Greetings,
I have a super simple network setup in our RV which consists of a single hAP ac Lite (RB952Ui-5ac2nD) running RouterOS v6.43.2. WAN is ether1 or the single USB port to a cellular LTE modem. either2-either5 and wlan1-wlan2 are bridged into a single LAN. Hardware offloading is being used on the ethernet ports. The firewall filters and NAT rules are stock, except a couple of filters and one NAT rule added to cover the cellular LTE modem as WAN. In other words, there's nothing too fancy here.
I have a ham radio (a.k.a.: amateur radio) communications device that I want to connect to this network through one of the hAP ac lite's ethernet ports so it access the internet. This device requires opening various ports to work (port forwarding) which normally isn't possible upstream through a cellular network. To "pierce through" the blocked ports of the cellular provider, the device establishes a VPN connection. The VPN provider has ALL ports open with no way to turn any of them off, so it's similar to having the device in a DMZ. Because of the security risk associated with this, I don't trust having this device on my main (and currently only) network. So I'd like to isolate it so it can't interact with my network just in case it becomes compromised. The catch is I still need to access to the device from my main network to control it using SSH and via its built-in web server.
So here's my question:
What's the best way for me to isolate this device to a single ethernet port on the hAP ac lite, but still allow me to connect to it from at least one PC on my main network, but not the other way around?
I presume I need to somehow set up a second isolated LAN and create new firewall filters and NAT rules?
I've read about Port Isolation, VLAN's, Private VLAN's, trunks, creating multiple bridges, creating multiple switches... and I'm so confused!
Thanks in advance,
John
AA7US