F5F Stay Refreshed Power Users Networks Isolation port configuration on MikroTik devices

Isolation port configuration on MikroTik devices

Isolation port configuration on MikroTik devices

B
bigcow666
Member
73
07-07-2024, 09:30 PM
#1
Hi everyone. I'm using a Mikrotik HAP Lite router with Nextcloud set up on Ethernet port 4, a WAN port on Ethernet port 1, and LAN connected via Ethernet port 2. After initial setup in RuterOS, I removed Ethernet port 4 from the bridge and enabled port isolation. Now Nextcloud is only allowed to communicate through Ethernet port 1 (WAN). My concern is whether this setup protects my network: if someone compromises the Nextcloud server, can they still reach my PCs on Ethernet port 2?
B
bigcow666
07-07-2024, 09:30 PM #1

Hi everyone. I'm using a Mikrotik HAP Lite router with Nextcloud set up on Ethernet port 4, a WAN port on Ethernet port 1, and LAN connected via Ethernet port 2. After initial setup in RuterOS, I removed Ethernet port 4 from the bridge and enabled port isolation. Now Nextcloud is only allowed to communicate through Ethernet port 1 (WAN). My concern is whether this setup protects my network: if someone compromises the Nextcloud server, can they still reach my PCs on Ethernet port 2?

T
129
07-17-2024, 02:21 AM
#2
You're wondering if hosting your Nextcloud server in a DMZ isn't feasible.
T
timmecraft2002
07-17-2024, 02:21 AM #2

You're wondering if hosting your Nextcloud server in a DMZ isn't feasible.

T
TommyTheLommy
Posting Freak
846
07-18-2024, 10:49 PM
#3
I don’t understand how to set it up. I’m using Nextcloud with a Nginx reverse proxy, which is a configuration I’m comfortable with. I think running the service on an isolated port on Mikrotik should work, but I’m not sure. When I try to reach my local PC from the Nextcloud VM via the command line, it times out.
T
TommyTheLommy
07-18-2024, 10:49 PM #3

I don’t understand how to set it up. I’m using Nextcloud with a Nginx reverse proxy, which is a configuration I’m comfortable with. I think running the service on an isolated port on Mikrotik should work, but I’m not sure. When I try to reach my local PC from the Nextcloud VM via the command line, it times out.

M
mumustrak
Senior Member
729
07-25-2024, 10:31 AM
#4
Enhance your network by adding VLANs using Inter-VLAN Routing. This should cover most needs. For details, check the provided links. If unsure, feel free to ask.
M
mumustrak
07-25-2024, 10:31 AM #4

Enhance your network by adding VLANs using Inter-VLAN Routing. This should cover most needs. For details, check the provided links. If unsure, feel free to ask.