From 7378e9977ce07d77165b1703bd864afae4627a17 Mon Sep 17 00:00:00 2001 From: Jose Martinez Date: Wed, 25 Mar 2026 23:07:09 +0100 Subject: [PATCH] feat(BCN01-LAB): puerto AP trunk y VLAN 111 WAN sin L3 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Puerto 3 eqt-lab-st01-sw01: trunk, native 108 (APs), tagged 100+101 - VLAN 111 WAN sin subnet ni appliance_ip (switching puro) - subnet/appliance_ip pasan a ser opcionales en el módulo --- modules/meraki-site/main.tf | 24 +++++++++++++----------- modules/meraki-site/variables.tf | 15 ++++++++------- sites/BCN01-LAB/switch.auto.tfvars | 10 ++++++++++ sites/BCN01-LAB/variables.tf | 5 +++-- sites/BCN01-LAB/vlans.auto.tfvars | 5 +++++ 5 files changed, 39 insertions(+), 20 deletions(-) diff --git a/modules/meraki-site/main.tf b/modules/meraki-site/main.tf index 149816b..42cc74d 100755 --- a/modules/meraki-site/main.tf +++ b/modules/meraki-site/main.tf @@ -141,8 +141,8 @@ resource "meraki_appliance_vlan" "mx_gateways" { network_id = local.network_id vlan_id = each.key name = each.value.name - subnet = each.value.subnet - appliance_ip = each.value.appliance_ip + subnet = each.value.subnet # null para VLANs sin L3 + appliance_ip = each.value.appliance_ip # null para VLANs sin L3 reserved_ip_ranges = each.value.reserved_ip_ranges dhcp_handling = each.value.dhcp_handling } @@ -152,15 +152,17 @@ resource "meraki_wireless_ssid" "ssids" { for_each = { for s in var.wireless_ssids : tostring(s.number) => s } depends_on = [meraki_appliance_vlans_settings.activate_vlans] - network_id = local.network_id - number = each.value.number - name = each.value.name - enabled = each.value.enabled - auth_mode = each.value.auth_mode - splash_page = each.value.splash_page - ip_assignment_mode = each.value.ip_assignment_mode - use_vlan_tagging = each.value.use_vlan_tagging - default_vlan_id = each.value.default_vlan_id + network_id = local.network_id + number = each.value.number + name = each.value.name + enabled = each.value.enabled + auth_mode = each.value.auth_mode + psk = each.value.psk + wpa_encryption_mode = each.value.wpa_encryption_mode + splash_page = each.value.splash_page + ip_assignment_mode = each.value.ip_assignment_mode + use_vlan_tagging = each.value.use_vlan_tagging + default_vlan_id = each.value.default_vlan_id radius_servers = length(each.value.radius_servers) > 0 ? [ for server in each.value.radius_servers : { host = server.host diff --git a/modules/meraki-site/variables.tf b/modules/meraki-site/variables.tf index 7883267..f4c55d9 100755 --- a/modules/meraki-site/variables.tf +++ b/modules/meraki-site/variables.tf @@ -30,11 +30,12 @@ variable "firewall_rules" { # SSIDs wireless variable "wireless_ssids" { type = list(object({ - number = number - name = string - enabled = optional(bool, true) - auth_mode = string - splash_page = optional(string, "None") + number = number + name = string + enabled = optional(bool, true) + auth_mode = string + psk = optional(string, null) # Contraseña WPA2/WPA3-PSK (sensible, usar TF_VAR o secret) + splash_page = optional(string, "None") wpa_encryption_mode = optional(string, "WPA3 only") ip_assignment_mode = optional(string, "Bridge mode") use_vlan_tagging = optional(bool, false) @@ -61,8 +62,8 @@ variable "radius_secret" { variable "switch_vlans" { type = map(object({ name = string - subnet = string - appliance_ip = string + subnet = optional(string, null) # null para VLANs sin L3 (p.ej. WAN puro switching) + appliance_ip = optional(string, null) dhcp_handling = optional(string, "Run a DHCP server") reserved_ip_ranges = optional(list(object({ comment = string diff --git a/sites/BCN01-LAB/switch.auto.tfvars b/sites/BCN01-LAB/switch.auto.tfvars index 5d92f7d..6d73fc5 100644 --- a/sites/BCN01-LAB/switch.auto.tfvars +++ b/sites/BCN01-LAB/switch.auto.tfvars @@ -144,6 +144,16 @@ switch_named_port_configs = [ vlan = 110 # SERVERS access_policy_type = "Open" }, + { + # Puerto 3 de eqt-lab-st01-sw01 → AP (trunk, nativa 108 APs, tageadas 100 ACCESS y 101 GUEST) + switch_name = "eqt-lab-st01-sw01" + port_range = "3" + name = "AP" + type = "trunk" + vlan = 108 # APs - VLAN nativa (untagged) + allowed_vlans = "100,101,108" # ACCESS + GUEST + APs + access_policy_type = "Open" + }, ] # VLAN de gestión de los switches del site diff --git a/sites/BCN01-LAB/variables.tf b/sites/BCN01-LAB/variables.tf index 2562be7..4af645a 100755 --- a/sites/BCN01-LAB/variables.tf +++ b/sites/BCN01-LAB/variables.tf @@ -34,6 +34,7 @@ variable "wireless_ssids" { name = string enabled = optional(bool, true) auth_mode = string + psk = optional(string, null) splash_page = optional(string, "None") wpa_encryption_mode = optional(string, "WPA3 only") ip_assignment_mode = optional(string, "Bridge mode") @@ -61,8 +62,8 @@ variable "radius_secret" { variable "switch_vlans" { type = map(object({ name = string - subnet = string - appliance_ip = string + subnet = optional(string, null) + appliance_ip = optional(string, null) dhcp_handling = optional(string, "Run a DHCP server") reserved_ip_ranges = optional(list(object({ comment = string diff --git a/sites/BCN01-LAB/vlans.auto.tfvars b/sites/BCN01-LAB/vlans.auto.tfvars index 189cfae..dbfa75c 100755 --- a/sites/BCN01-LAB/vlans.auto.tfvars +++ b/sites/BCN01-LAB/vlans.auto.tfvars @@ -89,4 +89,9 @@ switch_vlans = { appliance_ip = "10.2.56.1" dhcp_handling = "Do not respond to DHCP requests" } + "111" = { + name = "WAN" + dhcp_handling = "Do not respond to DHCP requests" + # Sin L3: sin subnet ni appliance_ip (VLAN de switching puro hacia el ISP) + } } \ No newline at end of file