04
Golden config รายชุด
ค่าจริงของแต่ละชุดแทนไว้แล้ว — เลือกชุดของตัวเอง กดคัดลอก แล้ววางลง CLI ได้เลย
POD 1
POD 2
POD 3
POD 4
POD 5
POD 6
POD 7
TEACHER
Controller MGMT 192.168.10.221 AP VLAN 2601 Subnet 10.26.1.0/24 Gateway / SVI 10.26.1.1 ช่วงที่แจก .11 – .240
คัดลอก ! POD 1 · Mobility Controller (VM) · ArubaOS 8.7.1.2
! Controller MGMT : 192.168.10.221 AP VLAN : 2601 Subnet : 10.26.1.0/24
configure terminal
vlan 2601
!
interface vlan 2601
description "POD 1 - Student AP VLAN"
ip address 10.26.1.1 255.255.255.0
ip nat inside
operstate up
!
ip dhcp excluded-address 10.26.1.1 10.26.1.10
ip dhcp excluded-address 10.26.1.241 10.26.1.254
!
ip dhcp pool POOL-VLAN2601
network 10.26.1.0 255.255.255.0
default-router 10.26.1.1
dns-server 8.8.8.8 1.1.1.1
domain-name lab.local
lease 0 8 0
!
service dhcp
write memory
Controller MGMT 192.168.10.222 AP VLAN 2602 Subnet 10.26.2.0/24 Gateway / SVI 10.26.2.1 ช่วงที่แจก .11 – .240
คัดลอก ! POD 2 · Mobility Controller (VM) · ArubaOS 8.7.1.2
! Controller MGMT : 192.168.10.222 AP VLAN : 2602 Subnet : 10.26.2.0/24
configure terminal
vlan 2602
!
interface vlan 2602
description "POD 2 - Student AP VLAN"
ip address 10.26.2.1 255.255.255.0
ip nat inside
operstate up
!
ip dhcp excluded-address 10.26.2.1 10.26.2.10
ip dhcp excluded-address 10.26.2.241 10.26.2.254
!
ip dhcp pool POOL-VLAN2602
network 10.26.2.0 255.255.255.0
default-router 10.26.2.1
dns-server 8.8.8.8 1.1.1.1
domain-name lab.local
lease 0 8 0
!
service dhcp
write memory
Controller MGMT 192.168.10.223 AP VLAN 2603 Subnet 10.26.3.0/24 Gateway / SVI 10.26.3.1 ช่วงที่แจก .11 – .240
คัดลอก ! POD 3 · Mobility Controller (VM) · ArubaOS 8.7.1.2
! Controller MGMT : 192.168.10.223 AP VLAN : 2603 Subnet : 10.26.3.0/24
configure terminal
vlan 2603
!
interface vlan 2603
description "POD 3 - Student AP VLAN"
ip address 10.26.3.1 255.255.255.0
ip nat inside
operstate up
!
ip dhcp excluded-address 10.26.3.1 10.26.3.10
ip dhcp excluded-address 10.26.3.241 10.26.3.254
!
ip dhcp pool POOL-VLAN2603
network 10.26.3.0 255.255.255.0
default-router 10.26.3.1
dns-server 8.8.8.8 1.1.1.1
domain-name lab.local
lease 0 8 0
!
service dhcp
write memory
Controller MGMT 192.168.10.224 AP VLAN 2604 Subnet 10.26.4.0/24 Gateway / SVI 10.26.4.1 ช่วงที่แจก .11 – .240
คัดลอก ! POD 4 · Mobility Controller (VM) · ArubaOS 8.7.1.2
! Controller MGMT : 192.168.10.224 AP VLAN : 2604 Subnet : 10.26.4.0/24
configure terminal
vlan 2604
!
interface vlan 2604
description "POD 4 - Student AP VLAN"
ip address 10.26.4.1 255.255.255.0
ip nat inside
operstate up
!
ip dhcp excluded-address 10.26.4.1 10.26.4.10
ip dhcp excluded-address 10.26.4.241 10.26.4.254
!
ip dhcp pool POOL-VLAN2604
network 10.26.4.0 255.255.255.0
default-router 10.26.4.1
dns-server 8.8.8.8 1.1.1.1
domain-name lab.local
lease 0 8 0
!
service dhcp
write memory
Controller MGMT 192.168.10.225 AP VLAN 2605 Subnet 10.26.5.0/24 Gateway / SVI 10.26.5.1 ช่วงที่แจก .11 – .240
คัดลอก ! POD 5 · Mobility Controller (VM) · ArubaOS 8.7.1.2
! Controller MGMT : 192.168.10.225 AP VLAN : 2605 Subnet : 10.26.5.0/24
configure terminal
vlan 2605
!
