locals { firewall_rules = [ { comment = "Allow ACCESS to internet" policy = "allow" protocol = "any" src_cidr = "10.2.32.0/21" # VLAN 100 - ACCESS dest_cidr = "any" }, { comment = "Allow MANAGEMENT to internet (Meraki Dashboard access)" policy = "allow" protocol = "any" src_cidr = "10.2.55.0/24" # VLAN 109 - MANAGEMENT dest_cidr = "any" }, { comment = "Allow APs to internet (Meraki Dashboard access)" policy = "allow" protocol = "any" src_cidr = "10.2.54.0/24" # VLAN 108 - APs dest_cidr = "any" }, { comment = "Allow GUEST to internet" policy = "allow" protocol = "any" src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST dest_cidr = "any" }, { comment = "Allow SERVERS to internet" policy = "allow" protocol = "any" src_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS dest_cidr = "any" }, { comment = "Allow GUEST to SERVERS" policy = "allow" protocol = "any" src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST dest_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS }, { comment = "Test" policy = "allow" protocol = "any" src_cidr = "10.212.0.0/16" dest_cidr = "10.212.225.51/32,10.2.56.5/32" }, { comment = "Allow VPN outbound traffic" policy = "allow" protocol = "any" src_cidr = "10.2.58.0/23" # Client VPN subnet dest_cidr = "any" }, { comment = "Deny all other outbound traffic" policy = "deny" protocol = "any" src_cidr = "any" dest_cidr = "any" }, ] }