diff --git a/modules/meraki-site/main.tf b/modules/meraki-site/main.tf index a2da0ab..b3c498a 100755 --- a/modules/meraki-site/main.tf +++ b/modules/meraki-site/main.tf @@ -159,13 +159,12 @@ resource "meraki_wireless_ssid" "ssids" { number = each.value.number name = each.value.name enabled = each.value.enabled + visible = each.value.visible auth_mode = each.value.auth_mode - # Si el SSID no tiene psk en el tfvars, usa var.wifi_password_psk (TF_VAR_wifi_password_psk) - psk = each.value.psk != null ? each.value.psk : var.wifi_password_psk - # wpa_encryption_mode solo es compatible con auth_mode != "open" - # Para OWE (open + WPA3) la API rechaza el campo; la encriptación Enhanced Open - # se negocia a nivel de beacon y no se expone como atributo de la API Meraki. - wpa_encryption_mode = each.value.auth_mode != "open" ? each.value.wpa_encryption_mode : null + # PSK solo se envía para SSIDs con auth_mode "psk"; para open/open-enhanced se deja null + psk = each.value.auth_mode == "psk" ? (each.value.psk != null ? each.value.psk : var.wifi_password_psk) : null + # wpa_encryption_mode se pasa directamente desde el tfvars (null si no aplica) + wpa_encryption_mode = each.value.wpa_encryption_mode encryption_mode = each.value.encryption_mode splash_page = each.value.splash_page ip_assignment_mode = each.value.ip_assignment_mode diff --git a/modules/meraki-site/variables.tf b/modules/meraki-site/variables.tf index 76b43d9..8686059 100755 --- a/modules/meraki-site/variables.tf +++ b/modules/meraki-site/variables.tf @@ -33,6 +33,7 @@ variable "wireless_ssids" { number = number name = string enabled = optional(bool, true) + visible = optional(bool, true) # false = SSID oculto (no broadcast) auth_mode = string psk = optional(string, null) # Contraseña WPA2/WPA3-PSK (sensible, usar TF_VAR o secret) encryption_mode = optional(string, null) # "wpa" para PSK; null para open/OWE diff --git a/sites/BCN01-LAB/ssids.auto.tfvars b/sites/BCN01-LAB/ssids.auto.tfvars index cd6f32a..33a5788 100644 --- a/sites/BCN01-LAB/ssids.auto.tfvars +++ b/sites/BCN01-LAB/ssids.auto.tfvars @@ -10,7 +10,7 @@ wireless_ssids = [ auth_mode = "open-enhanced" # OWE (Opportunistic Wireless Encryption) # Meraki API utiliza "open-enhanced" para indicar Enhanced Open / OWE. # Este valor refleja exactamente lo que está configurado en el Dashboard. - wpa_encryption_mode = null + wpa_encryption_mode = "WPA3 only" splash_page = "Password-protected with custom RADIUS" ip_assignment_mode = "Bridge mode" use_vlan_tagging = true @@ -23,6 +23,24 @@ wireless_ssids = [ } ] }, + { + number = 2 + name = "EQT-CORPO-OWE-OK" + enabled = true + visible = false # SSID oculto — no hace broadcast del nombre + auth_mode = "open" + splash_page = "Password-protected with custom RADIUS" + ip_assignment_mode = "Bridge mode" + use_vlan_tagging = true + default_vlan_id = 100 + redirect_url = "https://www.adevinta.com" + radius_servers = [ + { + host = "15.15.15.15" + port = 1912 + } + ] + }, { number = 1 name = "EQT-GUEST"