Security in LAN, RPI4 and GL-X750v2

Hi
I have GL-X750. I need to connect Raspberry PI 4 to it securely. I have webserver on RPI4 wich hosts some my resources (such as blog, home assistant, control panel from printers and other stuff) on .onion domains (no, I will not buy regular domain, it doesn’t cost wich it costs and no, I don’t consider third level domains, as if owner will want them to shut down I will be in trouble).
So, how to connect RPI4 to X750v2 to make interaction between router, my network and RPI4 impossible to avoid full access if some of this will ever breached?

X750 wired connects to RPi4 with the LAN port.

Based on your actual network and requirement, config the router firewall or RPi4 system firewall, to avoid full access, like only open the special port.