Copyright (c) Fire4 Systems Inc, 2019. All rights reserved
26
Settings: Adding inbound access from the Internet - DMZ
A DMZ (demilitarized zone or perimeter network) is a physical or logical subnetwork that contains
and exposes an organization's external-facing services to an external untrusted network, usually
the Internet. The purpose of a DMZ is to add an additional layer of security to an organization's
local area network (LAN) so that an external WAN network device can access only what is
exposed in the DMZ, while the rest of the organization's network remains firewalled.
To set the DMZ click on Settings then click Port Forward and DMZ.
The drop down menu lists known devices within the LAN network. Select a device that will be
visible from the WAN side of the network.
As with port forwarding, it is not a good policy to make a LAN side device accessable from the
Internet. This is an invitation for a hacker to start poking around looking for access. Set the DMZ
only in circumstances where there are no alternatives.
When a device in the LAN
is added to the DMZ then
that device becomes
accessible from the WAN
side of the network
However only open ports
can be accessed on the
DMZ device