feat(bcn01-lab): add 1:1 NAT support and import Synology rule
Add meraki_appliance_firewall_one_to_one_nat_rules resource to the meraki-site module and codify the existing Synology NAT rule found in BCN01-LAB Dashboard (57.133.120.190 → 10.2.56.3 via internet2). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
4a93967012
commit
b8e517cb40
@@ -1,4 +1,25 @@
|
||||
locals {
|
||||
one_to_one_nat_rules = [
|
||||
{
|
||||
name = "Synology"
|
||||
public_ip = "57.133.120.190"
|
||||
lan_ip = "10.2.56.3"
|
||||
uplink = "internet2"
|
||||
allowed_inbound = [
|
||||
{
|
||||
protocol = "any"
|
||||
destination_ports = ["Any"]
|
||||
allowed_ips = ["188.0.0.0/8"]
|
||||
},
|
||||
{
|
||||
protocol = "any"
|
||||
destination_ports = ["Any"]
|
||||
allowed_ips = ["57.133.120.176/28"]
|
||||
},
|
||||
]
|
||||
},
|
||||
]
|
||||
|
||||
appliance_ports = [
|
||||
{
|
||||
# Port 7: trunk toward the switch stack
|
||||
|
||||
@@ -33,6 +33,7 @@ module "bcn01_lab" {
|
||||
switch_named_port_configs = local.switch_named_port_configs
|
||||
switch_management_vlan = local.switch_management_vlan
|
||||
stack_routing_interfaces = local.stack_routing_interfaces
|
||||
one_to_one_nat_rules = local.one_to_one_nat_rules
|
||||
appliance_ports = local.appliance_ports
|
||||
mx_wan_uplinks = local.mx_wan_uplinks
|
||||
mx_warm_spare = local.mx_warm_spare
|
||||
|
||||
Reference in New Issue
Block a user