feat: add 802.1X switch access policy support
- Add meraki_switch_access_policy resource to module (multi-auth, critical VLAN) - Add meraki_switch_port resource for per-port policy assignment - Add switch_access_policies and switch_port_configs variables to module and site - Create switch.auto.tfvars for BCN01-LAB with 802.1X-CORPO policy (RADIUS: 15.15.15.15:1912, critical VLAN: 100, host_mode: Multi-Auth) - switch_port_configs starts empty; add serial + port_id to assign policy to ports Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
cb77482368
commit
9b86ba97af
@@ -71,3 +71,47 @@ resource "meraki_appliance_l3_firewall_rules" "reglas_firewall" {
|
|||||||
network_id = local.network_id
|
network_id = local.network_id
|
||||||
rules = var.firewall_rules
|
rules = var.firewall_rules
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# --- CONFIGURACIÓN SWITCHES (MS) ---
|
||||||
|
|
||||||
|
# 5. Políticas de acceso 802.1X
|
||||||
|
resource "meraki_switch_access_policy" "dot1x" {
|
||||||
|
for_each = { for p in var.switch_access_policies : p.name => p }
|
||||||
|
network_id = local.network_id
|
||||||
|
|
||||||
|
name = each.value.name
|
||||||
|
access_policy_type = each.value.access_policy_type
|
||||||
|
host_mode = each.value.host_mode
|
||||||
|
radius_accounting_enabled = each.value.radius_accounting_enabled
|
||||||
|
radius_failed_auth_vlan_id = each.value.radius_failed_auth_vlan_id
|
||||||
|
radius_re_authentication_interval = each.value.radius_re_authentication_interval
|
||||||
|
url_redirect_walled_garden_enabled = each.value.url_redirect_walled_garden_enabled
|
||||||
|
|
||||||
|
radius_servers = [
|
||||||
|
for server in each.value.radius_servers : {
|
||||||
|
host = server.host
|
||||||
|
port = server.port
|
||||||
|
secret = var.radius_secret
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
|
||||||
|
# 6. Configuración de puertos de switch
|
||||||
|
# Nota: se ejecuta después de crear las políticas para poder referenciar access_policy_number
|
||||||
|
resource "meraki_switch_port" "ports" {
|
||||||
|
for_each = {
|
||||||
|
for p in var.switch_port_configs : "${p.serial}:${p.port_id}" => p
|
||||||
|
}
|
||||||
|
depends_on = [meraki_switch_access_policy.dot1x]
|
||||||
|
|
||||||
|
serial = each.value.serial
|
||||||
|
port_id = each.value.port_id
|
||||||
|
name = each.value.name
|
||||||
|
type = each.value.type
|
||||||
|
|
||||||
|
vlan = each.value.vlan
|
||||||
|
voice_vlan_id = each.value.voice_vlan_id
|
||||||
|
|
||||||
|
access_policy_type = each.value.access_policy_type
|
||||||
|
access_policy_number = each.value.access_policy_number
|
||||||
|
}
|
||||||
|
|||||||
@@ -82,3 +82,39 @@ variable "switch_vlans" {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Políticas de acceso 802.1X para switches
|
||||||
|
variable "switch_access_policies" {
|
||||||
|
type = list(object({
|
||||||
|
name = string
|
||||||
|
access_policy_type = optional(string, "802.1x")
|
||||||
|
host_mode = optional(string, "Multi-Auth")
|
||||||
|
radius_accounting_enabled = optional(bool, false)
|
||||||
|
radius_failed_auth_vlan_id = optional(number, null)
|
||||||
|
radius_re_authentication_interval = optional(number, 0)
|
||||||
|
url_redirect_walled_garden_enabled = optional(bool, false)
|
||||||
|
radius_servers = list(object({
|
||||||
|
host = string
|
||||||
|
port = number
|
||||||
|
}))
|
||||||
|
}))
|
||||||
|
default = []
|
||||||
|
description = "Políticas de acceso 802.1X para switches MS. El shared secret se toma de radius_secret."
|
||||||
|
}
|
||||||
|
|
||||||
|
# Configuración de puertos de switch con 802.1X
|
||||||
|
# Requiere serial del switch (visible en Dashboard > Switches > nombre del switch)
|
||||||
|
variable "switch_port_configs" {
|
||||||
|
type = list(object({
|
||||||
|
serial = string
|
||||||
|
port_id = string
|
||||||
|
name = optional(string, "")
|
||||||
|
type = optional(string, "access")
|
||||||
|
vlan = optional(number, null)
|
||||||
|
voice_vlan_id = optional(number, null)
|
||||||
|
access_policy_type = optional(string, "Open")
|
||||||
|
access_policy_number = optional(number, null)
|
||||||
|
}))
|
||||||
|
default = []
|
||||||
|
description = "Puertos de switch a configurar. access_policy_number referencia el número de la política creada en switch_access_policies."
