- Add meraki_switch_access_policy resource to module (multi-auth, critical VLAN) - Add meraki_switch_port resource for per-port policy assignment - Add switch_access_policies and switch_port_configs variables to module and site - Create switch.auto.tfvars for BCN01-LAB with 802.1X-CORPO policy (RADIUS: 15.15.15.15:1912, critical VLAN: 100, host_mode: Multi-Auth) - switch_port_configs starts empty; add serial + port_id to assign policy to ports Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
112 lines
3.4 KiB
Terraform
Executable File
112 lines
3.4 KiB
Terraform
Executable File
# Definición de la Organización
|
|
variable "organization_name" {
|
|
type = string
|
|
description = "Nombre exacto de tu organización en el Dashboard de Meraki"
|
|
}
|
|
|
|
# Definición de la Red
|
|
variable "network_name" {
|
|
type = string
|
|
description = "Nombre de la red (Network) donde reside el switch"
|
|
}
|
|
|
|
|
|
# Reglas de firewall L3
|
|
variable "firewall_rules" {
|
|
type = list(object({
|
|
comment = string
|
|
policy = string
|
|
protocol = string
|
|
src_cidr = string
|
|
src_port = string
|
|
dest_cidr = string
|
|
dest_port = string
|
|
syslog_enabled = optional(bool, false)
|
|
}))
|
|
default = []
|
|
description = "Lista de reglas de firewall L3 para el site"
|
|
}
|
|
|
|
# SSIDs wireless
|
|
variable "wireless_ssids" {
|
|
type = list(object({
|
|
number = number
|
|
name = string
|
|
enabled = optional(bool, true)
|
|
auth_mode = string
|
|
splash_page = optional(string, "None")
|
|
wpa_encryption_mode = optional(string, "WPA3 only")
|
|
ip_assignment_mode = optional(string, "Bridge mode")
|
|
use_vlan_tagging = optional(bool, false)
|
|
default_vlan_id = optional(number, null)
|
|
redirect_url = optional(string, "")
|
|
radius_servers = optional(list(object({
|
|
host = string
|
|
port = number
|
|
})), [])
|
|
}))
|
|
default = []
|
|
description = "Lista de SSIDs wireless a configurar en el site"
|
|
}
|
|
|
|
# Shared secret para servidores RADIUS (sensible, no incluir en tfvars)
|
|
variable "radius_secret" {
|
|
type = string
|
|
sensitive = true
|
|
default = ""
|
|
description = "Shared secret para autenticación RADIUS. Pasar via TF_VAR_radius_secret"
|
|
}
|
|
|
|
# Definición de VLANs
|
|
variable "switch_vlans" {
|
|
type = map(object({
|
|
name = string
|
|
subnet = string
|
|
appliance_ip = string
|
|
dhcp_handling = optional(string, "Run a DHCP server")
|
|
reserved_ip_ranges = optional(list(object({
|
|
comment = string
|
|
id = string
|
|
start = string
|
|
end = string
|
|
})), [])
|
|
}))
|
|
description = "Mapa de configuraciones de VLAN. La clave del mapa será el ID de la VLAN"
|
|
}
|
|
|
|
|
|
# Políticas de acceso 802.1X para switches
|
|
variable "switch_access_policies" {
|
|
type = list(object({
|
|
name = string
|
|
access_policy_type = optional(string, "802.1x")
|
|
host_mode = optional(string, "Multi-Auth")
|
|
radius_accounting_enabled = optional(bool, false)
|
|
radius_failed_auth_vlan_id = optional(number, null)
|
|
radius_re_authentication_interval = optional(number, 0)
|
|
url_redirect_walled_garden_enabled = optional(bool, false)
|
|
radius_servers = list(object({
|
|
host = string
|
|
port = number
|
|
}))
|
|
}))
|
|
default = []
|
|
description = "Políticas de acceso 802.1X para switches MS"
|
|
}
|
|
|
|
# Configuración de puertos de switch
|
|
variable "switch_port_configs" {
|
|
type = list(object({
|
|
serial = string
|
|
port_id = string
|
|
name = optional(string, "")
|
|
type = optional(string, "access")
|
|
vlan = optional(number, null)
|
|
voice_vlan_id = optional(number, null)
|
|
access_policy_type = optional(string, "Open")
|
|
access_policy_number = optional(number, null)
|
|
}))
|
|
default = []
|
|
description = "Puertos de switch a configurar con 802.1X. Requiere serial del switch."
|
|
}
|