Añade regla de firewall L3 en posición 3 para permitir
que los clientes de la VLAN GUEST (10.2.40.0/21) accedan
a internet.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
La API de Meraki requiere encryption_mode="wpa" cuando auth_mode="psk",
además de wpa_encryption_mode. Sin este campo la API devuelve el error
"Pre-shared key mode requires a valid encryption mode (wep, wpa)".
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- ssids.auto.tfvars: eliminada referencia var.wifi_password_psk (inválida
en ficheros tfvars)
- main.tf: psk usa each.value.psk si está definido, sino cae en
var.wifi_password_psk (TF_VAR_wifi_password_psk desde GitHub Secrets)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- _expand_range ahora procesa segmentos separados por coma, cada uno
puede ser un puerto único o un rango numérico (1-48).
Ejemplos: "2,3" -> ["2","3"] | "1-3,5,47" -> ["1","2","3","5","47"]
- switch.auto.tfvars: puertos 2 y 3 de eqt-lab-st01-sw01 consolidados
en una sola entrada con port_range = "2,3"
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Añadido puerto 2 de eqt-lab-st01-sw01 como trunk AP con VLAN nativa
108 (APs) y tageadas 100 (ACCESS) y 101 (GUEST), igual que puerto 3
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- meraki_appliance_vlan: filtrar VLANs sin subnet (if v.subnet != null)
para que VLAN 111 WAN (L2-only) no se pase a la API del MX, que exige
CIDR en el campo subnet.
- meraki_wireless_ssid: pasar wpa_encryption_mode = null cuando
auth_mode = "open", ya que la API Meraki rechaza modos WPA con auth
abierta. OWE/Enhanced Open se negocia a nivel beacon y no se expone
como atributo API.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Puerto 3 eqt-lab-st01-sw01: trunk, native 108 (APs), tagged 100+101
- VLAN 111 WAN sin subnet ni appliance_ip (switching puro)
- subnet/appliance_ip pasan a ser opcionales en el módulo
La documentacion (HLD, LLD) se almacena en docs/ localmente
pero no se versiona en el repositorio.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add data source meraki_switch_stacks to resolve member serials by stack name
- Add switch_stack_port_configs variable: specify stack_name + port_range
instead of individual switch serials
- Terraform applies port_range to ALL members of the stack automatically
- Merge switch_port_configs and switch_stack_port_configs into all_ports local
- Add example for bcn01-lab-stack01 (2x48p) in switch.auto.tfvars
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Replace port_id with port_range in variable; add local to expand ranges
into individual port entries before creating meraki_switch_port resources.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add meraki_switch_access_policy resource to module (multi-auth, critical VLAN)
- Add meraki_switch_port resource for per-port policy assignment
- Add switch_access_policies and switch_port_configs variables to module and site
- Create switch.auto.tfvars for BCN01-LAB with 802.1X-CORPO policy
(RADIUS: 15.15.15.15:1912, critical VLAN: 100, host_mode: Multi-Auth)
- switch_port_configs starts empty; add serial + port_id to assign policy to ports
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Rename sites/bcn01/ -> sites/BCN01-LAB/
- Update S3 backend key: bcn01/terraform.tfstate -> BCN01-LAB/terraform.tfstate
- Rename Terraform module: bcn01 -> bcn01_lab
- Update working-directory in apply.yml and plan.yml
- Update job/step names to BCN01-LAB
NOTA: mover manualmente en S3 el objeto
bcn01/terraform.tfstate -> BCN01-LAB/terraform.tfstate
antes de hacer terraform init en el nuevo directorio.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
open-with-radius es para MAC-based RADIUS (sin splash), incompatible
con splash pages. auth_mode=open con custom RADIUS splash es la
combinacion correcta para captive portal + autenticacion RADIUS.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>