|
||||||
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -29,4 +29,6 @@ module "bcn01_lab" {
|
|||||||
firewall_rules = var.firewall_rules
|
firewall_rules = var.firewall_rules
|
||||||
wireless_ssids = var.wireless_ssids
|
wireless_ssids = var.wireless_ssids
|
||||||
radius_secret = var.radius_secret
|
radius_secret = var.radius_secret
|
||||||
|
switch_access_policies = var.switch_access_policies
|
||||||
|
switch_port_configs = var.switch_port_configs
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,45 @@
|
|||||||
|
# Configuración de switches MS - BCN01-LAB
|
||||||
|
# El shared secret de RADIUS se pasa via TF_VAR_radius_secret (GitHub secret: RADIUS_SECRET)
|
||||||
|
|
||||||
|
# --- POLÍTICAS DE ACCESO 802.1X ---
|
||||||
|
switch_access_policies = [
|
||||||
|
{
|
||||||
|
name = "802.1X-CORPO"
|
||||||
|
access_policy_type = "802.1x"
|
||||||
|
host_mode = "Multi-Auth"
|
||||||
|
radius_accounting_enabled = false
|
||||||
|
radius_re_authentication_interval = 0
|
||||||
|
url_redirect_walled_garden_enabled = false
|
||||||
|
|
||||||
|
# VLAN a la que cae el puerto si el RADIUS no responde
|
||||||
|
# Cambiar por la VLAN deseada (ej. VLAN 100 = ACCESS)
|
||||||
|
radius_failed_auth_vlan_id = 100
|
||||||
|
|
||||||
|
radius_servers = [
|
||||||
|
{
|
||||||
|
host = "15.15.15.15"
|
||||||
|
port = 1912
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
|
||||||
|
# --- PUERTOS DE SWITCH CON 802.1X ---
|
||||||
|
# Para configurar puertos, añade entradas con el serial del switch y el port_id.
|
||||||
|
# El serial aparece en Dashboard > Switches > nombre del switch > Overview.
|
||||||
|
# access_policy_number: número auto-asignado por Meraki a la política creada arriba
|
||||||
|
# (visible en Dashboard > Switches > Switch settings > Access policies, o en el output de terraform)
|
||||||
|
#
|
||||||
|
# Ejemplo:
|
||||||
|
# switch_port_configs = [
|
||||||
|
# {
|
||||||
|
# serial = "XXXX-XXXX-XXXX" # serial del switch
|
||||||
|
# port_id = "1"
|
||||||
|
# name = "Workstation 1"
|
||||||
|
# type = "access"
|
||||||
|
# vlan = 100
|
||||||
|
# access_policy_type = "Custom access policy"
|
||||||
|
# access_policy_number = 1 # número de la política 802.1X-CORPO
|
||||||
|
# },
|
||||||
|
# ]
|
||||||
|
switch_port_configs = []
|
||||||
@@ -74,3 +74,38 @@ variable "switch_vlans" {
|
|||||||
description = "Mapa de configuraciones de VLAN. La clave del mapa será el ID de la VLAN"
|
description = "Mapa de configuraciones de VLAN. La clave del mapa será el ID de la VLAN"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
# Políticas de acceso 802.1X para switches
|
||||||
|
variable "switch_access_policies" {
|
||||||
|
type = list(object({
|
||||||
|
name = string
|
||||||
|
access_policy_type = optional(string, "802.1x")
|
||||||
|
host_mode = optional(string, "Multi-Auth")
|
||||||
|
radius_accounting_enabled = optional(bool, false)
|
||||||
|
radius_failed_auth_vlan_id = optional(number, null)
|
||||||
|
radius_re_authentication_interval = optional(number, 0)
|
||||||
|
url_redirect_walled_garden_enabled = optional(bool, false)
|
||||||
|
radius_servers = list(object({
|
||||||
|
host = string
|
||||||
|
port = number
|
||||||
|
}))
|
||||||
|
}))
|
||||||
|
default = []
|
||||||
|
description = "Políticas de acceso 802.1X para switches MS"
|
||||||
|
}
|
||||||
|
|
||||||
|
# Configuración de puertos de switch
|
||||||
|
variable "switch_port_configs" {
|
||||||
|
type = list(object({
|
||||||
|
serial = string
|
||||||
|
port_id = string
|
||||||
|
name = optional(string, "")
|
||||||
|
type = optional(string, "access")
|
||||||
|
vlan = optional(number, null)
|
||||||
|
voice_vlan_id = optional(number, null)
|
||||||
|
access_policy_type = optional(string, "Open")
|
||||||
|
access_policy_number = optional(number, null)
|
||||||
|
}))
|
||||||
|
default = []
|
||||||
|
description = "Puertos de switch a configurar con 802.1X. Requiere serial del switch."
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user