- Table of Contents
-
- H3C Access Controllers and Access Points Configuration Examples(V7)-6W101
- 00-Preface
- 01-H3C Access Controllers AP's Association with the AC at Layer 2 Configuration Examples
- 02-H3C Access Controllers Comware 7 AP's Association with the AC at Layer 2 (IPv6) Configuration Examples
- 03-H3C Access Controllers AP's Association with the AC at Layer 3 Configuration Examples
- 04-H3C Access Controllers Comware 7 AP's Association with the AC at Layer 3 (IPv6) Configuration Examples
- 05-H3C Access Controllers Local MAC Authentication Configuration Examples (V7)
- 06-H3C Access Controllers MAC Authentication with Guest VLAN Assignment Configuration Examples (V7)
- 07-H3C Access Controllers Comware 7 MAC Authentication with Guest VLAN Assignment (IPv6) Configuration Examples
- 08-H3C Access Controllers MAC Authentication and PSK Authentication Configuration Examples (V7)
- 09-H3C Access Controllers Auto AP Configuration Examples (V7)
- 10-H3C Access Controllers WLAN Load Balancing Configuration Examples (V7)
- 11-H3C Access Controllers WEP Encryption Configuration Examples
- 12-H3C Access Controllers Local Forwarding Configuration Examples
- 13-H3C Access Controllers Layer 2 Static Aggregation Configuration Examples (V7)
- 14-H3C Access Controllers Remote 802.1X Authentication Configuration Examples (V7)
- 15-H3C Access Controllers Comware 7 Remote 802.1X Authentication (IPv6) Configuration Examples
- 16-H3C Access Controllers 802.1X Authentication with ACL Assignment Through IMC Server @CE@ (V7)
- 17-H3C Access Controllers 802.1X Authentication with User Profile Assignment Through IMC Server @CE@ (V7)
- 18-H3C Access Controllers EAD Authentication Configuration Examples (V7)
- 19-H3C Access Controllers Comware 7 EAD Authentication (IPv6) Configuration Examples
- 20-H3C Access Controllers Remote Portal Authenticaiton Configuration Examples (V7)
- 21-H3C Access Controllers Comware 7 Remote Portal Authenticaiton (IPv6) Configuration Examples
- 22-H3C Access Controllers Local Portal Authentication Configuration Examples (V7)
- 23-H3C Access Controllers Comware 7 Local Portal Authentication (IPv6) Configuration Examples
- 24-H3C Access Controllers Local Forwarding Mode Direct Portal Authentication Configuration Examples (V7)
- 25-H3C Access Controllers Local Forwarding Mode Direct Portal Authentication (IPv6) Configuration Examples(V7)
- 26-H3C Access Controllers Local Portal Authentication through LDAP Server Configuration Examples (V7)
- 27-H3C Access Controllers Local Portal Authentication through LDAP Server (IPv6) Configuration Examples(V7)
- 28-H3C Access Controllers MAC-based Portal Quick Authenticaiton Configuration Example (V7)
- 29-H3C Access Controllers Comware 7 MAC-based Quick Portal Authenticaiton (IPv6) Configuration Example
- 30-H3C Access Controllers SSH Configuration Examples (7)
- 31-H3C Access Controllers Internal-to-External Access Through NAT Configuration Examples (V7)
- 32-H3C Access Controllers Static Blacklist Configuration Examples
- 33-H3C Access Controllers Comware 7 WLAN Access (IPv6) Configuration Examples
- 34-H3C Access Controllers Inter-AC Roaming Configuration Examples (V7)
- 35-H3C Access Controllers Comware 7 Inter-AC Roaming (IPv6) Configuration Examples
- 36-H3C Access Controllers HTTPS Login Configuration Examples (V7)
- 37-H3C Access Controllers Client Rate Limiting Configuration Examples (V7)
- 38-H3C Access Controllers Client Quantity Control Configuration Examples
- 39-H3C Access Controllers Medical RFID Tag Management Configuration Examples (V7)
- 40-H3C Access Controllers iBeacon Management Configuration Examples (V7)
- 41-H3C Access Controllers Remote AP Configuration Examples (V7)
- 42-H3C Access Controllers PSK Encryption Configuration Examples
- 43-H3C Access Controllers WIPS Configuration Examples (V7)
- 44-H3C Access Controllers Layer 2 Multicast Configuration Example (V7)
- 45-H3C Access Controllers IRF Setup with Members Directly Connected Configuration Examples (V7)
- 46-H3C Access Controllers IRF Setup with Members Not Directly Connected Configuration Examples (V7)
- 47-H3C Access Controller Modules IRF Setup with Members in One Chassis Configuration Examples (V7)
- 48-H3C Access Controller Modules IRF Setup with Members in Different Chassis Configuration Examples (V7)
- 49-H3C Access Controllers Comware 7 IP Source Guard (IPv6) Configuration Examples
- 50-Policy-Based Forwarding with Dual Gateways Configuration Example
- 51-H3C Access Controllers Comware 7 Policy-Based Forwarding with Dual Gateways (IPv6) Configuration Example
- 52-Policy-Based Local Forwarding Configuration Examples
- Related Documents
-
Title | Size | Download |
---|---|---|
52-Policy-Based Local Forwarding Configuration Examples | 56.77 KB |
|
Policy-Based Local Forwarding |
Configuration Examples |
|
Copyright © 2019 New H3C Technologies Co., Ltd. All rights reserved.
No part of this manual may be reproduced or transmitted in any form or by any means without prior written consent of New H3C Technologies Co., Ltd.
Except for the trademarks of New H3C Technologies Co., Ltd., any trademarks that may be mentioned in this document are the property of their respective owners.
The information in this document is subject to change without notice.
