From b8e517cb40ef7accbcdb1cb8a622c871c565093f Mon Sep 17 00:00:00 2001 From: Jose Martinez Date: Thu, 7 May 2026 09:42:59 +0200 Subject: [PATCH 1/2] feat(bcn01-lab): add 1:1 NAT support and import Synology rule MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add meraki_appliance_firewall_one_to_one_nat_rules resource to the meraki-site module and codify the existing Synology NAT rule found in BCN01-LAB Dashboard (57.133.120.190 → 10.2.56.3 via internet2). Co-Authored-By: Claude Sonnet 4.6 --- modules/meraki-site/main.tf | 24 +++++++++++++++++++++++- modules/meraki-site/variables.tf | 17 +++++++++++++++++ sites/BCN01-LAB/appliance.tf | 21 +++++++++++++++++++++ sites/BCN01-LAB/main.tf | 1 + 4 files changed, 62 insertions(+), 1 deletion(-) diff --git a/modules/meraki-site/main.tf b/modules/meraki-site/main.tf index 5f328d5..1f3ba58 100755 --- a/modules/meraki-site/main.tf +++ b/modules/meraki-site/main.tf @@ -308,7 +308,29 @@ resource "meraki_switch_stack_routing_interface" "stack_interfaces" { default_gateway = each.value.default_gateway } -# 9. Puertos del firewall MX +# 9. Reglas NAT 1:1 del MX +resource "meraki_appliance_firewall_one_to_one_nat_rules" "nat_1to1" { + count = length(var.one_to_one_nat_rules) > 0 ? 1 : 0 + network_id = local.network_id + + rules = [ + for rule in var.one_to_one_nat_rules : { + name = rule.name + public_ip = rule.public_ip + lan_ip = rule.lan_ip + uplink = rule.uplink + allowed_inbound = [ + for ib in rule.allowed_inbound : { + protocol = ib.protocol + destination_ports = ib.destination_ports + allowed_ips = ib.allowed_ips + } + ] + } + ] +} + +# 10. Puertos del firewall MX resource "meraki_appliance_port" "ports" { for_each = { for p in var.appliance_ports : p.port_id => p } diff --git a/modules/meraki-site/variables.tf b/modules/meraki-site/variables.tf index fe67caa..488a669 100755 --- a/modules/meraki-site/variables.tf +++ b/modules/meraki-site/variables.tf @@ -213,6 +213,23 @@ variable "mx_warm_spare" { description = "Configuración Warm Spare (HA) del MX. El serial del spare se resuelve por nombre." } +# Reglas NAT 1:1 del firewall MX +variable "one_to_one_nat_rules" { + type = list(object({ + name = string + public_ip = string + lan_ip = string + uplink = optional(string, "internet1") + allowed_inbound = optional(list(object({ + protocol = optional(string, "any") + destination_ports = optional(list(string), ["Any"]) + allowed_ips = list(string) + })), []) + })) + default = [] + description = "Reglas NAT 1:1 del MX. Mapean una IP pública a una IP interna con control de tráfico entrante." +} + # Puertos del firewall MX variable "appliance_ports" { type = list(object({ diff --git a/sites/BCN01-LAB/appliance.tf b/sites/BCN01-LAB/appliance.tf index 9c83cee..a79eb3e 100644 --- a/sites/BCN01-LAB/appliance.tf +++ b/sites/BCN01-LAB/appliance.tf @@ -1,4 +1,25 @@ locals { + one_to_one_nat_rules = [ + { + name = "Synology" + public_ip = "57.133.120.190" + lan_ip = "10.2.56.3" + uplink = "internet2" + allowed_inbound = [ + { + protocol = "any" + destination_ports = ["Any"] + allowed_ips = ["188.0.0.0/8"] + }, + { + protocol = "any" + destination_ports = ["Any"] + allowed_ips = ["57.133.120.176/28"] + }, + ] + }, + ] + appliance_ports = [ { # Port 7: trunk toward the switch stack diff --git a/sites/BCN01-LAB/main.tf b/sites/BCN01-LAB/main.tf index 423ec05..3dbb029 100755 --- a/sites/BCN01-LAB/main.tf +++ b/sites/BCN01-LAB/main.tf @@ -33,6 +33,7 @@ module "bcn01_lab" { switch_named_port_configs = local.switch_named_port_configs switch_management_vlan = local.switch_management_vlan stack_routing_interfaces = local.stack_routing_interfaces + one_to_one_nat_rules = local.one_to_one_nat_rules appliance_ports = local.appliance_ports mx_wan_uplinks = local.mx_wan_uplinks mx_warm_spare = local.mx_warm_spare From 6d0f1867955ac4c1f04713f9e76d4e4d6f15bab4 Mon Sep 17 00:00:00 2001 From: Jose Martinez Date: Thu, 7 May 2026 09:52:27 +0200 Subject: [PATCH 2/2] fix(meraki-site): correct 1:1 NAT resource type name meraki_appliance_firewall_one_to_one_nat_rules does not exist in provider v1.9.0; correct name is meraki_appliance_one_to_one_nat_rules. Co-Authored-By: Claude Sonnet 4.6 --- modules/meraki-site/main.tf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/meraki-site/main.tf b/modules/meraki-site/main.tf index 1f3ba58..ec1dcf0 100755 --- a/modules/meraki-site/main.tf +++ b/modules/meraki-site/main.tf @@ -309,7 +309,7 @@ resource "meraki_switch_stack_routing_interface" "stack_interfaces" { } # 9. Reglas NAT 1:1 del MX -resource "meraki_appliance_firewall_one_to_one_nat_rules" "nat_1to1" { +resource "meraki_appliance_one_to_one_nat_rules" "nat_1to1" { count = length(var.one_to_one_nat_rules) > 0 ? 1 : 0 network_id = local.network_id