locals { # 802.1X access policies # The RADIUS shared secret is injected from var.radius_secret — never put it here. switch_access_policies = [ { name = "DOT1X-CORPO" access_policy_type = "802.1x" host_mode = "Multi-Host" radius_accounting_enabled = false radius_re_authentication_interval = 0 url_redirect_walled_garden_enabled = false radius_failed_auth_vlan_id = 101 # Fallback to GUEST if RADIUS unreachable radius_servers = [ { host = "10.2.56.5", port = 1812 } ] }, ] # Ports by explicit serial — use when targeting a switch directly by serial number # Example: # switch_port_configs = [ # { # serial = "XXXX-XXXX-XXXX" # port_range = "1-20" # type = "access" # vlan = 100 # ACCESS — fallback if RADIUS doesn't assign a VLAN # access_policy_type = "Custom access policy" # access_policy_number = 1 # references DOT1X-CORPO above # }, # ] switch_port_configs = [] # Ports by stack name — Terraform resolves serials for all stack members automatically. # The same port_range is applied to EVERY switch in the stack. switch_stack_port_configs = [ { stack_name = "bcn01-lab-stack01" port_range = "47" name = "UPLINK LAN BCN01-F04-MX01" type = "trunk" vlan = 109 # MANAGEMENT — native (untagged) VLAN allowed_vlans = "all" access_policy_type = "Open" }, { stack_name = "bcn01-lab-stack01" port_range = "48" name = "UPLINK LAN BCN01-F04-MX02" type = "trunk" vlan = 109 # MANAGEMENT — native (untagged) VLAN allowed_vlans = "all" access_policy_type = "Open" }, ] # Ports by switch display name — targets a specific stack member without knowing its serial switch_named_port_configs = [ { switch_name = "eqt-lab-st01-sw01" port_range = "11" name = "MANAGEMENT" type = "access" vlan = 109 # MANAGEMENT access_policy_type = "Open" }, { switch_name = "eqt-lab-st01-sw01" port_range = "12" name = "SERVERS" type = "access" vlan = 110 # SERVERS access_policy_type = "Open" }, { switch_name = "eqt-lab-st01-sw01" port_range = "1" name = "Servers" type = "access" vlan = 110 # SERVERS access_policy_type = "Open" }, { switch_name = "eqt-lab-st01-sw01" port_range = "2,3" name = "WAN" type = "access" vlan = 111 # WAN access_policy_type = "Open" }, { switch_name = "eqt-lab-st01-sw02" port_range = "2,3" name = "WAN" type = "access" vlan = 111 # WAN access_policy_type = "Open" }, { switch_name = "eqt-lab-st01-sw01" port_range = "37" name = "AP" type = "trunk" vlan = 108 # APs — native (untagged) VLAN allowed_vlans = "100,101,108" # ACCESS + GUEST + APs access_policy_type = "Open" }, ] switch_management_vlan = 109 # L3 routing interfaces on the stack (SVIs for management access to Meraki Dashboard) stack_routing_interfaces = [ { stack_name = "bcn01-lab-stack01" name = "MANAGEMENT" vlan_id = 109 ip_address = "10.2.55.2" subnet = "10.2.55.0/24" default_gateway = "10.2.55.1" }, ] }