feat(bcn01-lab): add 1:1 NAT support and import Synology rule
Add meraki_appliance_firewall_one_to_one_nat_rules resource to the meraki-site module and codify the existing Synology NAT rule found in BCN01-LAB Dashboard (57.133.120.190 → 10.2.56.3 via internet2). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
4a93967012
commit
b8e517cb40
@@ -308,7 +308,29 @@ resource "meraki_switch_stack_routing_interface" "stack_interfaces" {
|
||||
default_gateway = each.value.default_gateway
|
||||
}
|
||||
|
||||
# 9. Puertos del firewall MX
|
||||
# 9. Reglas NAT 1:1 del MX
|
||||
resource "meraki_appliance_firewall_one_to_one_nat_rules" "nat_1to1" {
|
||||
count = length(var.one_to_one_nat_rules) > 0 ? 1 : 0
|
||||
network_id = local.network_id
|
||||
|
||||
rules = [
|
||||
for rule in var.one_to_one_nat_rules : {
|
||||
name = rule.name
|
||||
public_ip = rule.public_ip
|
||||
lan_ip = rule.lan_ip
|
||||
uplink = rule.uplink
|
||||
allowed_inbound = [
|
||||
for ib in rule.allowed_inbound : {
|
||||
protocol = ib.protocol
|
||||
destination_ports = ib.destination_ports
|
||||
allowed_ips = ib.allowed_ips
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
# 10. Puertos del firewall MX
|
||||
resource "meraki_appliance_port" "ports" {
|
||||
for_each = { for p in var.appliance_ports : p.port_id => p }
|
||||
|
||||
|
||||
Reference in New Issue
Block a user