã
8.ãŸãšã
ãã¹ãããæ©åšã®å šäœçãªå°è±¡ã¯è¯å¥œãªãŸãŸã§ããã ããŒãã³ã°ãšãã©ãŒã«ããã¬ã©ã³ã¹ã¯äžæçã«è¹å€ã«æ®ãããŸããã ä¿¡é Œæ§ãã°ãªããã¬ã¹ã®èŠ³ç¹ãã-äžæºã¯ãããŸããã CLIãä»ãããã¥ãŒãã³ã°ãšèšºæã®å©äŸ¿æ§ã«ã¯çåããããŸããããã®å©ç¹ïŒã³ããŒã¢ã³ãããŒã¹ãïŒã¯ãããŸãã æ©èœé¢ã§ã¯ããžã¥ãããŒã®ã¯ã€ã€ã¬ã¹ã·ã¹ãã ã¯ã倧èŠæš¡ã§è€éãªã·ã¹ãã ãæ§ç¯ããããã«å¿ èŠãªãã¹ãŠãæäŸããŸãã äž»èŠãªç«¶åä»ç€Ÿã§ããCisco Unified Wirelessãšæ¯èŒãããšã现éšãŸã§ãæ©èœãšæ©èœã¯åãã§ãã åããšã³ãã£ãã£ïŒWLA-ã¢ã¯ã»ã¹ãã€ã³ãããµãŒãã¹ãããã¡ã€ã«-WLANããªã¢ãŒãWLA-FlexConnectïŒã®åœåã«ã¯å€§ããªéãããããŸãããããã¯ç¿æ £ã®åé¡ã§ãã ãããã«ãããäž¡æ¹ã®ã·ã¹ãã ã¯åãæšæºãšãããã³ã«ã«åºã¥ããŠãããçµç¹ã®äžè¬çãªããžãã¯ãä¿æããŠããŸãã
æ®å¿µãªãããã³ãã³ãã©ã€ã³ïŒãã¹ãŠã®æ©èœãå©çšå¯èœïŒãä»ããŠã¯ã€ã€ã¬ã¹ã·ã¹ãã ãå¶åŸ¡ããããšã¯å¯èœã§ããã䟿å©ã§ã¯ãããŸããïŒwebdanolã®æ代ã§ã¯ããŠãŒã¶ãŒã ãã§ãªã管çè ãçŸããGUIãæããŠããŸãïŒã 幞ããªããšã«ããžã¥ãããŒãããã¯ãŒã¯ã¹ã¯ãäžé£ã®ã³ã³ãããŒã©ãŒãäžå 管çããããã®ã°ã©ãã£ã«ã«ã·ã¹ãã RingMasterãæäŸããŠããŸããããã«ã€ããŠã¯ãä»åŸã®èšäºã§èª¬æããŸãã
PSèè ã¯ãããŸããŸãªã¡ãŒã«ãŒã®æ©åšã«åºã¥ããã·ã¹ãã ã®èšèšãšçµ±åã«æºãã£ãŠããŸãããããããšã¯ææºããŠããŸããã