Community discussions

MikroTik App
 
elico
Member Candidate
Member Candidate
Topic Author
Posts: 147
Joined: Mon Nov 07, 2016 3:23 am

Is it possible to protect RouterOS webfig with nginx or haproxy container?

Sat Nov 11, 2023 11:23 am

I have seen that lets encrypt can be used on RouterOS devices.
The drawback is to open port 80 to the world and there are workarounds using /ip/firewall/xyz rules to block port 80 and allow to only specific sources.
There is another option and it's to use some kind of reverse proxy such as nginx or haproxy or others... with some ACLs that will only pass through the relevant path to the webfig port 80 while showing another static page for all other port 80 traffic.
Have anyone tried to do such a thing?
I believe that a simple WAF exists in a container already and if someone wants to tinker a bit with coraza you can try to modify:
https://github.com/docker-servers/coraza-caddy

for RouterOS.

Who is online

Users browsing this forum: No registered users and 2 guests