# Pasos manuales — BCN01-LAB Configuraciones que no pueden gestionarse via Terraform (limitaciones del provider v1.9.0) y deben aplicarse directamente en el Meraki Dashboard. --- ## Client VPN (L2TP/IPSec) **Dashboard:** Security & SD-WAN → Client VPN | Parámetro | Valor | |-----------|-------| | Estado | Enabled | | Subnet VPN | `10.2.58.0/23` | | Authentication | RADIUS | | RADIUS server | IP del Okta RADIUS Agent, puerto `1812` | | RADIUS secret | Ver secret de Okta RADIUS Agent | > **Nota:** El provider `CiscoDevNet/meraki` v1.9.0 no incluye el resource > `meraki_appliance_vpn_client_vpn`. Cuando el provider lo soporte, esta > configuración deberá migrarse a `sites/BCN01-LAB/vpn.auto.tfvars`. --- ## OWE (Opportunistic Wireless Encryption) — SSID EQT-CORPO > **Note:** This is not a provider limitation. The provider manages `auth_mode = "open-enhanced"` correctly. **Dashboard:** Wireless → SSIDs → EQT-CORPO → Edit settings → Security After the first `terraform apply`, verify that **"Opportunistic Wireless Encryption"** is active in the Dashboard. In some cases Meraki requires a one-time manual confirmation click to enable OWE on a new SSID, even though Terraform has already pushed the correct configuration.