locals { firewall_rules = [ { comment = "Allow MANAGEMENT to internet (Meraki Dashboard access)" policy = "allow" protocol = "any" src_cidr = "10.2.55.0/24" # VLAN 109 - MANAGEMENT dest_cidr = "any" }, { comment = "Allow APs to internet (Meraki Dashboard access)" policy = "allow" protocol = "any" src_cidr = "10.2.54.0/24" # VLAN 108 - APs dest_cidr = "any" }, { comment = "Allow GUEST to internet" policy = "allow" protocol = "any" src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST dest_cidr = "any" }, { comment = "Allow SERVERS to internet" policy = "allow" protocol = "any" src_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS dest_cidr = "any" }, { comment = "Allow GUEST to SERVERS (temporary)" policy = "allow" protocol = "any" src_cidr = "10.2.40.0/21" # VLAN 101 - GUEST dest_cidr = "10.2.56.0/24" # VLAN 110 - SERVERS }, { comment = "Deny all other outbound traffic" policy = "deny" protocol = "any" src_cidr = "any" dest_cidr = "any" }, ] }