feat(BCN01-LAB): sync manual Dashboard changes to Terraform

- Management VLAN switches → 109
- Puerto 47 stack: trunk, native VLAN 109
- SVI stack bcn01-lab-stack01: VLAN 109, 10.2.55.2/24, GW 10.2.55.1
- MX puerto 7: trunk, native VLAN 109
- Firewall: allow MANAGEMENT → internet (primera regla)
- Puerto 1 eqt-lab-st01-sw01: VLAN 110 (SERVERS)
This commit is contained in:
Jose Martinez
2026-03-25 18:24:47 +01:00
parent 88ae4a7574
commit c86569436b
7 changed files with 267 additions and 12 deletions
+15
View File
@@ -0,0 +1,15 @@
# Configuración de puertos LAN del firewall MX
# port_id: número del puerto físico en el MX
# type: "trunk" o "access"
# vlan: VLAN nativa (untagged) en trunk, o VLAN de acceso en access
appliance_ports = [
{
# Puerto 7: trunk hacia el stack de switches
# VLAN nativa 109 (MANAGEMENT), permite todas las VLANs
port_id = "7"
enabled = true
type = "trunk"
vlan = 109 # MANAGEMENT - VLAN nativa (untagged)
allowed_vlans = "all"
},
]
+11
View File
@@ -1,5 +1,16 @@
# Reglas de firewall L3
firewall_rules = [
{
# Permite que los switches (VLAN MANAGEMENT) lleguen a internet para acceder al Dashboard de Meraki
comment = "Permitir MANAGEMENT a internet (acceso Dashboard Meraki)"
policy = "allow"
protocol = "any"
src_cidr = "10.2.55.0/24" # VLAN 109 - MANAGEMENT
src_port = "any"
dest_cidr = "any"
dest_port = "any"
syslog_enabled = false
},
{
comment = "Bloqueo temporal switch a 8.8.8.8"
policy = "deny"
+4
View File
@@ -32,4 +32,8 @@ module "bcn01_lab" {
switch_access_policies = var.switch_access_policies
switch_port_configs = var.switch_port_configs
switch_stack_port_configs = var.switch_stack_port_configs
switch_named_port_configs = var.switch_named_port_configs
switch_management_vlan = var.switch_management_vlan
stack_routing_interfaces = var.stack_routing_interfaces
appliance_ports = var.appliance_ports
}
+46 -5
View File
@@ -113,10 +113,51 @@ switch_port_configs = []
# ]
switch_stack_port_configs = [
{
stack_name = "bcn01-lab-stack01"
port_range = "6"
type = "access"
vlan = 101 # GUEST
access_policy_type = "Open"
stack_name = "bcn01-lab-stack01"
port_range = "6"
type = "access"
vlan = 101 # GUEST
access_policy_type = "Open"
},
{
# Puerto 47: uplink trunk en ambos miembros del stack
# VLAN nativa 109 (MANAGEMENT), permite todas las VLANs
stack_name = "bcn01-lab-stack01"
port_range = "47"
name = "Uplink trunk"
type = "trunk"
vlan = 109 # MANAGEMENT - VLAN nativa (untagged)
allowed_vlans = "all"
access_policy_type = "Open"
},
]
# Puertos por nombre de switch (para configurar un miembro concreto del stack)
switch_named_port_configs = [
{
# Puerto 1 de eqt-lab-st01-sw01 → VLAN SERVERS (estática, sin autenticación)
switch_name = "eqt-lab-st01-sw01"
port_range = "1"
name = "Servers"
type = "access"
vlan = 110 # SERVERS
access_policy_type = "Open"
},
]
# VLAN de gestión de los switches del site
switch_management_vlan = 109
# Interfaces L3 en el stack para acceso de gestión al Dashboard de Meraki
stack_routing_interfaces = [
{
stack_name = "bcn01-lab-stack01"
name = "MANAGEMENT"
vlan_id = 109
ip_address = "10.2.55.2"
subnet = "10.2.55.0/24"
default_gateway = "10.2.55.1"
dns1 = "8.8.8.8"
dns2 = "8.8.4.4"
},
]
+52 -2
View File
@@ -100,10 +100,11 @@ variable "switch_access_policies" {
variable "switch_port_configs" {
type = list(object({
serial = string
port_range = string # puerto único "1" o rango "1-24"
port_range = string
name = optional(string, "")
type = optional(string, "access")
vlan = optional(number, null)
allowed_vlans = optional(string, "all")
access_policy_type = optional(string, "Open")
access_policy_number = optional(number, null)
}))
@@ -111,7 +112,6 @@ variable "switch_port_configs" {
description = "Puertos de switch a configurar con 802.1X. Requiere serial del switch."
}
# Configuración de puertos por nombre de stack
variable "switch_stack_port_configs" {
type = list(object({
stack_name = string
@@ -119,9 +119,59 @@ variable "switch_stack_port_configs" {
name = optional(string, "")
type = optional(string, "access")
vlan = optional(number, null)
allowed_vlans = optional(string, "all")
access_policy_type = optional(string, "Open")
access_policy_number = optional(number, null)
}))
default = []
description = "Puertos de stack a configurar por nombre. Terraform resuelve los seriales automáticamente."
}
variable "switch_named_port_configs" {
type = list(object({
switch_name = string
port_range = string
name = optional(string, "")
type = optional(string, "access")
vlan = optional(number, null)
allowed_vlans = optional(string, "all")
access_policy_type = optional(string, "Open")
access_policy_number = optional(number, null)
}))
default = []
description = "Puertos de switch a configurar por nombre de dispositivo. Terraform resuelve el serial automáticamente."
}
variable "switch_management_vlan" {
type = number
default = null
description = "VLAN ID de gestión para los switches del site."
}
variable "stack_routing_interfaces" {
type = list(object({
stack_name = string
name = string
vlan_id = number
ip_address = string
subnet = string
default_gateway = optional(string, null)
dns1 = optional(string, null)
dns2 = optional(string, null)
}))
default = []
description = "Interfaces L3 (SVIs) en stacks de switches para acceso de gestión al Dashboard."
}
variable "appliance_ports" {
type = list(object({
port_id = string
enabled = optional(bool, true)
type = optional(string, "access")
vlan = optional(number, null)
allowed_vlans = optional(string, "all")
drop_untagged_traffic = optional(bool, false)
}))
default = []
description = "Configuración de puertos LAN del firewall MX."
}