This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
forward-dmz [2023/06/24 18:15] – hogwild | forward-dmz [2024/11/27 01:48] (current) – hogwild | ||
---|---|---|---|
Line 1: | Line 1: | ||
===== DMZ ===== | ===== DMZ ===== | ||
- | On a more sophisticated network, the DMZ (Demilitarized Zone) is a specific area of the network where services are provided in a secure way. However, in FreshTomato, | + | On a sophisticated network, the DMZ (Demilitarized Zone) is a specific area of the network where services are provided in a secure way. However, in FreshTomato, |
- | \\ | + | |
- | \\ | + | |
- | **Enable DMZ**: This turns the DMZ function on or off. | + | |
- | **Destination Address**: This is the LAN IP address of the device meant to receive all these forwarded ports. | + | Since it opens a large security hole, consider DMZ a " |
\\ | \\ | ||
- | [[https://wiki.freshtomato.org/ | + | **Destination Address**: the LAN IP address of the device to receive all these forwarded ports. |
\\ | \\ | ||
- | **Destination Interface**: This is the VLAN/bridge where the above host can be found. | + | [[https:// |
- | **Source Address Restriction**: | + | \\ |
- | **Leave Remote Access**: If enabled, | + | **Destination Interface**: this is the VLAN/bridge where the above host can be found. |
- | \\ | + | \\ |
+ | |||
+ | **Source Address Restriction**: | ||
+ | |||
+ | The Default is empty, which means ports from any address/ | ||
\\ | \\ | ||
+ | |||
+ | **Leave Remote Access**: if enabled, forces FreshTomato to always answer SSH (TCP/22) and HTTP (TCP/443) traffic, regardless of DMZ settings. | ||
+ | |||
+ | \\ \\ \\ | ||