Merge pull request #20 from its-corp/feature/bcn01-ssid-encryption-wan-ports
wip: add SSID slot 3 placeholder for drift detection via terraform plan
This commit is contained in:
@@ -159,13 +159,12 @@ resource "meraki_wireless_ssid" "ssids" {
|
||||
number = each.value.number
|
||||
name = each.value.name
|
||||
enabled = each.value.enabled
|
||||
visible = each.value.visible
|
||||
auth_mode = each.value.auth_mode
|
||||
# Si el SSID no tiene psk en el tfvars, usa var.wifi_password_psk (TF_VAR_wifi_password_psk)
|
||||
psk = each.value.psk != null ? each.value.psk : var.wifi_password_psk
|
||||
# wpa_encryption_mode solo es compatible con auth_mode != "open"
|
||||
# Para OWE (open + WPA3) la API rechaza el campo; la encriptación Enhanced Open
|
||||
# se negocia a nivel de beacon y no se expone como atributo de la API Meraki.
|
||||
wpa_encryption_mode = each.value.auth_mode != "open" ? each.value.wpa_encryption_mode : null
|
||||
# PSK solo se envía para SSIDs con auth_mode "psk"; para open/open-enhanced se deja null
|
||||
psk = each.value.auth_mode == "psk" ? (each.value.psk != null ? each.value.psk : var.wifi_password_psk) : null
|
||||
# wpa_encryption_mode se pasa directamente desde el tfvars (null si no aplica)
|
||||
wpa_encryption_mode = each.value.wpa_encryption_mode
|
||||
encryption_mode = each.value.encryption_mode
|
||||
splash_page = each.value.splash_page
|
||||
ip_assignment_mode = each.value.ip_assignment_mode
|
||||
|
||||
@@ -33,6 +33,7 @@ variable "wireless_ssids" {
|
||||
number = number
|
||||
name = string
|
||||
enabled = optional(bool, true)
|
||||
visible = optional(bool, true) # false = SSID oculto (no broadcast)
|
||||
auth_mode = string
|
||||
psk = optional(string, null) # Contraseña WPA2/WPA3-PSK (sensible, usar TF_VAR o secret)
|
||||
encryption_mode = optional(string, null) # "wpa" para PSK; null para open/OWE
|
||||
|
||||
@@ -10,7 +10,25 @@ wireless_ssids = [
|
||||
auth_mode = "open-enhanced" # OWE (Opportunistic Wireless Encryption)
|
||||
# Meraki API utiliza "open-enhanced" para indicar Enhanced Open / OWE.
|
||||
# Este valor refleja exactamente lo que está configurado en el Dashboard.
|
||||
wpa_encryption_mode = null
|
||||
wpa_encryption_mode = "WPA3 only"
|
||||
splash_page = "Password-protected with custom RADIUS"
|
||||
ip_assignment_mode = "Bridge mode"
|
||||
use_vlan_tagging = true
|
||||
default_vlan_id = 100
|
||||
redirect_url = "https://www.adevinta.com"
|
||||
radius_servers = [
|
||||
{
|
||||
host = "15.15.15.15"
|
||||
port = 1912
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
number = 2
|
||||
name = "EQT-CORPO-OWE-OK"
|
||||
enabled = true
|
||||
visible = false # SSID oculto — no hace broadcast del nombre
|
||||
auth_mode = "open"
|
||||
splash_page = "Password-protected with custom RADIUS"
|
||||
ip_assignment_mode = "Bridge mode"
|
||||
use_vlan_tagging = true
|
||||
|
||||
Reference in New Issue
Block a user