locals { one_to_one_nat_rules = [ { name = "Synology" public_ip = "57.133.120.190" lan_ip = "10.2.56.3" uplink = "internet2" allowed_inbound = [ { protocol = "tcp" destination_ports = ["443", "3000", "3333", "4769", "5001", "8080", "8081", "9890"] allowed_ips = ["Any"] }, ] }, ] appliance_ports = [ { # Port 7: trunk toward the switch stack # Native VLAN 109 (MANAGEMENT), allows all VLANs port_id = "7" enabled = true type = "trunk" vlan = 109 # MANAGEMENT — native (untagged) VLAN allowed_vlans = "all" }, ] }