Community discussions

MikroTik App
 
washdogg87
just joined
Topic Author
Posts: 7
Joined: Thu Nov 14, 2019 2:58 pm

Firewall considerations with LTE passthrough interface

Mon Jul 25, 2022 6:34 pm

Greetings,
Couldn't find an answer to this in the forums already but I wanted to resolve a nagging question in the back of my mind.

I have an SXT LTE6 kit as my main internet connection. This has the ether1 interface setup as a passthrough to a Hex S router. All is working great, but I haven't been able to figure out what if any firewall I should setup on the SXT device. Because it's doing passthrough, am I safe with no firewall setup at all on the SXT, and rely on the firewall in the Hex S as my frontline defence?

I followed these instructions to get setup: https://wiki.mikrotik.com/wiki/Manual:I ... gh_Example

What is the recommended firewall setup for an SXT device in this configuration?

Thanks for your help!
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19323
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Firewall considerations with LTE passthrough interface

Mon Jul 25, 2022 6:47 pm

Very good question I have not thought about since I dont have one.
Here is the updated reference doc..........

https://help.mikrotik.com/docs/display/ROS/LTE

It would appear that the LTE is simply used to apply modem type parameters (to verify traffic coming over assigned IP is legit)?
In any case not sure of the purpose, but it doesnt look like the LTE is doing anything special.

However you have to be able to login to the device and you want that capability to be secure and from your router and not the internet.
Hmmmm..........
Is there a default config from the LTE when you first login....... that may give some clues.........
 
nonosch68
just joined
Posts: 12
Joined: Thu May 26, 2022 1:03 am

Re: Firewall considerations with LTE passthrough interface

Tue Jul 26, 2022 1:03 pm

Hello,

if it can help you, i had a discussion with SiB about this here

viewtopic.php?t=186253
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: Firewall considerations with LTE passthrough interface  [SOLVED]

Tue Jul 26, 2022 4:22 pm

When you use your LTE device in passthrough mode, then the LTE device is responsible only for the Modem settings...
It does not have internet itself, but instead it needs your Router to access the internet i.e. the device that the passthrough is going to.

So, no, you don't need firewall on the LTE device when passthrough mode is active.
 
washdogg87
just joined
Topic Author
Posts: 7
Joined: Thu Nov 14, 2019 2:58 pm

Re: Firewall considerations with LTE passthrough interface

Thu Jul 28, 2022 8:53 pm

Excellent - thanks for the updated info and the links.

Makes sense - once the interface is consumed as the passthrough device, the only way I can communicate with the SXT is through RoMON.

Thanks all.
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: Firewall considerations with LTE passthrough interface

Mon Aug 01, 2022 4:04 pm

Excellent - thanks for the updated info and the links.

Makes sense - once the interface is consumed as the passthrough device, the only way I can communicate with the SXT is through RoMON.

Thanks all.
You can solve that with VLANs...

Who is online

Users browsing this forum: No registered users and 40 guests