Merge pull request #7 from its-corp/feature/switch-dot1x

Feature/switch dot1x
This commit is contained in:
Jose Martinez
2026-03-18 11:14:50 +01:00
committed by GitHub Enterprise
5 changed files with 172 additions and 6 deletions
+45
View File
@@ -71,3 +71,48 @@ resource "meraki_appliance_l3_firewall_rules" "reglas_firewall" {
network_id = local.network_id network_id = local.network_id
rules = var.firewall_rules rules = var.firewall_rules
} }
# --- CONFIGURACIÓN SWITCHES (MS) ---
# 5. Políticas de acceso 802.1X
resource "meraki_switch_access_policy" "dot1x" {
for_each = { for p in var.switch_access_policies : p.name => p }
network_id = local.network_id
name = each.value.name
access_policy_type = each.value.access_policy_type
host_mode = each.value.host_mode
radius_accounting_enabled = each.value.radius_accounting_enabled
radius_testing_enabled = each.value.radius_testing_enabled
radius_coa_support_enabled = each.value.radius_coa_support_enabled
radius_failed_auth_vlan_id = each.value.radius_failed_auth_vlan_id
radius_re_authentication_interval = each.value.radius_re_authentication_interval
url_redirect_walled_garden_enabled = each.value.url_redirect_walled_garden_enabled
radius_servers = [
for server in each.value.radius_servers : {
host = server.host
port = server.port
secret = var.radius_secret
}
]
}
# 6. Configuración de puertos de switch
# Nota: se ejecuta después de crear las políticas para poder referenciar access_policy_number
resource "meraki_switch_port" "ports" {
for_each = {
for p in var.switch_port_configs : "${p.serial}:${p.port_id}" => p
}
depends_on = [meraki_switch_access_policy.dot1x]
serial = each.value.serial
port_id = each.value.port_id
name = each.value.name
type = each.value.type
vlan = each.value.vlan
access_policy_type = each.value.access_policy_type
access_policy_number = each.value.access_policy_number
}
+38
View File
@@ -82,3 +82,41 @@ variable "switch_vlans" {
} }
} }
# Políticas de acceso 802.1X para switches
variable "switch_access_policies" {
type = list(object({
name = string
access_policy_type = optional(string, "802.1x")
host_mode = optional(string, "Multi-Auth")
radius_accounting_enabled = optional(bool, false)
radius_testing_enabled = optional(bool, false)
radius_coa_support_enabled = optional(bool, false)
radius_failed_auth_vlan_id = optional(number, null)
radius_re_authentication_interval = optional(number, 0)
url_redirect_walled_garden_enabled = optional(bool, false)
radius_servers = list(object({
host = string
port = number
}))
}))
default = []
description = "Políticas de acceso 802.1X para switches MS. El shared secret se toma de radius_secret."
}
# Configuración de puertos de switch con 802.1X
# Requiere serial del switch (visible en Dashboard > Switches > nombre del switch)
variable "switch_port_configs" {
type = list(object({
serial = string
port_id = string
name = optional(string, "")
type = optional(string, "access")
vlan = optional(number, null)
voice_vlan_id = optional(number, null)
access_policy_type = optional(string, "Open")
access_policy_number = optional(number, null)
}))
default = []
description = "Puertos de switch a configurar. access_policy_number referencia el número de la política creada en switch_access_policies."
}
+8 -6
View File
@@ -23,10 +23,12 @@ provider "meraki" {}
module "bcn01_lab" { module "bcn01_lab" {
source = "../../modules/meraki-site" source = "../../modules/meraki-site"
organization_name = var.organization_name organization_name = var.organization_name
network_name = var.network_name network_name = var.network_name
switch_vlans = var.switch_vlans switch_vlans = var.switch_vlans
firewall_rules = var.firewall_rules firewall_rules = var.firewall_rules
wireless_ssids = var.wireless_ssids wireless_ssids = var.wireless_ssids
radius_secret = var.radius_secret radius_secret = var.radius_secret
switch_access_policies = var.switch_access_policies
switch_port_configs = var.switch_port_configs
} }
+44
View File
@@ -0,0 +1,44 @@
# Configuración de switches MS - BCN01-LAB
# El shared secret de RADIUS se pasa via TF_VAR_radius_secret (GitHub secret: RADIUS_SECRET)
# --- POLÍTICAS DE ACCESO 802.1X ---
switch_access_policies = [
{
name = "802.1X-CORPO"
access_policy_type = "802.1x"
host_mode = "Multi-Auth"
radius_accounting_enabled = false
radius_re_authentication_interval = 0
url_redirect_walled_garden_enabled = false
# VLAN a la que cae el puerto si el RADIUS no responde
radius_failed_auth_vlan_id = 101 # GUEST
radius_servers = [
{
host = "15.15.15.15"
port = 1912
}
]
}
]
# --- PUERTOS DE SWITCH CON 802.1X ---
# Para configurar puertos, añade entradas con el serial del switch y el port_id.
# El serial aparece en Dashboard > Switches > nombre del switch > Overview.
# access_policy_number: número auto-asignado por Meraki a la política creada arriba
# (visible en Dashboard > Switches > Switch settings > Access policies, o en el output de terraform)
#
# Ejemplo:
# switch_port_configs = [
# {
# serial = "XXXX-XXXX-XXXX" # serial del switch
# port_id = "1"
# name = "Workstation 1"
# type = "access"
# vlan = 100
# access_policy_type = "Custom access policy"
# access_policy_number = 1 # número de la política 802.1X-CORPO
# },
# ]
switch_port_configs = []
+37
View File
@@ -74,3 +74,40 @@ variable "switch_vlans" {
description = "Mapa de configuraciones de VLAN. La clave del mapa será el ID de la VLAN" description = "Mapa de configuraciones de VLAN. La clave del mapa será el ID de la VLAN"
} }
# Políticas de acceso 802.1X para switches
variable "switch_access_policies" {
type = list(object({
name = string
access_policy_type = optional(string, "802.1x")
host_mode = optional(string, "Multi-Auth")
radius_accounting_enabled = optional(bool, false)
radius_testing_enabled = optional(bool, false)
radius_coa_support_enabled = optional(bool, false)
radius_failed_auth_vlan_id = optional(number, null)
radius_re_authentication_interval = optional(number, 0)
url_redirect_walled_garden_enabled = optional(bool, false)
radius_servers = list(object({
host = string
port = number
}))
}))
default = []
description = "Políticas de acceso 802.1X para switches MS"
}
# Configuración de puertos de switch
variable "switch_port_configs" {
type = list(object({
serial = string
port_id = string
name = optional(string, "")
type = optional(string, "access")
vlan = optional(number, null)
voice_vlan_id = optional(number, null)
access_policy_type = optional(string, "Open")
access_policy_number = optional(number, null)
}))
default = []
description = "Puertos de switch a configurar con 802.1X. Requiere serial del switch."
}