Site Tools


forward-dmz

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
forward-dmz [2024/10/09 22:56] – -Condense hogwildforward-dmz [2024/11/27 01:48] (current) hogwild
Line 3: Line 3:
 On a sophisticated network, the DMZ (Demilitarized Zone) is a specific area of the network where services are provided in a secure way. However, in FreshTomato, DMZ has a simpler effect. When enabled, all unknown ports on FreshTomato's WAN are forwarded to the defined DMZ host IP address, instead of each being dealt with individually. On a sophisticated network, the DMZ (Demilitarized Zone) is a specific area of the network where services are provided in a secure way. However, in FreshTomato, DMZ has a simpler effect. When enabled, all unknown ports on FreshTomato's WAN are forwarded to the defined DMZ host IP address, instead of each being dealt with individually.
  
-Since it opens a large security hole, consider DMZ a "lazy" and potentially dangerous approach to port forwarding. You are advised to use other port forwarding methods before resorting to DMZ.\\   \\ **Enable DMZ**: This turns the DMZ function on or off.+Since it opens a large security hole, consider DMZ a "lazy" and potentially dangerous approach to port forwarding. You are advised to use other port forwarding methods before resorting to DMZ.\\   \\ **Enable DMZ**: turns on or off the DMZ function.
  
  \\  \\
  
-**Destination Address**: The LAN IP address of the device to receive all these forwarded ports.+**Destination Address**: the LAN IP address of the device to receive all these forwarded ports.
  
  \\  \\
  
-[[https://wiki.freshtomato.org/lib/exe/detail.php?id=dmz&media=c3eb8300c295e4230ec42a93d23e3aeb.png|{{:c3eb8300c295e4230ec42a93d23e3aeb.png?746}}]]+[[https://wiki.freshtomato.org/lib/exe/detail.php?id=dmz&media=c3eb8300c295e4230ec42a93d23e3aeb.png|{{:c3eb8300c295e4230ec42a93d23e3aeb.png?621}}]]
  
  \\  \\
  
-**Destination Interface**: This is the VLAN/bridge where the above host can be found.+**Destination Interface**: this is the VLAN/bridge where the above host can be found.
  
  \\  \\
  
-**Source Address Restriction**: If entered, this limits DMZ activity to the defined source IP address range. The Default is empty, which means ports from any address/range will be forwarded.+**Source Address Restriction**: if entered, limits DMZ activity to the defined source IP address range. 
 + 
 +The Default is empty, which means ports from any address/range will be forwarded.
  
  \\  \\
  
-**Leave Remote Access**: If enabled, this forces SSH (TCP port 22) and HTTP (TCP port 443) traffic to always be answered by the FreshTomato router, regardless of DMZ settings.+**Leave Remote Access**: if enabled, forces FreshTomato to always answer SSH (TCP/22) and HTTP (TCP/443) traffic, regardless of DMZ settings.
  
-\\ +\\  \\  \\
- +
- \\+
  
  
forward-dmz.1728510961.txt.gz · Last modified: 2024/10/09 22:56 by hogwild