How to Build a PCI-Ready UniFi Network for Tenants
Network Devices VLAN, Guest VLAN, Camera VLAN β PCI compliance is a network structure. MKR Systems configures UniFi f...
43% of cyberattacks target small businesses. Enterprise-level protection is no longer optional β and with the right open-source stack, it's no longer out of reach.
The Complete Stack
Most small business IT setups are a collection of disconnected tools β a firewall here, a cloud service there, backups that may or may not work. MKR builds infrastructure where every layer is designed to work with every other layer: security policies flow from identity management, backups integrate with virtualization, and remote access ties into your internal firewall zones.
Most businesses expose services to the internet by opening firewall ports β creating attack surfaces that scanners find within minutes. Cloudflare Tunnel reverses this: your server initiates an outbound-only encrypted connection to Cloudflare's network, so there are no inbound ports to probe. DDoS mitigation and WAF filtering happen at Cloudflare's edge (330+ cities across 120+ countries) before traffic ever touches your infrastructure.
The Double Caddy architecture adds a second layer of protection: a primary reverse proxy handles TLS termination and blocks external attack traffic, while a secondary proxy handles internal app routing and access control. An attacker who bypasses Cloudflare's edge still hits two proxy layers before reaching any application.
A flat network β where every device can reach every other device β is a security disaster waiting to happen. MKR configures zone-based firewall rules on the UniFi Dream Machine Pro: WAN, DMZ (public services), LAN (internal), and IoT each exist in their own security zone with explicit policies controlling what can communicate across boundaries.
Proxmox is enterprise-grade hypervisor software that runs multiple isolated virtual machines and containers on a single physical server (or clustered across several). MKR layers three redundancy systems on top: ZFS for automatic disk-level recovery inside a server, DRBD for real-time replication across servers, and Proxmox Backup Server for deduplicated, ransomware-resistant backups.
When every service has its own login, security falls apart fast β people reuse passwords, share credentials, and leaving employees retain access for months. FreeIPA (built on Red Hat Enterprise Linux technology) provides centralized LDAP directory, Kerberos authentication, DNS, and a Certificate Authority. Keycloak connects it all to web applications via OIDC, SAML, and OAuth 2.0.
Network storage that anyone on the network can access is not storage β it is a liability. MKR configures Samba as a domain member of FreeIPA, so only computers and users that have authenticated against the directory can access NAS shares. Unverified devices are blocked at the authentication layer, not just at the firewall.
Instead of paying SaaS subscriptions for every tool β and trusting third-party servers with your business data β MKR builds a self-hosted workspace where every application integrates with Keycloak SSO and is accessible only through VPN. Your data stays on your infrastructure, under your control.
Attack Defense
Layer 07
Zero Trust is not a product β it is a design principle. Every access request, from every user and device, on every network (including your own internal LAN), is treated as untrusted until verified. MKR's 7-layer stack applies Zero Trust principles β identity-verified access at every layer through FreeIPA, Keycloak SSO, and Cloudflare Access β rather than trusting the network perimeter. (Full per-request enforcement to NIST SP 800-207 is achieved by placing Cloudflare Access in front of every internal app.)
Common Questions
Zero Trust means no user, device, or connection is automatically trusted β even inside your own network. Every access request must be verified. Small businesses need this because 43% of cyberattacks target small companies, and a single compromised credential can expose everything. MKR applies Zero Trust principles through Cloudflare Tunnel, FreeIPA, Keycloak SSO, and Cloudflare Access so every service requires identity verification before granting access.
A Cloudflare Tunnel creates an outbound-only encrypted connection from your server to Cloudflare's network, eliminating the need to open any inbound ports on your firewall. Attackers cannot scan for or probe what does not exist. DDoS protection and WAF filtering happen at Cloudflare's edge β across 330+ cities in 120+ countries β before any traffic reaches your infrastructure.
Proxmox is an enterprise virtualization platform that runs multiple services on one physical server (or cluster). MKR combines it with ZFS for automatic disk recovery, DRBD for real-time server-to-server replication, and Proxmox Backup Server for deduplicated, ransomware-resistant backups. PBS deduplication and compression typically reduce backup storage 5β10Γ (this is deduplication, not raw compression, and varies by workload). If a disk fails, ZFS recovers automatically. If a server fails, DRBD quorum-based failover (via DRBD Reactor or Pacemaker) restores service within sub-minute.
FreeIPA (built on Red Hat technology) is centralized identity management combining LDAP, Kerberos, DNS, and a Certificate Authority. Keycloak connects it to all web applications using OIDC, SAML, and OAuth 2.0. Together, one account accesses everything β and when an employee leaves, disabling one account immediately blocks access to every service. No more shared passwords, forgotten credential revocations, or orphaned accounts.
Microsoft 365 and Google Workspace are hosted on third-party servers and charge per-seat licensing fees. MKR's stack is self-hosted on your own infrastructure β your data stays under your control. The open-source tools (Proxmox, FreeIPA, Nextcloud, Cloudflare) eliminate per-seat fees and vendor lock-in. For teams handling sensitive data β healthcare, legal, financial, or any regulated industry β self-hosted is often a compliance necessity, not just a preference.
MKR analyzes your current setup and proposes the optimal configuration for your team size and budget.
No per-seat licensing. No vendor lock-in. Enterprise-grade security, sized for you.
888-382-5164Free On-Site Assessment Β· MKR Technology Solutions Β· La Mesa, CA 91941
Los Angeles Β· Orange County Β· Riverside Β· San Diego Β· Southern California
β¬ Download the Full PDF Guide β Free Infrastructure Assessment Learn More at makeonline.io βRelated Reading on cloverpos.io
PCI-Ready UniFi Network β Fiber + 5G Failover β UniFi Firewall + IDS/IPS β UDM Pro Recovery Case Study βMKR Technology Solutions provides IT infrastructure design, deployment, and management for small businesses and enterprise teams in Southern California. This article describes a complete infrastructure buildout approach using open-source enterprise tools. Specific configurations vary based on organization size, compliance requirements, and existing infrastructure. Contact MKR at 888-382-5164 for a tailored assessment.
Request a free quote and site survey for fiber, network, and structured cabling tailored to your building.
Request a Quote