interface vlan 2605
description "POD 5 - Student AP VLAN"
ip address 10.26.5.1 255.255.255.0
ip nat inside
operstate up
!
ip dhcp excluded-address 10.26.5.1 10.26.5.10
ip dhcp excluded-address 10.26.5.241 10.26.5.254
!
ip dhcp pool POOL-VLAN2605
network 10.26.5.0 255.255.255.0
default-router 10.26.5.1
dns-server 8.8.8.8 1.1.1.1
domain-name lab.local
lease 0 8 0
!
service dhcp
write memory
Controller MGMT 192.168.10.226 AP VLAN 2606 Subnet 10.26.6.0/24 Gateway / SVI 10.26.6.1 ช่วงที่แจก .11 – .240
คัดลอก ! POD 6 · Mobility Controller (VM) · ArubaOS 8.7.1.2
! Controller MGMT : 192.168.10.226 AP VLAN : 2606 Subnet : 10.26.6.0/24
configure terminal
vlan 2606
!
interface vlan 2606
description "POD 6 - Student AP VLAN"
ip address 10.26.6.1 255.255.255.0
ip nat inside
operstate up
!
ip dhcp excluded-address 10.26.6.1 10.26.6.10
ip dhcp excluded-address 10.26.6.241 10.26.6.254
!
ip dhcp pool POOL-VLAN2606
network 10.26.6.0 255.255.255.0
default-router 10.26.6.1
dns-server 8.8.8.8 1.1.1.1
domain-name lab.local
lease 0 8 0
!
service dhcp
write memory
Controller MGMT 192.168.10.227 AP VLAN 2607 Subnet 10.26.7.0/24 Gateway / SVI 10.26.7.1 ช่วงที่แจก .11 – .240
คัดลอก ! POD 7 · Mobility Controller (VM) · ArubaOS 8.7.1.2
! Controller MGMT : 192.168.10.227 AP VLAN : 2607 Subnet : 10.26.7.0/24
configure terminal
vlan 2607
!
interface vlan 2607
description "POD 7 - Student AP VLAN"
ip address 10.26.7.1 255.255.255.0
ip nat inside
operstate up
!
ip dhcp excluded-address 10.26.7.1 10.26.7.10
ip dhcp excluded-address 10.26.7.241 10.26.7.254
!
ip dhcp pool POOL-VLAN2607
network 10.26.7.0 255.255.255.0
default-router 10.26.7.1
dns-server 8.8.8.8 1.1.1.1
domain-name lab.local
lease 0 8 0
!
service dhcp
write memory
Controller MGMT 192.168.10.133 AP VLAN 2608 Subnet 10.26.8.0/24 Gateway / SVI 10.26.8.1 ช่วงที่แจก .11 – .240
คัดลอก ! TEACHER · Mobility Controller (VM) · ArubaOS 8.7.1.2
! Controller MGMT : 192.168.10.133 AP VLAN : 2608 Subnet : 10.26.8.0/24
configure terminal
vlan 2608
!
interface vlan 2608
description "TEACHER - Instructor / Demo AP VLAN"
ip address 10.26.8.1 255.255.255.0
ip nat inside
operstate up
!
ip dhcp excluded-address 10.26.8.1 10.26.8.10
ip dhcp excluded-address 10.26.8.241 10.26.8.254
!
ip dhcp pool POOL-VLAN2608
network 10.26.8.0 255.255.255.0
default-router 10.26.8.1
dns-server 8.8.8.8 1.1.1.1
domain-name lab.local
lease 0 8 0
!
