Merge pull request #15 from its-corp/feature/bcn01-ap-internet-rule

Feature/bcn01 ap internet rule
This commit is contained in:
Jose Martinez
2026-03-26 21:13:36 +01:00
committed by GitHub Enterprise
7 changed files with 117 additions and 2 deletions
+24
View File
@@ -186,6 +186,30 @@ resource "meraki_appliance_l3_firewall_rules" "reglas_firewall" {
rules = var.firewall_rules rules = var.firewall_rules
} }
# 4b. Configuración WAN estática de los MX (primary y spare)
# El serial se resuelve dinámicamente a partir del nombre del dispositivo
# usando el mismo data source meraki_network_devices que ya se usa para los switches
resource "meraki_device_management_interface" "mx_wan" {
for_each = { for mx in var.mx_wan_uplinks : mx.name => mx }
serial = local.device_serials[each.key]
wan1_static_ip = each.value.wan1_static_ip
wan1_static_subnet_mask = each.value.wan1_static_subnet_mask
wan1_static_gateway_ip = each.value.wan1_static_gateway_ip
wan1_static_dns = each.value.wan1_static_dns
}
# 4c. Warm Spare (HA) — VIP flotante entre primary y spare
resource "meraki_appliance_warm_spare" "ha" {
count = var.mx_warm_spare != null ? 1 : 0
network_id = local.network_id
enabled = var.mx_warm_spare.enabled
spare_serial = local.device_serials[var.mx_warm_spare.spare_name]
uplink_mode = var.mx_warm_spare.uplink_mode
virtual_ip1 = var.mx_warm_spare.virtual_ip1
}
# --- CONFIGURACIÓN SWITCHES (MS) --- # --- CONFIGURACIÓN SWITCHES (MS) ---
# 5. Políticas de acceso 802.1X # 5. Políticas de acceso 802.1X
+25
View File
@@ -184,6 +184,31 @@ variable "stack_routing_interfaces" {
description = "Interfaces L3 (SVIs) en stacks de switches para acceso de gestión al Dashboard de Meraki." description = "Interfaces L3 (SVIs) en stacks de switches para acceso de gestión al Dashboard de Meraki."
} }
# Configuración WAN de los firewalls MX (primary y spare)
variable "mx_wan_uplinks" {
type = list(object({
name = string # Nombre del dispositivo en el Dashboard
wan1_static_ip = optional(string, null)
wan1_static_subnet_mask = optional(string, null)
wan1_static_gateway_ip = optional(string, null)
wan1_static_dns = optional(list(string), null)
}))
default = []
description = "Configuración de interfaz WAN1 estática para cada MX. El serial se resuelve automáticamente por nombre de dispositivo."
}
# Warm Spare (HA) del firewall MX
variable "mx_warm_spare" {
type = object({
enabled = optional(bool, true)
spare_name = string # Nombre del MX spare en el Dashboard
uplink_mode = optional(string, "virtual")
virtual_ip1 = optional(string, null) # VIP WAN1
})
default = null
description = "Configuración Warm Spare (HA) del MX. El serial del spare se resuelve por nombre."
}
# Puertos del firewall MX # Puertos del firewall MX
variable "appliance_ports" { variable "appliance_ports" {
type = list(object({ type = list(object({
+10
View File
@@ -33,6 +33,16 @@ firewall_rules = [
dest_port = "any" dest_port = "any"
syslog_enabled = false syslog_enabled = false
}, },
{
comment = "Acceso Javi a synology"
policy = "allow"
protocol = "any"
src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST
src_port = "any"
dest_cidr = "10.2.56.0/24"
dest_port = "any"
syslog_enabled = false
},
{ {
comment = "Bloqueo temporal switch a 8.8.8.8" comment = "Bloqueo temporal switch a 8.8.8.8"
policy = "deny" policy = "deny"
+3 -1
View File
@@ -36,5 +36,7 @@ module "bcn01_lab" {
switch_management_vlan = var.switch_management_vlan switch_management_vlan = var.switch_management_vlan
stack_routing_interfaces = var.stack_routing_interfaces stack_routing_interfaces = var.stack_routing_interfaces
appliance_ports = var.appliance_ports appliance_ports = var.appliance_ports
wifi_password_psk = var.wifi_password_psk mx_wan_uplinks = var.mx_wan_uplinks
mx_warm_spare = var.mx_warm_spare
wifi_password_psk = var.wifi_password_psk
} }
+1 -1
View File
@@ -141,7 +141,7 @@ switch_named_port_configs = [
port_range = "1" port_range = "1"
name = "Servers" name = "Servers"
type = "access" type = "access"
vlan = 110 # SERVERS vlan = 101 # SERVERS
access_policy_type = "Open" access_policy_type = "Open"
}, },
{ {
+23
View File
@@ -183,3 +183,26 @@ variable "appliance_ports" {
default = [] default = []
description = "Configuración de puertos LAN del firewall MX." description = "Configuración de puertos LAN del firewall MX."
} }
variable "mx_warm_spare" {
type = object({
enabled = optional(bool, true)
spare_name = string
uplink_mode = optional(string, "virtual")
virtual_ip1 = optional(string, null)
})
default = null
description = "Configuración Warm Spare (HA) del MX."
}
variable "mx_wan_uplinks" {
type = list(object({
name = string # Nombre del dispositivo en el Dashboard
wan1_static_ip = optional(string, null)
wan1_static_subnet_mask = optional(string, null)
wan1_static_gateway_ip = optional(string, null)
wan1_static_dns = optional(list(string), null)
}))
default = []
description = "Configuración WAN1 estática de los MX. El serial se resuelve automáticamente por nombre de dispositivo."
}
+31
View File
@@ -0,0 +1,31 @@
# Configuración WAN1 estática de los firewalls MX
# El nombre debe coincidir exactamente con el nombre del dispositivo en el Dashboard
# Dashboard > Security & SD-WAN > Appliance > nombre del dispositivo
# Warm Spare (HA): VIP flotante entre primary y spare
# La IP de salida del tráfico será siempre la VIP
mx_warm_spare = {
enabled = true
spare_name = "BCN01-F04-MX02"
uplink_mode = "virtual"
virtual_ip1 = "213.229.159.148" # VIP WAN1
}
mx_wan_uplinks = [
{
# MX Primary
name = "BCN01-F04-MX01" # TODO: ajustar al nombre real en el Dashboard
wan1_static_ip = "213.229.159.145"
wan1_static_subnet_mask = "255.255.255.240" # /28
wan1_static_gateway_ip = "213.229.159.147"
wan1_static_dns = ["8.8.8.8", "8.8.4.4"]
},
{
# MX Spare (Warm Spare / HA)
name = "BCN01-F04-MX02" # TODO: ajustar al nombre real en el Dashboard
wan1_static_ip = "213.229.159.146"
wan1_static_subnet_mask = "255.255.255.240" # /28
wan1_static_gateway_ip = "213.229.159.147"
wan1_static_dns = ["8.8.8.8", "8.8.4.4"]
},
]