This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
forward-upnp [2024/10/09 23:07] – [UPnP/NAT-PMP] -Condense, add level 4 subheads hogwild | forward-upnp [2024/11/27 01:54] (current) – [Settings] -Condense, formatting hogwild | ||
---|---|---|---|
Line 3: | Line 3: | ||
=== UPnP === | === UPnP === | ||
- | Universal Plug and Play is a controversial protocol that allows fully dynamic (automatic) port mapping from LAN IP addresses onto the Internet. It has been criticized for its poor security. With UPnP, each network program maps its own ports automatically. In the screenshot below, WhatsApp has mapped certain ports on the WAN IP/ | + | Universal Plug and Play is a controversial protocol that allows fully dynamic (automatic) port mapping from LAN IP addresses onto the Internet. It has been criticized for its poor security. |
+ | |||
+ | With UPnP, each network program maps its own ports automatically. In the screenshot below, WhatsApp has mapped certain ports on the WAN IP/ | ||
\\ | \\ | ||
+ | |||
+ | \\ \\ {{:: | ||
=== NAT-PMP === | === NAT-PMP === | ||
Line 17: | Line 21: | ||
**Enable UPnP: | **Enable UPnP: | ||
+ | |||
+ | \\ | ||
**Enable NAT-PMP: | **Enable NAT-PMP: | ||
- | **Inactive Rule Cleaning: | + | \\ |
+ | |||
+ | **Inactive Rule Cleaning: | ||
\\ | \\ | ||
Line 28: | Line 36: | ||
\\ | \\ | ||
- | **Cleaning Threshold: | + | **Cleaning Threshold: |
- | **Secure Mode**: | + | \\ |
- | **Enable on:** | + | **Secure Mode**: eabling this lets only the "owner LAN IP address" |
+ | |||
+ | In other words, the client is only allowed to map an incoming port to its own IP address, not to another address. | ||
+ | |||
+ | \\ | ||
+ | |||
+ | **Enable on:** this allows you to enable UPnp/NATPMP only on certain VLANs. | ||
+ | |||
+ | \\ | ||
+ | |||
+ | **Show in My Network Places:** if enabled, makes FreshTomato appear as a gateway in Windows' | ||
+ | |||
+ | \\ | ||
- | **Show in My Network Places:** If enabled, this makes FreshTomato appear as a gateway | + | **Miniupnpd custom config:** here, enter custom configuration options unavailable |
- | **Miniupnpd custom config: | + | In the image above, all UPnP requests/ |
- | \\ | + | |
- | \\ | + | |
- | \\ | + | |