service dhcp
write memory
ก่อนเริ่มไล่ปัญหา เช็คก่อนว่าต่อ console/SSH ถูก controller ของชุดตัวเอง ด้วย show running-config | include vlan
เช็คว่าแก้ถูกจุด show user-table ต้องเห็นเครื่องที่ทดสอบเปลี่ยนสถานะหลังแก้ · ping ผ่านตามที่ policy กำหนดไว้
ถ้าหลงไปแก้ผิดชุด ทุกชุดมีสถานการณ์ปัญหาต่างกัน — ยืนยันเลขชุด (n) ของตัวเองก่อนแก้ config ทุกครั้ง
05
Lab ทีละขั้น
DEMO 1 ช่วง + LAB 2 ช่วง — ทุกช่วงอยู่บน Controller VM ของชุด (DEMO ผู้สอนทำให้ดู)
Workshop นี้ไม่มีการตั้งค่าเริ่มต้น — Controller และ AP ของแต่ละชุดถูกเตรียมสถานการณ์ปัญหาไว้ล่วงหน้าแล้ว DEMO ให้ดูก่อน จากนั้น LAB 1–2 ลงมือไล่ปัญหาเอง
อุปกรณ์จริงที่ใช้ร่วมกัน — Aruba 9004-LTE (หัวสาย RAP), AP-515 และ Aruba CX 6100 — ผู้สอนเป็นคนคุม · Workshop นี้ไม่มี ClearPass จึงทำ 802.1X และ MAC Authentication ด้วยฐานผู้ใช้ในตัว controller เอง
DEMO
AP ไม่ขึ้นระบบ ผู้สอนสาธิต (Demo — ไม่ต้องลงมือเอง)
ดูผู้สอนไล่หาสาเหตุที่ AP ไม่ขึ้นระบบสองสถานการณ์ จดลำดับการวินิจฉัยไว้ใช้เป็นเช็คลิสต์
อ่านสถานะจาก AP LED ก่อนเปิดคอมพิวเตอร์ — กะพริบเขียวช้า ๆ = กำลัง boot, กะพริบเขียว-เหลืองสลับ = หา DHCP/controller ไม่เจอ, เขียวติดค้าง = เชื่อมสำเร็จแล้ว
สถานการณ์ที่ 1 — AP ค้างที่ "searching": เช็คว่า AP ขอ IP มาหรือยัง ถ้าไม่มีในลิสต์ แปลว่าปัญหาอยู่ที่ VLAN/DHCP ไม่ใช่ตัว APshow ip dhcp binding
show vlan
show ip interface brief
สาเหตุที่พบบ่อยของสถานการณ์ที่ 1: AP เสียบผิดพอร์ตเข้า VLAN ของชุดอื่น, DHCP pool เต็มหรือถูกปิดไว้
สถานการณ์ที่ 2 — AP ได้ IP แล้วแต่ไม่ขึ้น Active: เช็คว่ายังค้างใน Allowlist รอ Approve อยู่ไหมshow ap database
show ap allowlist
สาเหตุที่พบบ่อยของสถานการณ์ที่ 2: ลืม Approve ใน Allowlist, Country code ไม่ตรงกับ Controller, เวลาเครื่อง (clock) เพี้ยนกันมากจน certificate ตรวจสอบไม่ผ่าน
LAB 1
Client ต่อ WLAN ไม่ได้ Controller VM ของชุด
Controller มี SSID สี่แบบตั้งไว้แล้ว (PSK, MAC, 802.1X, Captive Portal) แต่ละตัวถูกใส่ปัญหาไว้หนึ่งอย่าง — หาให้เจอแล้วแก้ให้ client ต่อผ่าน
SSID แบบ PSK: เช็ค Key management ตรงกับ client ไหม (WPA2 vs WPA3-only) และเทียบ passphrase ในเครื่องกับใน configshow wlan ssid-profile
show ap active
SSID แบบ MAC Authentication: เช็ครูปแบบ MAC ในฐานข้อมูล — ต้องเป็นตัวพิมพ์เล็กไม่มีขีด/จุดคั่น (aabbccddeeff)show local-userdb
show user-table
SSID แบบ 802.1X: เช็คว่า Authentication server ชี้เป็น Internal และผู้ใช้ทดสอบมีอยู่จริงพร้อมรหัสตรงกันshow aaa authentication-server internal
show user-table
SSID แบบ Captive Portal: ถ้าหน้า Login ไม่เด้ง ให้เช็คว่า role ก่อนล็อกอิน (logon) อนุญาต DNS ออกไปได้ไหมก่อนshow user-table
show aaa authentication captive-portal
LAB 2
Role/Policy และ Dashboard Controller VM ของชุด
ปัญหาที่ authentication ผ่านแล้วแต่พฤติกรรมเครือข่ายยังไม่ถูกต้อง — ต้องอ่านผลจาก Dashboard และ show command แทน error
Policy ไม่ทำงานตามที่ตั้งไว้: เช็คลำดับกฎ — กฎแรกที่แมตช์คือกฎที่ใช้จริง permit any ที่อยู่เหนือ deny จะทำให้ deny ไม่มีวันทำงานshow rights
show netdestination
show acl brief
แก้ policy แล้วเครื่องเดิมยังไม่เปลี่ยนพฤติกรรม เพราะ role ผูกกับ session ที่ค้างอยู่แล้ว — ต้องตัดแล้วต่อใหม่
ไล่ปัญหาด้วย Dashboard: Overview (ภาพรวม) → Access Points (AP ตัวเอง active ไหม) → Clients (SSID/role/RSSI ของเครื่องที่ต่ออยู่) → Applications/AppRF (ใช้แอปอะไรอยู่ เทียบกับ policy)
เช็คลิสต์วินิจฉัยครบวงจร: AP active? → Client เห็น SSID? → Authentication ผ่านหรือติดขั้นไหน? → ได้ IP ไหม? → Role ตรงไหม?show ap active
show user-table verbose
show ip dhcp binding
show ap debug client-table