feat: SSID encryption + WAN/uplink switch ports 44-48

SSIDs:
- EQT-CORPO: wpa_encryption_mode → null (OWE / Enhanced Open)
- EQT-GUEST: wpa_encryption_mode → WPA3 Transition Mode

Puertos stack bcn01-lab-stack01 (sw01 y sw02):
- Puerto 44: access VLAN 111 WAN — ISP router 1
- Puerto 45: access VLAN 111 WAN — WAN 1 BCN01-F04-MX01
- Puerto 46: access VLAN 111 WAN — WAN 1 BCN01-F04-MX02
- Puerto 47: trunk VLAN nativa 109, todas — UPLINK LAN BCN01-F04-MX01
- Puerto 48: trunk VLAN nativa 109, todas — UPLINK LAN BCN01-F04-MX02

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Jose Martinez
2026-03-27 07:17:42 +01:00
co-authored by Claude Sonnet 4.6
parent ee0f34bd34
commit 5cdc09747e
2 changed files with 41 additions and 5 deletions
+2 -2
View File
@@ -8,7 +8,7 @@ wireless_ssids = [
name = "EQT-CORPO"
enabled = true
auth_mode = "open"
wpa_encryption_mode = "WPA3 only"
wpa_encryption_mode = null # OWE (Opportunistic Wireless Encryption / Enhanced Open)
splash_page = "Password-protected with custom RADIUS"
ip_assignment_mode = "Bridge mode"
use_vlan_tagging = true
@@ -27,7 +27,7 @@ wireless_ssids = [
enabled = true
auth_mode = "psk" # Modo para contraseña compartida
encryption_mode = "wpa" # Requerido por la API Meraki para PSK
wpa_encryption_mode = "WPA2 only" # Lo que pediste para compatibilidad
wpa_encryption_mode = "WPA3 Transition Mode"
# psk se inyecta via TF_VAR_wifi_password_psk (GitHub secret WIFI_PASSWORD_PSK)
ip_assignment_mode = "Bridge mode"
use_vlan_tagging = true
+39 -3
View File
@@ -120,11 +120,47 @@ switch_stack_port_configs = [
access_policy_type = "Open"
},
{
# Puerto 47: uplink trunk en ambos miembros del stack
# VLAN nativa 109 (MANAGEMENT), permite todas las VLANs
# Puerto 44: ISP router (acceso WAN)
stack_name = "bcn01-lab-stack01"
port_range = "44"
name = "ISP router 1"
type = "access"
vlan = 111 # WAN
access_policy_type = "Open"
},
{
# Puerto 45: WAN1 del MX primary
stack_name = "bcn01-lab-stack01"
port_range = "45"
name = "WAN 1 BCN01-F04-MX01"
type = "access"
vlan = 111 # WAN
access_policy_type = "Open"
},
{
# Puerto 46: WAN1 del MX spare
stack_name = "bcn01-lab-stack01"
port_range = "46"
name = "WAN 1 BCN01-F04-MX02"
type = "access"
vlan = 111 # WAN
access_policy_type = "Open"
},
{
# Puerto 47: uplink LAN del MX primary
stack_name = "bcn01-lab-stack01"
port_range = "47"
name = "Uplink trunk"
name = "UPLINK LAN BCN01-F04-MX01"
type = "trunk"
vlan = 109 # MANAGEMENT - VLAN nativa (untagged)
allowed_vlans = "all"
access_policy_type = "Open"
},
{
# Puerto 48: uplink LAN del MX spare
stack_name = "bcn01-lab-stack01"
port_range = "48"
name = "UPLINK LAN BCN01-F04-MX02"
type = "trunk"
vlan = 109 # MANAGEMENT - VLAN nativa (untagged)
allowed_vlans = "all"