Does 2nd WAN need it's own ethernet port

Using a hEX PoE for main router and a few wAP ac’s in home network (set to handoff clients…horrible faraday cage house).

I currently have a cable modem as primary WAN through a dedicated ethernet port.

I want to add Starlink as an ‘emergency’ failover (fallback) WAN.

Due to the terrible design of the house and where the equipment rack is, I shudder in fear of running another dedicated ethernet line direcly from the router.

My target chunk of CAT6 already has an AP with PoE (outside).

Is it possible to have the fallback WAN sitting on an existing part of the network?
…can I VLAN it into the router?
Is the only realistic answer ‘just’ run another ethernet line?

Thanks.
Mic

What you can do is get another hex or managed tplink type switch at where equipment can be placed with ethernet cable.
On the single cable from this switch to the router YES, you can run vlans including a vlan to carry the internet signal from any ISP device to the router for termination.

But of course your external AP needs to have a free ethernet port to connect the Starlink, the wap AC has only one, so you need a switch or anyway a managed device (better if inside) to connect the Cat6 cable from the hex to the AP and to the Starlink.

If you need to put it outdoors, the PowerBox Pro is the only possible choice AFAICT:
https://mikrotik.com/product/RB960PGS-PB

But you could replace the WapAC with a wAPAx that has two ports.
https://mikrotik.com/product/wap_ax

I was thinking of running the line to the Netpower Lite…then one port to the AP, other port VLAN for the starlink.

I have to make sure it is a direct line from the External to the Router…I don’t remember how I wired it…I don’t think I can run that through another switch…unless that switch is also managed with VLAN routing?

Mic

Well, if you have a Netpower Lite it should have VLAN support (even if it runs SwOS Lite).

Going through non-managed switch(es) may (or may not) work, it depends on the specific switch make/model behaviour, some let VLANs “pass through” without changes and work just fine, some may strip the VLAN tags or downright drop the VLAN packets.