feat: multi-site scalability, locals refactor, README
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
locals {
|
||||
firewall_rules = [
|
||||
{
|
||||
comment = "Allow MANAGEMENT to internet (Meraki Dashboard access)"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.55.0/24" # VLAN 109 - MANAGEMENT
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Allow APs to internet (Meraki Dashboard access)"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.54.0/24" # VLAN 108 - APs
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Allow GUEST to internet"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Allow SERVERS to internet"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS
|
||||
dest_cidr = "any"
|
||||
},
|
||||
{
|
||||
comment = "Allow GUEST to SERVERS (temporary)"
|
||||
policy = "allow"
|
||||
protocol = "any"
|
||||
src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST
|
||||
dest_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS
|
||||
},
|
||||
{
|
||||
comment = "Deny all other outbound traffic"
|
||||
policy = "deny"
|
||||
protocol = "any"
|
||||
src_cidr = "any"
|
||||
dest_cidr = "any"
|
||||
},
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user