feat(bcn01-lab): onboard BCN01-LAB site and extend module with WAN2 support

- Add sites/BCN01-LAB with full Meraki configuration: VLANs, SSIDs,
  switch ports, 802.1X policy, firewall rules, WAN uplinks and warm spare
- Extend modules/meraki-site to support wan2_* fields in mx_wan_uplinks

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Jose Martinez
2026-04-29 07:02:06 +02:00
co-authored by Claude Sonnet 4.6
parent 097a3c5b6c
commit 29614e1dc4
12 changed files with 457 additions and 0 deletions
+67
View File
@@ -0,0 +1,67 @@
locals {
firewall_rules = [
{
comment = "Allow ACCESS to internet"
policy = "allow"
protocol = "any"
src_cidr = "10.2.32.0/21" # VLAN 100 - ACCESS
dest_cidr = "any"
},
{
comment = "Allow MANAGEMENT to internet (Meraki Dashboard access)"
policy = "allow"
protocol = "any"
src_cidr = "10.2.55.0/24" # VLAN 109 - MANAGEMENT
dest_cidr = "any"
},
{
comment = "Allow APs to internet (Meraki Dashboard access)"
policy = "allow"
protocol = "any"
src_cidr = "10.2.54.0/24" # VLAN 108 - APs
dest_cidr = "any"
},
{
comment = "Allow GUEST to internet"
policy = "allow"
protocol = "any"
src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST
dest_cidr = "any"
},
{
comment = "Allow SERVERS to internet"
policy = "allow"
protocol = "any"
src_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS
dest_cidr = "any"
},
{
comment = "Allow GUEST to SERVERS"
policy = "allow"
protocol = "any"
src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST
dest_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS
},
{
comment = "Test"
policy = "allow"
protocol = "any"
src_cidr = "10.212.0.0/16"
dest_cidr = "10.212.225.51/32,10.2.56.5/32"
},
{
comment = "Allow VPN outbound traffic"
policy = "allow"
protocol = "any"
src_cidr = "10.2.58.0/23" # Client VPN subnet
dest_cidr = "any"
},
{
comment = "Deny all other outbound traffic"
policy = "deny"
protocol = "any"
src_cidr = "any"
dest_cidr = "any"
},
]
}