diff --git a/modules/meraki-site/main.tf b/modules/meraki-site/main.tf index c2d7002..7ba3a14 100755 --- a/modules/meraki-site/main.tf +++ b/modules/meraki-site/main.tf @@ -71,3 +71,48 @@ resource "meraki_appliance_l3_firewall_rules" "reglas_firewall" { network_id = local.network_id rules = var.firewall_rules } + +# --- CONFIGURACIÓN SWITCHES (MS) --- + +# 5. Políticas de acceso 802.1X +resource "meraki_switch_access_policy" "dot1x" { + for_each = { for p in var.switch_access_policies : p.name => p } + network_id = local.network_id + + name = each.value.name + access_policy_type = each.value.access_policy_type + host_mode = each.value.host_mode + radius_accounting_enabled = each.value.radius_accounting_enabled + radius_testing_enabled = each.value.radius_testing_enabled + radius_coa_support_enabled = each.value.radius_coa_support_enabled + radius_failed_auth_vlan_id = each.value.radius_failed_auth_vlan_id + radius_re_authentication_interval = each.value.radius_re_authentication_interval + url_redirect_walled_garden_enabled = each.value.url_redirect_walled_garden_enabled + + radius_servers = [ + for server in each.value.radius_servers : { + host = server.host + port = server.port + secret = var.radius_secret + } + ] +} + +# 6. Configuración de puertos de switch +# Nota: se ejecuta después de crear las políticas para poder referenciar access_policy_number +resource "meraki_switch_port" "ports" { + for_each = { + for p in var.switch_port_configs : "${p.serial}:${p.port_id}" => p + } + depends_on = [meraki_switch_access_policy.dot1x] + + serial = each.value.serial + port_id = each.value.port_id + name = each.value.name + type = each.value.type + + vlan = each.value.vlan + + access_policy_type = each.value.access_policy_type + access_policy_number = each.value.access_policy_number +} diff --git a/modules/meraki-site/variables.tf b/modules/meraki-site/variables.tf index ac43bcc..7c21d3e 100755 --- a/modules/meraki-site/variables.tf +++ b/modules/meraki-site/variables.tf @@ -82,3 +82,41 @@ variable "switch_vlans" { } } +# Políticas de acceso 802.1X para switches +variable "switch_access_policies" { + type = list(object({ + name = string + access_policy_type = optional(string, "802.1x") + host_mode = optional(string, "Multi-Auth") + radius_accounting_enabled = optional(bool, false) + radius_testing_enabled = optional(bool, false) + radius_coa_support_enabled = optional(bool, false) + radius_failed_auth_vlan_id = optional(number, null) + radius_re_authentication_interval = optional(number, 0) + url_redirect_walled_garden_enabled = optional(bool, false) + radius_servers = list(object({ + host = string + port = number + })) + })) + default = [] + description = "Políticas de acceso 802.1X para switches MS. El shared secret se toma de radius_secret." +} + +# Configuración de puertos de switch con 802.1X +# Requiere serial del switch (visible en Dashboard > Switches > nombre del switch) +variable "switch_port_configs" { + type = list(object({ + serial = string + port_id = string + name = optional(string, "") + type = optional(string, "access") + vlan = optional(number, null) + voice_vlan_id = optional(number, null) + access_policy_type = optional(string, "Open") + access_policy_number = optional(number, null) + })) + default = [] + description = "Puertos de switch a configurar. access_policy_number referencia el número de la política creada en switch_access_policies." +} + diff --git a/sites/BCN01-LAB/main.tf b/sites/BCN01-LAB/main.tf index 68672cb..b460758 100755 --- a/sites/BCN01-LAB/main.tf +++ b/sites/BCN01-LAB/main.tf @@ -23,10 +23,12 @@ provider "meraki" {} module "bcn01_lab" { source = "../../modules/meraki-site" - organization_name = var.organization_name - network_name = var.network_name - switch_vlans = var.switch_vlans - firewall_rules = var.firewall_rules - wireless_ssids = var.wireless_ssids - radius_secret = var.radius_secret + organization_name = var.organization_name + network_name = var.network_name + switch_vlans = var.switch_vlans + firewall_rules = var.firewall_rules + wireless_ssids = var.wireless_ssids + radius_secret = var.radius_secret + switch_access_policies = var.switch_access_policies + switch_port_configs = var.switch_port_configs } diff --git a/sites/BCN01-LAB/switch.auto.tfvars b/sites/BCN01-LAB/switch.auto.tfvars new file mode 100644 index 0000000..004313e --- /dev/null +++ b/sites/BCN01-LAB/switch.auto.tfvars @@ -0,0 +1,44 @@ +# Configuración de switches MS - BCN01-LAB +# El shared secret de RADIUS se pasa via TF_VAR_radius_secret (GitHub secret: RADIUS_SECRET) + +# --- POLÍTICAS DE ACCESO 802.1X --- +switch_access_policies = [ + { + name = "802.1X-CORPO" + access_policy_type = "802.1x" + host_mode = "Multi-Auth" + radius_accounting_enabled = false + radius_re_authentication_interval = 0 + url_redirect_walled_garden_enabled = false + + # VLAN a la que cae el puerto si el RADIUS no responde + radius_failed_auth_vlan_id = 101 # GUEST + + radius_servers = [ + { + host = "15.15.15.15" + port = 1912 + } + ] + } +] + +# --- PUERTOS DE SWITCH CON 802.1X --- +# Para configurar puertos, añade entradas con el serial del switch y el port_id. +# El serial aparece en Dashboard > Switches > nombre del switch > Overview. +# access_policy_number: número auto-asignado por Meraki a la política creada arriba +# (visible en Dashboard > Switches > Switch settings > Access policies, o en el output de terraform) +# +# Ejemplo: +# switch_port_configs = [ +# { +# serial = "XXXX-XXXX-XXXX" # serial del switch +# port_id = "1" +# name = "Workstation 1" +# type = "access" +# vlan = 100 +# access_policy_type = "Custom access policy" +# access_policy_number = 1 # número de la política 802.1X-CORPO +# }, +# ] +switch_port_configs = [] diff --git a/sites/BCN01-LAB/variables.tf b/sites/BCN01-LAB/variables.tf index 7e983d6..7e9e6fe 100755 --- a/sites/BCN01-LAB/variables.tf +++ b/sites/BCN01-LAB/variables.tf @@ -74,3 +74,40 @@ variable "switch_vlans" { description = "Mapa de configuraciones de VLAN. La clave del mapa será el ID de la VLAN" } + +# Políticas de acceso 802.1X para switches +variable "switch_access_policies" { + type = list(object({ + name = string + access_policy_type = optional(string, "802.1x") + host_mode = optional(string, "Multi-Auth") + radius_accounting_enabled = optional(bool, false) + radius_testing_enabled = optional(bool, false) + radius_coa_support_enabled = optional(bool, false) + radius_failed_auth_vlan_id = optional(number, null) + radius_re_authentication_interval = optional(number, 0) + url_redirect_walled_garden_enabled = optional(bool, false) + radius_servers = list(object({ + host = string + port = number + })) + })) + default = [] + description = "Políticas de acceso 802.1X para switches MS" +} + +# Configuración de puertos de switch +variable "switch_port_configs" { + type = list(object({ + serial = string + port_id = string + name = optional(string, "") + type = optional(string, "access") + vlan = optional(number, null) + voice_vlan_id = optional(number, null) + access_policy_type = optional(string, "Open") + access_policy_number = optional(number, null) + })) + default = [] + description = "Puertos de switch a configurar con 802.1X. Requiere serial del switch." +}