feat: configure static WAN1 IP for primary and spare MX

Añade recurso meraki_device_management_interface para configurar
IP estática en el puerto WAN1 de ambos firewalls MX:
  - Primary: 213.229.159.145/28 (255.255.255.240), GW 213.229.159.147
  - Spare:   213.229.159.146/28 (255.255.255.240), GW 213.229.159.147

Los seriales del MX deben reemplazarse en wan.auto.tfvars.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Jose Martinez
2026-03-26 20:50:14 +01:00
co-authored by Claude Sonnet 4.6
parent 1dd08e5a28
commit 7fdb3e956e
5 changed files with 63 additions and 1 deletions
+12
View File
@@ -186,6 +186,18 @@ resource "meraki_appliance_l3_firewall_rules" "reglas_firewall" {
rules = var.firewall_rules
}
# 4b. Configuración WAN estática de los MX (primary y spare)
resource "meraki_device_management_interface" "mx_wan" {
for_each = { for mx in var.mx_wan_uplinks : mx.serial => mx }
serial = each.key
interfaces_wan1_enabled = each.value.interfaces_wan1_enabled
wan1_static_ip = each.value.wan1_static_ip
wan1_static_subnet_mask = each.value.wan1_static_subnet_mask
wan1_static_gateway_ip = each.value.wan1_static_gateway_ip
wan1_static_dns = each.value.wan1_static_dns
}
# --- CONFIGURACIÓN SWITCHES (MS) ---
# 5. Políticas de acceso 802.1X
+14
View File
@@ -184,6 +184,20 @@ variable "stack_routing_interfaces" {
description = "Interfaces L3 (SVIs) en stacks de switches para acceso de gestión al Dashboard de Meraki."
}
# Configuración WAN de los firewalls MX (primary y spare)
variable "mx_wan_uplinks" {
type = list(object({
serial = string
interfaces_wan1_enabled = optional(bool, true)
wan1_static_ip = optional(string, null)
wan1_static_subnet_mask = optional(string, null)
wan1_static_gateway_ip = optional(string, null)
wan1_static_dns = optional(list(string), null)
}))
default = []
description = "Configuración de interfaz WAN1 estática para cada MX (primary y spare)."
}
# Puertos del firewall MX
variable "appliance_ports" {
type = list(object({
+1
View File
@@ -36,5 +36,6 @@ module "bcn01_lab" {
switch_management_vlan = var.switch_management_vlan
stack_routing_interfaces = var.stack_routing_interfaces
appliance_ports = var.appliance_ports
mx_wan_uplinks = var.mx_wan_uplinks
wifi_password_psk = var.wifi_password_psk
}
+13
View File
@@ -183,3 +183,16 @@ variable "appliance_ports" {
default = []
description = "Configuración de puertos LAN del firewall MX."
}
variable "mx_wan_uplinks" {
type = list(object({
serial = string
interfaces_wan1_enabled = optional(bool, true)
wan1_static_ip = optional(string, null)
wan1_static_subnet_mask = optional(string, null)
wan1_static_gateway_ip = optional(string, null)
wan1_static_dns = optional(list(string), null)
}))
default = []
description = "Configuración WAN1 estática de los MX (primary y spare)."
}
+22
View File
@@ -0,0 +1,22 @@
# Configuración WAN1 estática de los firewalls MX
# Los seriales se encuentran en: Dashboard > Security & SD-WAN > Appliance > Overview
mx_wan_uplinks = [
{
# MX Primary
serial = "XXXX-XXXX-XXXX" # TODO: reemplazar con serial del MX primary
interfaces_wan1_enabled = true
wan1_static_ip = "213.229.159.145"
wan1_static_subnet_mask = "255.255.255.240" # /28
wan1_static_gateway_ip = "213.229.159.147"
wan1_static_dns = ["8.8.8.8", "8.8.4.4"]
},
{
# MX Spare (Warm Spare / HA)
serial = "YYYY-YYYY-YYYY" # TODO: reemplazar con serial del MX spare
interfaces_wan1_enabled = true
wan1_static_ip = "213.229.159.146"
wan1_static_subnet_mask = "255.255.255.240" # /28
wan1_static_gateway_ip = "213.229.159.147"
wan1_static_dns = ["8.8.8.8", "8.8.4.4"]
},
]