feat: add Warm Spare (HA) with VIP for MX appliances
Configura meraki_appliance_warm_spare con VIP flotante en WAN1: - Spare: BCN01-F04-MX02 (serial resuelto por nombre) - Uplink mode: virtual - VIP WAN1: 213.229.159.148 La IP de salida del tráfico será siempre la VIP (.148), independientemente de qué MX esté activo. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
5d0f043503
commit
4a2eeb6c17
@@ -200,6 +200,17 @@ resource "meraki_device_management_interface" "mx_wan" {
|
|||||||
wan1_static_dns = each.value.wan1_static_dns
|
wan1_static_dns = each.value.wan1_static_dns
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# 4c. Warm Spare (HA) — VIP flotante entre primary y spare
|
||||||
|
resource "meraki_appliance_warm_spare" "ha" {
|
||||||
|
count = var.mx_warm_spare != null ? 1 : 0
|
||||||
|
|
||||||
|
network_id = local.network_id
|
||||||
|
enabled = var.mx_warm_spare.enabled
|
||||||
|
spare_serial = local.device_serials[var.mx_warm_spare.spare_name]
|
||||||
|
uplink_mode = var.mx_warm_spare.uplink_mode
|
||||||
|
virtual_ip1 = var.mx_warm_spare.virtual_ip1
|
||||||
|
}
|
||||||
|
|
||||||
# --- CONFIGURACIÓN SWITCHES (MS) ---
|
# --- CONFIGURACIÓN SWITCHES (MS) ---
|
||||||
|
|
||||||
# 5. Políticas de acceso 802.1X
|
# 5. Políticas de acceso 802.1X
|
||||||
|
|||||||
@@ -198,6 +198,18 @@ variable "mx_wan_uplinks" {
|
|||||||
description = "Configuración de interfaz WAN1 estática para cada MX. El serial se resuelve automáticamente por nombre de dispositivo."
|
description = "Configuración de interfaz WAN1 estática para cada MX. El serial se resuelve automáticamente por nombre de dispositivo."
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Warm Spare (HA) del firewall MX
|
||||||
|
variable "mx_warm_spare" {
|
||||||
|
type = object({
|
||||||
|
enabled = optional(bool, true)
|
||||||
|
spare_name = string # Nombre del MX spare en el Dashboard
|
||||||
|
uplink_mode = optional(string, "virtual")
|
||||||
|
virtual_ip1 = optional(string, null) # VIP WAN1
|
||||||
|
})
|
||||||
|
default = null
|
||||||
|
description = "Configuración Warm Spare (HA) del MX. El serial del spare se resuelve por nombre."
|
||||||
|
}
|
||||||
|
|
||||||
# Puertos del firewall MX
|
# Puertos del firewall MX
|
||||||
variable "appliance_ports" {
|
variable "appliance_ports" {
|
||||||
type = list(object({
|
type = list(object({
|
||||||
|
|||||||
@@ -37,5 +37,6 @@ module "bcn01_lab" {
|
|||||||
stack_routing_interfaces = var.stack_routing_interfaces
|
stack_routing_interfaces = var.stack_routing_interfaces
|
||||||
appliance_ports = var.appliance_ports
|
appliance_ports = var.appliance_ports
|
||||||
mx_wan_uplinks = var.mx_wan_uplinks
|
mx_wan_uplinks = var.mx_wan_uplinks
|
||||||
|
mx_warm_spare = var.mx_warm_spare
|
||||||
wifi_password_psk = var.wifi_password_psk
|
wifi_password_psk = var.wifi_password_psk
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -184,6 +184,17 @@ variable "appliance_ports" {
|
|||||||
description = "Configuración de puertos LAN del firewall MX."
|
description = "Configuración de puertos LAN del firewall MX."
|
||||||
}
|
}
|
||||||
|
|
||||||
|
variable "mx_warm_spare" {
|
||||||
|
type = object({
|
||||||
|
enabled = optional(bool, true)
|
||||||
|
spare_name = string
|
||||||
|
uplink_mode = optional(string, "virtual")
|
||||||
|
virtual_ip1 = optional(string, null)
|
||||||
|
})
|
||||||
|
default = null
|
||||||
|
description = "Configuración Warm Spare (HA) del MX."
|
||||||
|
}
|
||||||
|
|
||||||
variable "mx_wan_uplinks" {
|
variable "mx_wan_uplinks" {
|
||||||
type = list(object({
|
type = list(object({
|
||||||
name = string # Nombre del dispositivo en el Dashboard
|
name = string # Nombre del dispositivo en el Dashboard
|
||||||
|
|||||||
@@ -1,10 +1,20 @@
|
|||||||
# Configuración WAN1 estática de los firewalls MX
|
# Configuración WAN1 estática de los firewalls MX
|
||||||
# El nombre debe coincidir exactamente con el nombre del dispositivo en el Dashboard
|
# El nombre debe coincidir exactamente con el nombre del dispositivo en el Dashboard
|
||||||
# Dashboard > Security & SD-WAN > Appliance > nombre del dispositivo
|
# Dashboard > Security & SD-WAN > Appliance > nombre del dispositivo
|
||||||
|
|
||||||
|
# Warm Spare (HA): VIP flotante entre primary y spare
|
||||||
|
# La IP de salida del tráfico será siempre la VIP
|
||||||
|
mx_warm_spare = {
|
||||||
|
enabled = true
|
||||||
|
spare_name = "BCN01-F04-MX02"
|
||||||
|
uplink_mode = "virtual"
|
||||||
|
virtual_ip1 = "213.229.159.148" # VIP WAN1
|
||||||
|
}
|
||||||
|
|
||||||
mx_wan_uplinks = [
|
mx_wan_uplinks = [
|
||||||
{
|
{
|
||||||
# MX Primary
|
# MX Primary
|
||||||
name = "eqt-lab-fw01-mx01" # TODO: ajustar al nombre real en el Dashboard
|
name = "BCN01-F04-MX01" # TODO: ajustar al nombre real en el Dashboard
|
||||||
interfaces_wan1_enabled = true
|
interfaces_wan1_enabled = true
|
||||||
wan1_static_ip = "213.229.159.145"
|
wan1_static_ip = "213.229.159.145"
|
||||||
wan1_static_subnet_mask = "255.255.255.240" # /28
|
wan1_static_subnet_mask = "255.255.255.240" # /28
|
||||||
@@ -13,7 +23,7 @@ mx_wan_uplinks = [
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
# MX Spare (Warm Spare / HA)
|
# MX Spare (Warm Spare / HA)
|
||||||
name = "eqt-lab-fw01-mx02" # TODO: ajustar al nombre real en el Dashboard
|
name = "BCN01-F04-MX02" # TODO: ajustar al nombre real en el Dashboard
|
||||||
interfaces_wan1_enabled = true
|
interfaces_wan1_enabled = true
|
||||||
wan1_static_ip = "213.229.159.146"
|
wan1_static_ip = "213.229.159.146"
|
||||||
wan1_static_subnet_mask = "255.255.255.240" # /28
|
wan1_static_subnet_mask = "255.255.255.240" # /28
|
||||||
|
|||||||
Reference in New Issue
Block a user