Introduction
This document provides a configuration example for configuring policy-based local forwarding.
Prerequisites
This document applies to Comware 7-based access controllers and access points. Procedures and information in the examples might be slightly different depending on the software or hardware version of the access controllers and access points.
The configuration examples were created and verified in a lab environment, and all the devices were started with the factory default configuration. When you are working on a live network, make sure you understand the potential impact of every command on your network.
The following information is provided based on the assumption that you have basic knowledge of WLAN access and OpenFlow.
Example: Configuring policy-based local forwarding
Network configuration
As shown in Figure 1, the AC acts as the DHCP server to assign IP addresses to the AP and client. Configure ACL to perform local forwarding for clients matching the specified ACL rule.
Procedures
1. Configure VLANs:
# Create VLAN 100 and VLAN-interface 100, and assign an IP address to the VLAN interface. APs will use this IP address to establish CAPWAP tunnels with the AC.
<AC> system-view
[AC] vlan 100
[AC-vlan100] quit
[AC] interface vlan-interface 100
[AC-Vlan-interface100] ip address 192.168.0.100 16
[AC-Vlan-interface100] quit
# Create VLAN 200.
[AC] vlan 200
[AC-vlan200] quit
2. Configure DHCP:
# Enable DHCP.
[AC] dhcp enable
# Create DHCP address pool vlan100, specify the subnet for dynamic allocation as 192.168.0.0/24, and specify the gateway address as 192.168.0.100.
[AC] dhcp server ip-pool vlan100
[AC-dhcp-pool-vlan100] network 192.168.0.0 mask 255.255.255.0
[AC-dhcp-pool-vlan100] gateway-list 192.168.0.100
[AC-dhcp-pool-vlan100] quit
# Create DHCP address pool vlan200, specify the subnet for dynamic allocation as 192.168.1.0/24, and specify the gateway address as 192.168.1.100.
[AC] dhcp server ip-pool vlan200
[AC-dhcp-pool-vlan200] network 192.168.1.0 mask 255.255.255.0
[AC-dhcp-pool-vlan200] gateway-list 192.168.1.100
[AC-dhcp-pool-vlan200] quit
3. Configure policy-based forwarding:
# Create IPv4 basic ACL 2000, and configure an ACL rule to permit matching packets.
[AC] acl basic 2000
[AC-acl-ipv4-basic-2000] rule permit
[AC-acl-ipv4-basic-2000] quit
# Create forwarding policy policy1, and configure the forwarding policy to locally forward packets that match ACL 2000.
[AC] wlan forwarding-policy policy1
[AC-wlan-fp-policy1] classifier acl 2000 behavior local
[AC-wlan-fp-policy1] quit
# Create service template service1, and set the SSID to service1.
[AC] wlan service-template service1
[AC-wlan-st-service1] ssid service1
# Assign clients to join VLAN 200 after coming online through the service template.
[AC-wlan-st-service1] vlan 200
# Apply forwarding policy policy1 to the service template.
[AC-wlan-st-service1] client forwarding-policy-name policy1
# Enable policy-based forwarding.
[AC-wlan-st-service1] client forwarding-policy enable
# Enable the service template.
[AC-wlan-st-service1] service-template enable
[AC-wlan-st-service1] quit
4. Configure a manual AP:
# Create AP ap1 and specify its serial ID.
[AC] wlan ap ap1 model WA560-WW
[AC-wlan-ap-ap1] serial-id 219801A1NM8182032235
# Bind service template service1 to radio 1 and enable radio 1.
[AC-wlan-ap-ap1-radio-1] radio enable
[AC-wlan-ap-ap1-radio-1] service-template service1
[AC-wlan-ap-ap1-radio-1] quit
[AC-wlan-ap-ap1] quit
Verifying the configuration
# Display connected controllers' flow entries and verify that the output interface is in Normal status, which indicates that the forwarding policy is issued to APs through OpenFlow.
[AC] display openflow-controller flow-table
Datapath ID: 0x1005741f4acb9520
Table 0 information:
total flow entry count: 0
Datapath ID: 0x1004741f4acb9520
Table 10 information:
total flow entry count: 0
Table 11 information:
total flow entry count: 0
Table 20 information:
total flow entry count: 0
Table 21 information:
total flow entry count: 0
Table 30 information:
total flow entry count: 0
Table 40 information:
total flow entry count: 1
Flow entry information:
cookie: 0x114047d000000001, priority: 65535, hard time: 0, idle time: 0,
flags: flow_send_rem
Match information:
Ethernet source MAC address: 64b0-a6c6-c25a
Ethernet source MAC address mask: ffff-ffff-ffff
Ethernet type: 0x0800
Experimenter:
In-BSSID: 741f-4acb-9520
Instruction information:
Write actions:
Output interface: Normal
Configuration files
#
dhcp enable
#
vlan 100
#
vlan 200
#
dhcp server ip-pool vlan100
gateway-list 192.168.0.100
network 192.168.0.0 mask 255.255.255.0
#
dhcp server ip-pool vlan200
gateway-list 192.168.1.100
network 192.168.1.0 mask 255.255.255.0
#
wlan forwarding-policy policy1
classifier acl 2000 behavior local
#
wlan service-template service1
ssid service1
vlan 200
client forwarding-policy-name policy1
client forwarding-policy enable
service-template enable
#
interface Vlan-interface100
ip address 192.168.0.100 255.255.255.0
#
acl basic 2000
rule 0 permit
#
wlan ap ap1 model WA560-WW
serial-id 219801A1NM8182032235
radio 1
radio enable
service-template service1
#
Related documentation
· WLAN Command Reference in H3C Access Controllers Command References
· WLAN Configuration Guide in H3C Access Controllers Configuration Guides