Jose Martinez and Claude Sonnet 4.6
b8e517cb40
feat(bcn01-lab): add 1:1 NAT support and import Synology rule
...
Add meraki_appliance_firewall_one_to_one_nat_rules resource to the
meraki-site module and codify the existing Synology NAT rule found in
BCN01-LAB Dashboard (57.133.120.190 → 10.2.56.3 via internet2).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-07 09:42:59 +02:00
Jose Martinez and Claude Sonnet 4.6
4a93967012
fix(bcn01-lab): use null default for radius_secret variable
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-05 07:51:24 +02:00
Jose Martinez and Claude Sonnet 4.6
de90079f32
ci: retrigger apply for BCN01-LAB port 1 sw01
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:34:00 +02:00
Jose Martinez and Claude Sonnet 4.6
d71ae52979
ci: retrigger apply for BCN01-LAB port 1 sw01
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:32:30 +02:00
Jose Martinez and GitHub Enterprise
1157b7cfc7
Merge pull request #22 from its-corp/bcn01-lab
...
feat(bcn01-lab): onboard BCN01-LAB site
2026-04-29 07:13:35 +02:00
Jose Martinez and Claude Sonnet 4.6
9227e3a1ab
fix(bcn01-lab): set DOT1X-CORPO host_mode to Multi-Host to match Dashboard
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:09:09 +02:00
Jose Martinez and Claude Sonnet 4.6
9184567152
fix(bcn01-lab): correct auth_mode value for EQT-CORPO SSID
...
Use '8021x-radius' instead of '8021x' — required by CiscoDevNet/meraki provider v1.9.0
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:04:35 +02:00
Jose Martinez and Claude Sonnet 4.6
29614e1dc4
feat(bcn01-lab): onboard BCN01-LAB site and extend module with WAN2 support
...
- Add sites/BCN01-LAB with full Meraki configuration: VLANs, SSIDs,
switch ports, 802.1X policy, firewall rules, WAN uplinks and warm spare
- Extend modules/meraki-site to support wan2_* fields in mx_wan_uplinks
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:02:06 +02:00
Javier Veral and GitHub Enterprise
097a3c5b6c
Merge pull request #21 from its-corp/feature/multi-site-scalability
...
feat: multi-site scalability, locals refactor, README
2026-04-21 10:33:53 +02:00
Xavier Lario
fde7a160ac
fake change: just to force checks
2026-04-21 10:29:53 +02:00
Xavier Lario
d1839fce7a
temp fix: remove BCN01-LAB to commit just code
2026-04-21 10:26:00 +02:00
Xavier Lario
824ba83f93
fix(ci): use MERAKI_API_KEY env var — correct name for CiscoDevNet/meraki provider
2026-04-21 09:03:57 +02:00
Xavier Lario
79ee5868ee
revert last changes
2026-04-21 08:58:41 +02:00
Xavier Lario
55a6a98044
fix: pass meraki api key explicitly via provider block and TF_VAR
2026-04-20 16:43:24 +02:00
Xavier Lario
6ffe6bfcc5
ix(BCN01-LAB): add required_providers to root module — not inherited from child modules
2026-04-20 16:27:20 +02:00
Xavier Lario
c6dfd9deef
fix(ci): add contents: read permission to plan job
2026-04-20 16:24:10 +02:00
Xavier Lario
01acb2e54d
fix(ci): reset git SSH override before checkout to prevent self-hosted runner state pollution
2026-04-20 16:20:39 +02:00
Xavier Lario
20c9b142fd
fix: problem with the sites discovery
2026-04-20 16:14:17 +02:00
Xavier Lario
a797a18909
fix: change ubuntu for selfhosted for tests
2026-04-20 15:00:24 +02:00
Xavier Lario
43d696a3c6
change: add vscode files to gitignore
2026-04-20 10:24:02 +02:00
Xavier Lario
8ff53503db
feat: multi-site scalability, locals refactor, README
2026-04-20 10:16:49 +02:00
Jose Martinez
881d0ac5b8
docs: add MANUAL_STEPS.md with Client VPN and OWE manual config
2026-04-07 06:28:43 +02:00
Jose Martinez
44f53fa5cb
changing rules
2026-03-27 12:38:37 +01:00
Jose Martinez
e0273cfdb1
feat: remove firewall rules - Acceso Javi, Bloqueo 8.8.8.8, Bloqueo Cloudflare
2026-03-27 12:31:44 +01:00
Jose Martinez
76a0ef9d93
fix: split SSID resource - ssids_open omits wpa_encryption_mode (API rejects it for auth_mode=open)
2026-03-27 12:24:21 +01:00
Jose Martinez
21bdb41e9d
fix: change wpa_encryption_mode default to null to avoid WPA3 incompatibility with open SSIDs
2026-03-27 12:19:53 +01:00
Jose Martinez
e8172f35d7
fix: set wpa_encryption_mode=null for EQT-CORPO-OWE-OK (open incompatible with WPA3)
2026-03-27 12:16:57 +01:00
Jose Martinez and GitHub Enterprise
57c1b9f2a2
Merge pull request #20 from its-corp/feature/bcn01-ssid-encryption-wan-ports
...
