feat: add 802.1X switch access policy support

- Add meraki_switch_access_policy resource to module (multi-auth, critical VLAN)
- Add meraki_switch_port resource for per-port policy assignment
- Add switch_access_policies and switch_port_configs variables to module and site
- Create switch.auto.tfvars for BCN01-LAB with 802.1X-CORPO policy
  (RADIUS: 15.15.15.15:1912, critical VLAN: 100, host_mode: Multi-Auth)
- switch_port_configs starts empty; add serial + port_id to assign policy to ports

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Jose Martinez
2026-03-18 11:01:55 +01:00
co-authored by Claude Sonnet 4.6
parent cb77482368
commit 9b86ba97af
5 changed files with 168 additions and 6 deletions
+44
View File
@@ -71,3 +71,47 @@ resource "meraki_appliance_l3_firewall_rules" "reglas_firewall" {
network_id = local.network_id
rules = var.firewall_rules
}
# --- CONFIGURACIÓN SWITCHES (MS) ---
# 5. Políticas de acceso 802.1X
resource "meraki_switch_access_policy" "dot1x" {
for_each = { for p in var.switch_access_policies : p.name => p }
network_id = local.network_id
name = each.value.name
access_policy_type = each.value.access_policy_type
host_mode = each.value.host_mode
radius_accounting_enabled = each.value.radius_accounting_enabled
radius_failed_auth_vlan_id = each.value.radius_failed_auth_vlan_id
radius_re_authentication_interval = each.value.radius_re_authentication_interval
url_redirect_walled_garden_enabled = each.value.url_redirect_walled_garden_enabled
radius_servers = [
for server in each.value.radius_servers : {
host = server.host
port = server.port
secret = var.radius_secret
}
]
}
# 6. Configuración de puertos de switch
# Nota: se ejecuta después de crear las políticas para poder referenciar access_policy_number
resource "meraki_switch_port" "ports" {
for_each = {
for p in var.switch_port_configs : "${p.serial}:${p.port_id}" => p
}
depends_on = [meraki_switch_access_policy.dot1x]
serial = each.value.serial
port_id = each.value.port_id
name = each.value.name
type = each.value.type
vlan = each.value.vlan
voice_vlan_id = each.value.voice_vlan_id
access_policy_type = each.value.access_policy_type
access_policy_number = each.value.access_policy_number
}