data "aws_availability_zones" "available" { state = "available" } resource "aws_vpc" "this" { cidr_block = local.vpc_cidr enable_dns_support = true enable_dns_hostnames = true tags = { Name = "syslog-server-vpc" } # file-share (PLAT-77) places its subnet in this VPC. Replacing it takes # that share down with the collector. lifecycle { prevent_destroy = true } } resource "aws_internet_gateway" "this" { vpc_id = aws_vpc.this.id tags = { Name = "syslog-server-igw" } lifecycle { prevent_destroy = true } } resource "aws_subnet" "public" { vpc_id = aws_vpc.this.id cidr_block = local.public_subnet_cidr availability_zone = data.aws_availability_zones.available.names[0] map_public_ip_on_launch = true tags = { Name = "syslog-server-public" } } resource "aws_route_table" "public" { vpc_id = aws_vpc.this.id tags = { Name = "syslog-server-public" } } resource "aws_route" "public_default" { route_table_id = aws_route_table.public.id destination_cidr_block = "0.0.0.0/0" gateway_id = aws_internet_gateway.this.id } resource "aws_route" "office_lans" { for_each = toset(local.office_lan_cidrs) route_table_id = aws_route_table.public.id destination_cidr_block = each.value gateway_id = aws_vpn_gateway.office.id } resource "aws_route_table_association" "public" { subnet_id = aws_subnet.public.id route_table_id = aws_route_table.public.id } # Prod has no existing IPsec. Mgmt still owns the 10.20 tunnel. # This VGW is a second child SA so UniFi can reach 10.40.0.0/16 privately. resource "aws_vpn_gateway" "office" { vpc_id = aws_vpc.this.id tags = { Name = "syslog-server-office" } lifecycle { prevent_destroy = true } } resource "aws_customer_gateway" "ronkonkoma" { bgp_asn = local.customer_gateway_bgp_asn ip_address = local.ronkonkoma_wan_ip type = "ipsec.1" tags = { Name = "syslog-server-ronkonkoma" } } resource "aws_vpn_connection" "office" { customer_gateway_id = aws_customer_gateway.ronkonkoma.id vpn_gateway_id = aws_vpn_gateway.office.id type = "ipsec.1" static_routes_only = true tags = { Name = "syslog-server-office" } lifecycle { prevent_destroy = true } } resource "aws_vpn_connection_route" "office_lans" { for_each = toset(local.office_lan_cidrs) destination_cidr_block = each.value vpn_connection_id = aws_vpn_connection.office.id } resource "aws_security_group" "this" { name = "syslog-server" description = "UniFi syslog/IPFIX collector over office IPsec" vpc_id = aws_vpc.this.id tags = { Name = "syslog-server" } } resource "aws_vpc_security_group_egress_rule" "all" { security_group_id = aws_security_group.this.id ip_protocol = "-1" cidr_ipv4 = "0.0.0.0/0" description = "Outbound for Vector install, Firehose, and SSM" } resource "aws_vpc_security_group_ingress_rule" "syslog_tcp" { for_each = toset(local.office_lan_cidrs) security_group_id = aws_security_group.this.id ip_protocol = "tcp" from_port = 514 to_port = 514 cidr_ipv4 = each.value description = "syslog TCP 514 from office LAN" } resource "aws_vpc_security_group_ingress_rule" "syslog_udp" { for_each = toset(local.office_lan_cidrs) security_group_id = aws_security_group.this.id ip_protocol = "udp" from_port = 514 to_port = 514 cidr_ipv4 = each.value description = "syslog UDP 514 from office LAN" } resource "aws_vpc_security_group_ingress_rule" "netflow_2055" { for_each = toset(local.office_lan_cidrs) security_group_id = aws_security_group.this.id ip_protocol = "udp" from_port = 2055 to_port = 2055 cidr_ipv4 = each.value description = "NetFlow/IPFIX UDP 2055 Ronkonkoma" } resource "aws_vpc_security_group_ingress_rule" "netflow_2056" { for_each = toset(local.office_lan_cidrs) security_group_id = aws_security_group.this.id ip_protocol = "udp" from_port = 2056 to_port = 2056 cidr_ipv4 = each.value description = "NetFlow/IPFIX UDP 2056 Locust" }