Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
120 lines
3.8 KiB
Terraform
Executable File
120 lines
3.8 KiB
Terraform
Executable File
terraform {
|
|
required_providers {
|
|
meraki = {
|
|
source = "CiscoDevNet/meraki"
|
|
version = "1.9.0"
|
|
}
|
|
}
|
|
}
|
|
|
|
# Búsqueda automática de IDs (Data Sources)
|
|
data "meraki_organization" "org" {
|
|
name = var.organization_name
|
|
}
|
|
|
|
data "meraki_networks" "net" {
|
|
organization_id = data.meraki_organization.org.id
|
|
}
|
|
|
|
# Local para extraer el network_id exacto de la lista de redes
|
|
locals {
|
|
network_id = [for n in data.meraki_networks.net.items : n.id if n.name == var.network_name][0]
|
|
}
|
|
|
|
# --- CONFIGURACIÓN GATEWAY (MX) ---
|
|
|
|
# 1. Activar VLANs en el Appliance (MX)
|
|
resource "meraki_appliance_vlans_settings" "activate_vlans" {
|
|
network_id = local.network_id
|
|
vlans_enabled = true
|
|
}
|
|
|
|
# 2. Crear las interfaces L3 y VLANs en el MX
|
|
resource "meraki_appliance_vlan" "mx_gateways" {
|
|
for_each = var.switch_vlans
|
|
depends_on = [meraki_appliance_vlans_settings.activate_vlans]
|
|
|
|
network_id = local.network_id
|
|
vlan_id = each.key
|
|
name = each.value.name
|
|
subnet = each.value.subnet
|
|
appliance_ip = each.value.appliance_ip
|
|
reserved_ip_ranges = each.value.reserved_ip_ranges
|
|
dhcp_handling = each.value.dhcp_handling
|
|
}
|
|
|
|
# 3. SSIDs wireless
|
|
resource "meraki_wireless_ssid" "ssids" {
|
|
for_each = { for s in var.wireless_ssids : tostring(s.number) => s }
|
|
depends_on = [meraki_appliance_vlans_settings.activate_vlans]
|
|
|
|
network_id = local.network_id
|
|
number = each.value.number
|
|
name = each.value.name
|
|
enabled = each.value.enabled
|
|
auth_mode = each.value.auth_mode
|
|
splash_page = each.value.splash_page
|
|
ip_assignment_mode = each.value.ip_assignment_mode
|
|
use_vlan_tagging = each.value.use_vlan_tagging
|
|
default_vlan_id = each.value.default_vlan_id
|
|
radius_servers = length(each.value.radius_servers) > 0 ? [
|
|
for server in each.value.radius_servers : {
|
|
host = server.host
|
|
port = server.port
|
|
secret = var.radius_secret
|
|
}
|
|
] : []
|
|
}
|
|
|
|
# 4. Reglas de firewall L3
|
|
resource "meraki_appliance_l3_firewall_rules" "reglas_firewall" {
|
|
network_id = local.network_id
|
|
rules = var.firewall_rules
|
|
}
|
|
|
|
# --- CONFIGURACIÓN SWITCHES (MS) ---
|
|
|
|
# 5. Políticas de acceso 802.1X
|
|
resource "meraki_switch_access_policy" "dot1x" {
|
|
for_each = { for p in var.switch_access_policies : p.name => p }
|
|
network_id = local.network_id
|
|
|
|
name = each.value.name
|
|
access_policy_type = each.value.access_policy_type
|
|
host_mode = each.value.host_mode
|
|
radius_accounting_enabled = each.value.radius_accounting_enabled
|
|
radius_testing_enabled = each.value.radius_testing_enabled
|
|
radius_coa_support_enabled = each.value.radius_coa_support_enabled
|
|
radius_failed_auth_vlan_id = each.value.radius_failed_auth_vlan_id
|
|
radius_re_authentication_interval = each.value.radius_re_authentication_interval
|
|
url_redirect_walled_garden_enabled = each.value.url_redirect_walled_garden_enabled
|
|
|
|
radius_servers = [
|
|
for server in each.value.radius_servers : {
|
|
host = server.host
|
|
port = server.port
|
|
secret = var.radius_secret
|
|
}
|
|
]
|
|
}
|
|
|
|
# 6. Configuración de puertos de switch
|
|
# Nota: se ejecuta después de crear las políticas para poder referenciar access_policy_number
|
|
resource "meraki_switch_port" "ports" {
|
|
for_each = {
|
|
for p in var.switch_port_configs : "${p.serial}:${p.port_id}" => p
|
|
}
|
|
depends_on = [meraki_switch_access_policy.dot1x]
|
|
|
|
serial = each.value.serial
|
|
port_id = each.value.port_id
|
|
name = each.value.name
|
|
type = each.value.type
|
|
|
|
vlan = each.value.vlan
|
|
voice_vlan_id = each.value.voice_vlan_id
|
|
|
|
access_policy_type = each.value.access_policy_type
|
|
access_policy_number = each.value.access_policy_number
|
|
}
|