Add meraki_appliance_firewall_one_to_one_nat_rules resource to the meraki-site module and codify the existing Synology NAT rule found in BCN01-LAB Dashboard (57.133.120.190 → 10.2.56.3 via internet2). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
35 lines
820 B
Terraform
35 lines
820 B
Terraform
locals {
|
|
one_to_one_nat_rules = [
|
|
{
|
|
name = "Synology"
|
|
public_ip = "57.133.120.190"
|
|
lan_ip = "10.2.56.3"
|
|
uplink = "internet2"
|
|
allowed_inbound = [
|
|
{
|
|
protocol = "any"
|
|
destination_ports = ["Any"]
|
|
allowed_ips = ["188.0.0.0/8"]
|
|
},
|
|
{
|
|
protocol = "any"
|
|
destination_ports = ["Any"]
|
|
allowed_ips = ["57.133.120.176/28"]
|
|
},
|
|
]
|
|
},
|
|
]
|
|
|
|
appliance_ports = [
|
|
{
|
|
# Port 7: trunk toward the switch stack
|
|
# Native VLAN 109 (MANAGEMENT), allows all VLANs
|
|
port_id = "7"
|
|
enabled = true
|
|
type = "trunk"
|
|
vlan = 109 # MANAGEMENT — native (untagged) VLAN
|
|
allowed_vlans = "all"
|
|
},
|
|
]
|
|
}
|