- Add sites/BCN01-LAB with full Meraki configuration: VLANs, SSIDs, switch ports, 802.1X policy, firewall rules, WAN uplinks and warm spare - Extend modules/meraki-site to support wan2_* fields in mx_wan_uplinks Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1.2 KiB
Pasos manuales — BCN01-LAB
Configuraciones que no pueden gestionarse via Terraform (limitaciones del provider v1.9.0) y deben aplicarse directamente en el Meraki Dashboard.
Client VPN (L2TP/IPSec)
Dashboard: Security & SD-WAN → Client VPN
| Parámetro | Valor |
|---|---|
| Estado | Enabled |
| Subnet VPN | 10.2.58.0/23 |
| Authentication | RADIUS |
| RADIUS server | IP del Okta RADIUS Agent, puerto 1812 |
| RADIUS secret | Ver secret de Okta RADIUS Agent |
Nota: El provider
CiscoDevNet/merakiv1.9.0 no incluye el resourcemeraki_appliance_vpn_client_vpn. Cuando el provider lo soporte, esta configuración deberá migrarse asites/BCN01-LAB/vpn.auto.tfvars.
OWE (Opportunistic Wireless Encryption) — SSID EQT-CORPO
Note: This is not a provider limitation. The provider manages
auth_mode = "open-enhanced"correctly.
Dashboard: Wireless → SSIDs → EQT-CORPO → Edit settings → Security
After the first terraform apply, verify that "Opportunistic Wireless Encryption" is active in the Dashboard. In some cases Meraki requires a one-time manual confirmation click to enable OWE on a new SSID, even though Terraform has already pushed the correct configuration.