Commit Graph
12 Commits
Author SHA1 Message Date
Jose MartinezandClaude Sonnet 4.6 85ef316745 feat(bcn01-lab): restrict 1:1 NAT to specific service ports, allow any source
Replace open any/any inbound rule on Synology NAT with explicit TCP ports:
443 (Synology), 9890 (Vaultwarden), 4769 (Zabbix), 8080 (Snipe-IT),
3000 (Metabase), 3333 (Gitea), 8081 (phpIPAM). Access allowed from any IP.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-07 10:30:29 +02:00
Jose MartinezandClaude Sonnet 4.6 6d0f186795 fix(meraki-site): correct 1:1 NAT resource type name
meraki_appliance_firewall_one_to_one_nat_rules does not exist in
provider v1.9.0; correct name is meraki_appliance_one_to_one_nat_rules.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-07 09:52:27 +02:00
Jose MartinezandClaude Sonnet 4.6 b8e517cb40 feat(bcn01-lab): add 1:1 NAT support and import Synology rule
Add meraki_appliance_firewall_one_to_one_nat_rules resource to the
meraki-site module and codify the existing Synology NAT rule found in
BCN01-LAB Dashboard (57.133.120.190 → 10.2.56.3 via internet2).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-07 09:42:59 +02:00
Jose MartinezandClaude Sonnet 4.6 4a93967012 fix(bcn01-lab): use null default for radius_secret variable
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-05 07:51:24 +02:00
Jose MartinezandClaude Sonnet 4.6 de90079f32 ci: retrigger apply for BCN01-LAB port 1 sw01
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-29 07:34:00 +02:00
Jose MartinezandClaude Sonnet 4.6 d71ae52979 ci: retrigger apply for BCN01-LAB port 1 sw01
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-29 07:32:30 +02:00
Jose MartinezandClaude Sonnet 4.6 9227e3a1ab fix(bcn01-lab): set DOT1X-CORPO host_mode to Multi-Host to match Dashboard
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-29 07:09:09 +02:00
Jose MartinezandClaude Sonnet 4.6 9184567152 fix(bcn01-lab): correct auth_mode value for EQT-CORPO SSID
Use '8021x-radius' instead of '8021x' — required by CiscoDevNet/meraki provider v1.9.0

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-29 07:04:35 +02:00
Jose MartinezandClaude Sonnet 4.6 29614e1dc4 feat(bcn01-lab): onboard BCN01-LAB site and extend module with WAN2 support
- Add sites/BCN01-LAB with full Meraki configuration: VLANs, SSIDs,
  switch ports, 802.1X policy, firewall rules, WAN uplinks and warm spare
- Extend modules/meraki-site to support wan2_* fields in mx_wan_uplinks

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-29 07:02:06 +02:00
Jose Martinez fea7b85099 fix: remove wpa_encryption_mode to fix MAC-based AC incompatibility 2026-03-16 18:44:57 +01:00
Jose Martinez bbe4921bc9 fix: use radius_servers as list attribute in wireless SSID 2026-03-16 17:18:07 +01:00
Jose Martinez c1595cd9d5 feat: add EQT-CORPO SSID with OWE and Okta RADIUS 2026-03-16 17:13:40 +01:00