Firewall considerations with LTE passthrough interface

Greetings,
Couldn’t find an answer to this in the forums already but I wanted to resolve a nagging question in the back of my mind.

I have an SXT LTE6 kit as my main internet connection. This has the ether1 interface setup as a passthrough to a Hex S router. All is working great, but I haven’t been able to figure out what if any firewall I should setup on the SXT device. Because it’s doing passthrough, am I safe with no firewall setup at all on the SXT, and rely on the firewall in the Hex S as my frontline defence?

I followed these instructions to get setup: https://wiki.mikrotik.com/wiki/Manual:Interface/LTE#Passthrough_Example

What is the recommended firewall setup for an SXT device in this configuration?

Thanks for your help!

Very good question I have not thought about since I dont have one.
Here is the updated reference doc…

https://help.mikrotik.com/docs/display/ROS/LTE

It would appear that the LTE is simply used to apply modem type parameters (to verify traffic coming over assigned IP is legit)?
In any case not sure of the purpose, but it doesnt look like the LTE is doing anything special.

However you have to be able to login to the device and you want that capability to be secure and from your router and not the internet.
Hmmmm…
Is there a default config from the LTE when you first login… that may give some clues…

Hello,

if it can help you, i had a discussion with SiB about this here

http://forum.mikrotik.com/t/chateau-lte-passthrough-and-bridge-on-other-ports/158270/1

When you use your LTE device in passthrough mode, then the LTE device is responsible only for the Modem settings…
It does not have internet itself, but instead it needs your Router to access the internet i.e. the device that the passthrough is going to.

So, no, you don’t need firewall on the LTE device when passthrough mode is active.

Excellent - thanks for the updated info and the links.

Makes sense - once the interface is consumed as the passthrough device, the only way I can communicate with the SXT is through RoMON.

Thanks all.

You can solve that with VLANs…