feat(bcn01-lab): add 1:1 NAT support and import Synology rule
Add meraki_appliance_firewall_one_to_one_nat_rules resource to the meraki-site module and codify the existing Synology NAT rule found in BCN01-LAB Dashboard (57.133.120.190 → 10.2.56.3 via internet2). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
4a93967012
commit
b8e517cb40
@@ -308,7 +308,29 @@ resource "meraki_switch_stack_routing_interface" "stack_interfaces" {
|
|||||||
default_gateway = each.value.default_gateway
|
default_gateway = each.value.default_gateway
|
||||||
}
|
}
|
||||||
|
|
||||||
# 9. Puertos del firewall MX
|
# 9. Reglas NAT 1:1 del MX
|
||||||
|
resource "meraki_appliance_firewall_one_to_one_nat_rules" "nat_1to1" {
|
||||||
|
count = length(var.one_to_one_nat_rules) > 0 ? 1 : 0
|
||||||
|
network_id = local.network_id
|
||||||
|
|
||||||
|
rules = [
|
||||||
|
for rule in var.one_to_one_nat_rules : {
|
||||||
|
name = rule.name
|
||||||
|
public_ip = rule.public_ip
|
||||||
|
lan_ip = rule.lan_ip
|
||||||
|
uplink = rule.uplink
|
||||||
|
allowed_inbound = [
|
||||||
|
for ib in rule.allowed_inbound : {
|
||||||
|
protocol = ib.protocol
|
||||||
|
destination_ports = ib.destination_ports
|
||||||
|
allowed_ips = ib.allowed_ips
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
|
||||||
|
# 10. Puertos del firewall MX
|
||||||
resource "meraki_appliance_port" "ports" {
|
resource "meraki_appliance_port" "ports" {
|
||||||
for_each = { for p in var.appliance_ports : p.port_id => p }
|
for_each = { for p in var.appliance_ports : p.port_id => p }
|
||||||
|
|
||||||
|
|||||||
@@ -213,6 +213,23 @@ variable "mx_warm_spare" {
|
|||||||
description = "Configuración Warm Spare (HA) del MX. El serial del spare se resuelve por nombre."
|
description = "Configuración Warm Spare (HA) del MX. El serial del spare se resuelve por nombre."
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Reglas NAT 1:1 del firewall MX
|
||||||
|
variable "one_to_one_nat_rules" {
|
||||||
|
type = list(object({
|
||||||
|
name = string
|
||||||
|
public_ip = string
|
||||||
|
lan_ip = string
|
||||||
|
uplink = optional(string, "internet1")
|
||||||
|
allowed_inbound = optional(list(object({
|
||||||
|
protocol = optional(string, "any")
|
||||||
|
destination_ports = optional(list(string), ["Any"])
|
||||||
|
allowed_ips = list(string)
|
||||||
|
})), [])
|
||||||
|
}))
|
||||||
|
default = []
|
||||||
|
description = "Reglas NAT 1:1 del MX. Mapean una IP pública a una IP interna con control de tráfico entrante."
|
||||||
|
}
|
||||||
|
|
||||||
# Puertos del firewall MX
|
# Puertos del firewall MX
|
||||||
variable "appliance_ports" {
|
variable "appliance_ports" {
|
||||||
type = list(object({
|
type = list(object({
|
||||||
|
|||||||
@@ -1,4 +1,25 @@
|
|||||||
locals {
|
locals {
|
||||||
|
one_to_one_nat_rules = [
|
||||||
|
{
|
||||||
|
name = "Synology"
|
||||||
|
public_ip = "57.133.120.190"
|
||||||
|
lan_ip = "10.2.56.3"
|
||||||
|
uplink = "internet2"
|
||||||
|
allowed_inbound = [
|
||||||
|
{
|
||||||
|
protocol = "any"
|
||||||
|
destination_ports = ["Any"]
|
||||||
|
allowed_ips = ["188.0.0.0/8"]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
protocol = "any"
|
||||||
|
destination_ports = ["Any"]
|
||||||
|
allowed_ips = ["57.133.120.176/28"]
|
||||||
|
},
|
||||||
|
]
|
||||||
|
},
|
||||||
|
]
|
||||||
|
|
||||||
appliance_ports = [
|
appliance_ports = [
|
||||||
{
|
{
|
||||||
# Port 7: trunk toward the switch stack
|
# Port 7: trunk toward the switch stack
|
||||||
|
|||||||
@@ -33,6 +33,7 @@ module "bcn01_lab" {
|
|||||||
switch_named_port_configs = local.switch_named_port_configs
|
switch_named_port_configs = local.switch_named_port_configs
|
||||||
switch_management_vlan = local.switch_management_vlan
|
switch_management_vlan = local.switch_management_vlan
|
||||||
stack_routing_interfaces = local.stack_routing_interfaces
|
stack_routing_interfaces = local.stack_routing_interfaces
|
||||||
|
one_to_one_nat_rules = local.one_to_one_nat_rules
|
||||||
appliance_ports = local.appliance_ports
|
appliance_ports = local.appliance_ports
|
||||||
mx_wan_uplinks = local.mx_wan_uplinks
|
mx_wan_uplinks = local.mx_wan_uplinks
|
||||||
mx_warm_spare = local.mx_warm_spare
|
mx_warm_spare = local.mx_warm_spare
|
||||||
|
|||||||
Reference in New Issue
Block a user