feat(bcn01-lab): onboard BCN01-LAB site and extend module with WAN2 support
- Add sites/BCN01-LAB with full Meraki configuration: VLANs, SSIDs, switch ports, 802.1X policy, firewall rules, WAN uplinks and warm spare - Extend modules/meraki-site to support wan2_* fields in mx_wan_uplinks Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
097a3c5b6c
commit
29614e1dc4
@@ -0,0 +1,67 @@
|
||||
locals {
|
||||
firewall_rules = [
|
||||
{
|
||||
comment = "Allow ACCESS to internet"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.32.0/21" # VLAN 100 - ACCESS
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Allow MANAGEMENT to internet (Meraki Dashboard access)"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.55.0/24" # VLAN 109 - MANAGEMENT
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Allow APs to internet (Meraki Dashboard access)"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.54.0/24" # VLAN 108 - APs
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Allow GUEST to internet"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Allow SERVERS to internet"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Allow GUEST to SERVERS"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST
|
||||
dest_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS
|
||||
},
|
||||
{
|
||||
comment = "Test"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.212.0.0/16"
|
||||
dest_cidr = "10.212.225.51/32,10.2.56.5/32"
|
||||
},
|
||||
{
|
||||
comment = "Allow VPN outbound traffic"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.58.0/23" # Client VPN subnet
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Deny all other outbound traffic"
|
||||
policy = "deny"
|
||||
protocol = "any"
|
||||
src_cidr = "any"
|
||||
dest_cidr = "any"
|
||||
},
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user