feat(bcn01-lab): set port 15 sw01 to SERVERS VLAN (110) access mode
131 lines
4.2 KiB
Terraform
131 lines
4.2 KiB
Terraform
locals {
|
|
# 802.1X access policies
|
|
# The RADIUS shared secret is injected from var.radius_secret — never put it here.
|
|
switch_access_policies = [
|
|
{
|
|
name = "DOT1X-CORPO"
|
|
access_policy_type = "802.1x"
|
|
host_mode = "Multi-Host"
|
|
radius_accounting_enabled = false
|
|
radius_re_authentication_interval = 0
|
|
url_redirect_walled_garden_enabled = false
|
|
radius_failed_auth_vlan_id = 101 # Fallback to GUEST if RADIUS unreachable
|
|
radius_servers = [
|
|
{ host = "10.2.56.5", port = 1812 }
|
|
]
|
|
},
|
|
]
|
|
|
|
# Ports by explicit serial — use when targeting a switch directly by serial number
|
|
# Example:
|
|
# switch_port_configs = [
|
|
# {
|
|
# serial = "XXXX-XXXX-XXXX"
|
|
# port_range = "1-20"
|
|
# type = "access"
|
|
# vlan = 100 # ACCESS — fallback if RADIUS doesn't assign a VLAN
|
|
# access_policy_type = "Custom access policy"
|
|
# access_policy_number = 1 # references DOT1X-CORPO above
|
|
# },
|
|
# ]
|
|
switch_port_configs = []
|
|
|
|
# Ports by stack name — Terraform resolves serials for all stack members automatically.
|
|
# The same port_range is applied to EVERY switch in the stack.
|
|
switch_stack_port_configs = [
|
|
{
|
|
stack_name = "bcn01-lab-stack01"
|
|
port_range = "47"
|
|
name = "UPLINK LAN BCN01-F04-MX01"
|
|
type = "trunk"
|
|
vlan = 109 # MANAGEMENT — native (untagged) VLAN
|
|
allowed_vlans = "all"
|
|
access_policy_type = "Open"
|
|
},
|
|
{
|
|
stack_name = "bcn01-lab-stack01"
|
|
port_range = "48"
|
|
name = "UPLINK LAN BCN01-F04-MX02"
|
|
type = "trunk"
|
|
vlan = 109 # MANAGEMENT — native (untagged) VLAN
|
|
allowed_vlans = "all"
|
|
access_policy_type = "Open"
|
|
},
|
|
]
|
|
|
|
# Ports by switch display name — targets a specific stack member without knowing its serial
|
|
switch_named_port_configs = [
|
|
{
|
|
switch_name = "eqt-lab-st01-sw01"
|
|
port_range = "11"
|
|
name = "MANAGEMENT"
|
|
type = "access"
|
|
vlan = 109 # MANAGEMENT
|
|
access_policy_type = "Open"
|
|
},
|
|
{
|
|
switch_name = "eqt-lab-st01-sw01"
|
|
port_range = "12"
|
|
name = "SERVERS"
|
|
type = "access"
|
|
vlan = 110 # SERVERS
|
|
access_policy_type = "Open"
|
|
},
|
|
{
|
|
switch_name = "eqt-lab-st01-sw01"
|
|
port_range = "1"
|
|
name = "Servers"
|
|
type = "access"
|
|
vlan = 110 # SERVERS
|
|
access_policy_type = "Open"
|
|
},
|
|
{
|
|
switch_name = "eqt-lab-st01-sw01"
|
|
port_range = "2,3"
|
|
name = "WAN"
|
|
type = "access"
|
|
vlan = 111 # WAN
|
|
access_policy_type = "Open"
|
|
},
|
|
{
|
|
switch_name = "eqt-lab-st01-sw02"
|
|
port_range = "2,3"
|
|
name = "WAN"
|
|
type = "access"
|
|
vlan = 111 # WAN
|
|
access_policy_type = "Open"
|
|
},
|
|
{
|
|
switch_name = "eqt-lab-st01-sw01"
|
|
port_range = "15"
|
|
name = "SERVERS"
|
|
type = "access"
|
|
vlan = 110 # SERVERS
|
|
access_policy_type = "Open"
|
|
},
|
|
{
|
|
switch_name = "eqt-lab-st01-sw01"
|
|
port_range = "37"
|
|
name = "AP"
|
|
type = "trunk"
|
|
vlan = 108 # APs — native (untagged) VLAN
|
|
allowed_vlans = "100,101,108" # ACCESS + GUEST + APs
|
|
access_policy_type = "Open"
|
|
},
|
|
]
|
|
|
|
switch_management_vlan = 109
|
|
|
|
# L3 routing interfaces on the stack (SVIs for management access to Meraki Dashboard)
|
|
stack_routing_interfaces = [
|
|
{
|
|
stack_name = "bcn01-lab-stack01"
|
|
name = "MANAGEMENT"
|
|
vlan_id = 109
|
|
ip_address = "10.2.55.2"
|
|
subnet = "10.2.55.0/24"
|
|
default_gateway = "10.2.55.1"
|
|
},
|
|
]
|
|
}
|