Files
eqt-network-meraki/sites/BCN01-LAB/appliance.tf
Jose MartinezandClaude Sonnet 4.6 85ef316745 feat(bcn01-lab): restrict 1:1 NAT to specific service ports, allow any source
Replace open any/any inbound rule on Synology NAT with explicit TCP ports:
443 (Synology), 9890 (Vaultwarden), 4769 (Zabbix), 8080 (Snipe-IT),
3000 (Metabase), 3333 (Gitea), 8081 (phpIPAM). Access allowed from any IP.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-07 10:30:29 +02:00

30 lines
713 B
Terraform

locals {
one_to_one_nat_rules = [
{
name = "Synology"
public_ip = "57.133.120.190"
lan_ip = "10.2.56.3"
uplink = "internet2"
allowed_inbound = [
{
protocol = "tcp"
destination_ports = ["443", "9890", "4769", "8080", "3000", "3333", "8081"]
allowed_ips = ["Any"]
},
]
},
]
appliance_ports = [
{
# Port 7: trunk toward the switch stack
# Native VLAN 109 (MANAGEMENT), allows all VLANs
port_id = "7"
enabled = true
type = "trunk"
vlan = 109 # MANAGEMENT — native (untagged) VLAN
allowed_vlans = "all"
},
]
}