feat: add 802.1X switch access policy support
- Add meraki_switch_access_policy resource to module (multi-auth, critical VLAN) - Add meraki_switch_port resource for per-port policy assignment - Add switch_access_policies and switch_port_configs variables to module and site - Create switch.auto.tfvars for BCN01-LAB with 802.1X-CORPO policy (RADIUS: 15.15.15.15:1912, critical VLAN: 100, host_mode: Multi-Auth) - switch_port_configs starts empty; add serial + port_id to assign policy to ports Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
cb77482368
commit
9b86ba97af
@@ -0,0 +1,45 @@
|
||||
# Configuración de switches MS - BCN01-LAB
|
||||
# El shared secret de RADIUS se pasa via TF_VAR_radius_secret (GitHub secret: RADIUS_SECRET)
|
||||
|
||||
# --- POLÍTICAS DE ACCESO 802.1X ---
|
||||
switch_access_policies = [
|
||||
{
|
||||
name = "802.1X-CORPO"
|
||||
access_policy_type = "802.1x"
|
||||
host_mode = "Multi-Auth"
|
||||
radius_accounting_enabled = false
|
||||
radius_re_authentication_interval = 0
|
||||
url_redirect_walled_garden_enabled = false
|
||||
|
||||
# VLAN a la que cae el puerto si el RADIUS no responde
|
||||
# Cambiar por la VLAN deseada (ej. VLAN 100 = ACCESS)
|
||||
radius_failed_auth_vlan_id = 100
|
||||
|
||||
radius_servers = [
|
||||
{
|
||||
host = "15.15.15.15"
|
||||
port = 1912
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
|
||||
# --- PUERTOS DE SWITCH CON 802.1X ---
|
||||
# Para configurar puertos, añade entradas con el serial del switch y el port_id.
|
||||
# El serial aparece en Dashboard > Switches > nombre del switch > Overview.
|
||||
# access_policy_number: número auto-asignado por Meraki a la política creada arriba
|
||||
# (visible en Dashboard > Switches > Switch settings > Access policies, o en el output de terraform)
|
||||
#
|
||||
# Ejemplo:
|
||||
# switch_port_configs = [
|
||||
# {
|
||||
# serial = "XXXX-XXXX-XXXX" # serial del switch
|
||||
# port_id = "1"
|
||||
# name = "Workstation 1"
|
||||
# type = "access"
|
||||
# vlan = 100
|
||||
# access_policy_type = "Custom access policy"
|
||||
# access_policy_number = 1 # número de la política 802.1X-CORPO
|
||||
# },
|
||||
# ]
|
||||
switch_port_configs = []
|
||||
Reference in New Issue
Block a user