This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| advanced-firewall [2026/07/21 15:23] – pedro | advanced-firewall [2026/09/30 12:59] (current) – [NAT] rs232 | ||
|---|---|---|---|
| Line 21: | Line 21: | ||
| \\ **Enable TCP SYN cookies: | \\ **Enable TCP SYN cookies: | ||
| - | It encodes information from the SYN packet into the (SYN/ACK) response. | + | This uses a standard method for preventing SYN floods. |
| \\ | \\ | ||
| Line 31: | Line 31: | ||
| **Allow DHCP Spoofing: **makes FreshTomato accept/ | **Allow DHCP Spoofing: **makes FreshTomato accept/ | ||
| - | Such behaviour is often categorized as a DHCP spoofing attack, but rarely, might be legitimate. Using this lowers security.\\ \\ | + | Such behaviour is often categorized as a DHCP spoofing attack, but rarely, might be legitimate. Using this lowers security. |
| - | **Smart MTU black hole detection: | + | |
| - | For details on MTU and black holes, see this blog post: [[https:// | + | **Smart MTU black hole detection: |
| + | |||
| + | For details on MTU and black holes, see this blog post: [[https:// | ||
| + | |||
| + | \\ | ||
| **TCP MSS Clamping:** | **TCP MSS Clamping:** | ||
| - | TCP MSS Clamping | + | This adjusts the Maximum Segment Size of forwarded TCP connections on WAN and VPN interfaces to match the discovered path MTU. |
| - | This helps avoid MTU-related connection problems, especially on PPPoE links, VPN tunnels, IPv6 tunnels, or networks | + | This helps avoid MTU-related connection problems, especially on PPPoE links, VPN tunnels, IPv6 tunnels, or networks |
| Disabling this option reduces the number of firewall rules and may slightly improve performance on low-end routers, but can cause connection stalls or TLS handshake timeouts on links with reduced MTU. | Disabling this option reduces the number of firewall rules and may slightly improve performance on low-end routers, but can cause connection stalls or TLS handshake timeouts on links with reduced MTU. | ||
| - | Recommended setting: enabled, unless MTU/MSS is handled manually or the network | + | Recommended setting: enabled, unless MTU/MSS is handled manually or the network |
| ===== NAT ===== | ===== NAT ===== | ||
| - | **NAT loopback: | + | **NAT loopback: |
| - | Also known as " | + | \\ |
| - | \\ | + | 1. Disabled \\ |
| + | Under the Hood (iptables): FreshTomato omits loopback rules in the NAT chains. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Behavior: When a local LAN client sends traffic destined for the router’s public WAN IP address (or DDNS domain name), the router receives it, sees that there is no active rule translating internal LAN traffic back into the LAN, and simply drops or rejects the traffic. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Pros: | ||
| + | - Lowest router CPU load and max throughput (zero extra NAT inspection or packet rewriting for LAN traffic). | ||
| + | - Forces proper network boundary segregation. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Cons: | ||
| + | - LAN devices cannot access local servers using public domain names or public IP addresses nor the router admin interface on the WAN. | ||
| + | |||
| + | \\ | ||
| + | \\ | ||
| + | |||
| + | 2. Forwarded Only (default) \\ | ||
| + | |||
| + | Under the Hood (iptables): FreshTomato generates rules that apply loopback translation only to traffic aimed at ports that are explicitly defined in the Port Forwarding rules. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Matches LAN traffic destined for WAN_IP:PORT only if PORT exists in nat PREROUTING / port-forward tables. These are essentially ports you find defined under Port Forwarding. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Behavior: If you forward port 8443 to an internal server at 192.168.1.10: | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Pros: | ||
| + | - Security & Control: Prevents local LAN traffic from hitting closed or un-forwarded router ports via the external WAN identity. | ||
| + | - Performance: | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Cons: | ||
| + | - Will not work for dynamic or non-forwarded services (e.g., UPnP-opened ports or DMZ configurations depending on implementation). It will not work for the router administration GUI called on its WAN interface from a LAN device. | ||
| + | |||
| + | \\ | ||
| + | \\ | ||
| + | |||
| + | 3. All \\ | ||
| + | |||
| + | Under the Hood (iptables): FreshTomato inserts a blanket PREROUTING NAT rule matching all traffic coming from the LAN interface aimed at the WAN interface IP address, regardless of whether a port forward rule exists. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Behavior: Any LAN connection sent to the WAN IP (only to the WAN IP, not the Internet!) is looped back to the router or LAN destination. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Pros: | ||
| + | - "It just works" convenience—applies to UPnP mapped ports, DMZ hosts, and all services without needing individual port forward rules. This is the only mode supporting the WAN router administration called from the LAN. | ||
| + | |||
| + | \\ | ||
| - | * All | + | Cons: |
| - | * Forwarded Only | + | - Performance Bottlenecks (minor): Every single piece of LAN-to-" |
| - | * Disabled | + | - Unintended Loops/ |
| \\ | \\ | ||