docs: add port config examples (802.1X, impresoras, uplink) in switch.auto.tfvars
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
775dbce9a8
commit
dcc7398355
@@ -23,21 +23,43 @@ switch_access_policies = [
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|
||||||
# --- PUERTOS DE SWITCH CON 802.1X ---
|
# --- PUERTOS DE SWITCH ---
|
||||||
# Para configurar puertos, añade entradas con el serial del switch y el port_id.
|
|
||||||
# El serial aparece en Dashboard > Switches > nombre del switch > Overview.
|
# El serial aparece en Dashboard > Switches > nombre del switch > Overview.
|
||||||
# access_policy_number: número auto-asignado por Meraki a la política creada arriba
|
# access_policy_number: número auto-asignado por Meraki a la política creada arriba
|
||||||
# (visible en Dashboard > Switches > Switch settings > Access policies, o en el output de terraform)
|
# (visible en Dashboard > Switches > Switch settings > Access policies)
|
||||||
#
|
#
|
||||||
# Ejemplo:
|
# Ejemplo con los tres tipos de puerto:
|
||||||
# switch_port_configs = [
|
# switch_port_configs = [
|
||||||
|
#
|
||||||
|
# # Puertos de acceso general con 802.1X (PCs, portátiles)
|
||||||
|
# # Autenticación: 802.1X → MAB → VLAN GUEST si falla RADIUS
|
||||||
|
# # La VLAN final la asigna Okta dinámicamente; vlan=100 es el fallback estático
|
||||||
# {
|
# {
|
||||||
# serial = "XXXX-XXXX-XXXX" # serial del switch
|
# serial = "XXXX-XXXX-XXXX"
|
||||||
# port_range = "1-24" # rango de puertos (o "1" para uno solo)
|
# port_range = "1-20"
|
||||||
# type = "access"
|
# type = "access"
|
||||||
# vlan = 100
|
# vlan = 100 # ACCESS - fallback si Okta no devuelve VLAN
|
||||||
# access_policy_type = "Custom access policy"
|
# access_policy_type = "Custom access policy"
|
||||||
# access_policy_number = 1 # número de la política DOT1X-CORPO (id=1)
|
# access_policy_number = 1 # id de la política DOT1X-CORPO
|
||||||
# },
|
# },
|
||||||
|
#
|
||||||
|
# # Puertos designados para impresoras (sin 802.1X)
|
||||||
|
# # La VLAN la asigna Meraki Group Policy por MAC; vlan=103 es el fallback estático
|
||||||
|
# {
|
||||||
|
# serial = "XXXX-XXXX-XXXX"
|
||||||
|
# port_range = "21-24"
|
||||||
|
# type = "access"
|
||||||
|
# vlan = 103 # PRINTERS - fallback si la MAC no tiene Group Policy
|
||||||
|
# access_policy_type = "Open"
|
||||||
|
# },
|
||||||
|
#
|
||||||
|
# # Puerto de uplink (trunk, sin autenticación)
|
||||||
|
# {
|
||||||
|
# serial = "XXXX-XXXX-XXXX"
|
||||||
|
# port_range = "28"
|
||||||
|
# type = "trunk"
|
||||||
|
# access_policy_type = "Open"
|
||||||
|
# },
|
||||||
|
#
|
||||||
# ]
|
# ]
|
||||||
switch_port_configs = []
|
switch_port_configs = []
|
||||||
|
|||||||
Reference in New Issue
Block a user