Comment by ornornor
You can put the public facing stuff on a separate VLAN and have firewall rules that don’t give the VLAN access to LAN stuff. I only know how to do this with IPv4 though, IPv6 confuses me and I’m scared to get it wrong so I disabled it.