wip: add SSID slot 3 placeholder for drift detection via terraform plan
2026-03-27 12:02:16 +01:00
Jose Martinez
e6668edd37
feat: add visible field to SSID module + hide EQT-CORPO-OWE-OK
2026-03-27 11:53:02 +01:00
Jose Martinez
1919e1ffc9
feat: add EQT-CORPO-OWE-OK SSID (slot 2) synced from Dashboard
2026-03-27 11:35:06 +01:00
Jose Martinez
ab3f30469b
fix: sync wpa_encryption_mode WPA3 only for EQT-CORPO OWE + pass through from tfvars
2026-03-27 08:43:08 +01:00
Jose Martinez
27292fddb6
fix: set real name for SSID slot 2 (EQT-CORPO-OWE-OK)
2026-03-27 08:39:00 +01:00
Jose Martinez
02381faf91
fix: SSID slot 3 -> slot 2 (Meraki indexa desde 0)
2026-03-27 08:38:20 +01:00
Jose Martinez
af7f59f3c2
fix: only inject PSK and wpa_encryption_mode for auth_mode=psk SSIDs
2026-03-27 08:37:14 +01:00
Jose Martinez
4cf91c5c96
wip: add SSID slot 3 placeholder for drift detection via terraform plan
2026-03-27 08:32:54 +01:00
Jose Martinez and GitHub Enterprise
cb3fa39a6f
Merge pull request #19 from its-corp/feature/bcn01-ssid-encryption-wan-ports
...
fix: use auth_mode=open-enhanced to match OWE config in Dashboard
2026-03-27 08:28:04 +01:00
Jose Martinez
252695d911
fix: use auth_mode=open-enhanced to match OWE config in Dashboard
2026-03-27 08:26:01 +01:00
Jose Martinez and GitHub Enterprise
65452a8f05
Merge pull request #18 from its-corp/feature/bcn01-ssid-encryption-wan-ports
...
Feature/bcn01 ssid encryption wan ports
2026-03-27 07:26:47 +01:00
Jose Martinez and Claude Sonnet 4.6
30379c343e
docs: add comment explaining OWE API limitation on EQT-CORPO
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-27 07:21:03 +01:00
Jose Martinez and Claude Sonnet 4.6
5cdc09747e
feat: SSID encryption + WAN/uplink switch ports 44-48
...
SSIDs:
- EQT-CORPO: wpa_encryption_mode → null (OWE / Enhanced Open)
- EQT-GUEST: wpa_encryption_mode → WPA3 Transition Mode
Puertos stack bcn01-lab-stack01 (sw01 y sw02):
- Puerto 44: access VLAN 111 WAN — ISP router 1
- Puerto 45: access VLAN 111 WAN — WAN 1 BCN01-F04-MX01
- Puerto 46: access VLAN 111 WAN — WAN 1 BCN01-F04-MX02
- Puerto 47: trunk VLAN nativa 109, todas — UPLINK LAN BCN01-F04-MX01
- Puerto 48: trunk VLAN nativa 109, todas — UPLINK LAN BCN01-F04-MX02
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-27 07:17:42 +01:00
Jose Martinez and GitHub Enterprise
ee0f34bd34
Merge pull request #17 from its-corp/feature/bcn01-ap-internet-rule
...
Feature/bcn01 ap internet rule
2026-03-27 06:30:26 +01:00
Jose Martinez and Claude Sonnet 4.6
493ef14933
fix: add virtual_ip2 10.212.160.40 for WAN2 warm spare
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-27 05:27:52 +01:00
Jose Martinez and Claude Sonnet 4.6
25cf428235
fix: remove virtual_ip2 — WAN2 se desconecta, todo el tráfico por WAN1
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-26 21:33:03 +01:00
Jose Martinez and Claude Sonnet 4.6
0afeda07bc
fix: change virtual_ip2 to free IP (can't use WAN IP itself)
...
La API rechaza que virtual_ip2 coincida con la WAN IP del dispositivo.
Cambiado a 10.212.169.133 (IP libre adyacente en el rango WAN2).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-26 21:27:20 +01:00
Jose Martinez and GitHub Enterprise
363174c2c3
Merge pull request #16 from its-corp/feature/bcn01-ap-internet-rule
...
fix: add virtual_ip2 for WAN2 in warm spare (WAN2 DHCP activo)
2026-03-26 21:25:57 +01:00
Jose Martinez and Claude Sonnet 4.6
4e319962a8
fix: add virtual_ip2 for WAN2 in warm spare (WAN2 DHCP activo)
...
La API de Meraki exige virtual_ip2 cuando WAN2 está activo.
Se usa la IP DHCP actual del primary (10.212.169.132) como VIP WAN2.
Pendiente: hacer reserva DHCP para estabilizar esa IP.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-26 21:20:42 +01:00
Jose Martinez and GitHub Enterprise
5525f12094
Merge pull request #15 from its-corp/feature/bcn01-ap-internet-rule
...
Feature/bcn01 ap internet rule
2026-03-26 21:13:36 +01:00
Jose Martinez and Claude Sonnet 4.6
632205f997
fix: sync dashboard drift — Javi synology rule + Servers port VLAN
...
- Añade regla firewall "Acceso Javi a synology" (posición 4):
allow GUEST (10.2.40.0/21) → 10.2.56.0/24
- Corrige VLAN del puerto Servers (eqt-lab-st01-sw01:1): 110 → 101
para coincidir con el estado actual del Dashboard
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-26 21:10:30 +01:00
Jose Martinez and Claude Sonnet 4.6
c171ebee5f
fix: remove unsupported interfaces_wan1_enabled from device_management_interface
...
El campo no está expuesto en el provider CiscoDevNet/meraki v1.9.0.
Solo se usan los campos de IP estática soportados por el recurso.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-26 21:02:55 +01:00
Jose Martinez and Claude Sonnet 4.6
4a2eeb6c17
feat: add Warm Spare (HA) with VIP for MX appliances
...
Configura meraki_appliance_warm_spare con VIP flotante en WAN1:
- Spare: BCN01-F04-MX02 (serial resuelto por nombre)
- Uplink mode: virtual
- VIP WAN1: 213.229.159.148
La IP de salida del tráfico será siempre la VIP (.148),
independientemente de qué MX esté activo.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-26 20:59:20 +01:00