This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| advanced-firewall [2026/07/23 17:41] – [Firewall] Condense hogwild | advanced-firewall [2026/09/30 12:59] (current) – [NAT] rs232 | ||
|---|---|---|---|
| Line 21: | Line 21: | ||
| \\ **Enable TCP SYN cookies: | \\ **Enable TCP SYN cookies: | ||
| - | This encodes information from the SYN packet into the (SYN/ACK) response-a standard method for preventing SYN floods. However, its limitations may cause issues with some old TCP/IP stacks. \\ | + | This uses a standard method for preventing SYN floods. It encodes information from the SYN packet into the (SYN/ACK) response. |
| \\ | \\ | ||
| Line 54: | Line 54: | ||
| ===== NAT ===== | ===== NAT ===== | ||
| - | **NAT loopback: | + | **NAT loopback: |
| - | Also known as " | + | \\ |
| - | \\ | + | 1. Disabled \\ |
| + | Under the Hood (iptables): FreshTomato omits loopback rules in the NAT chains. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Behavior: When a local LAN client sends traffic destined for the router’s public WAN IP address (or DDNS domain name), the router receives it, sees that there is no active rule translating internal LAN traffic back into the LAN, and simply drops or rejects the traffic. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Pros: | ||
| + | - Lowest router CPU load and max throughput (zero extra NAT inspection or packet rewriting for LAN traffic). | ||
| + | - Forces proper network boundary segregation. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Cons: | ||
| + | - LAN devices cannot access local servers using public domain names or public IP addresses nor the router admin interface on the WAN. | ||
| + | |||
| + | \\ | ||
| + | \\ | ||
| + | |||
| + | 2. Forwarded Only (default) \\ | ||
| + | |||
| + | Under the Hood (iptables): FreshTomato generates rules that apply loopback translation only to traffic aimed at ports that are explicitly defined in the Port Forwarding rules. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Matches LAN traffic destined for WAN_IP:PORT only if PORT exists in nat PREROUTING / port-forward tables. These are essentially ports you find defined under Port Forwarding. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Behavior: If you forward port 8443 to an internal server at 192.168.1.10: | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Pros: | ||
| + | - Security & Control: Prevents local LAN traffic from hitting closed or un-forwarded router ports via the external WAN identity. | ||
| + | - Performance: | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Cons: | ||
| + | - Will not work for dynamic or non-forwarded services (e.g., UPnP-opened ports or DMZ configurations depending on implementation). It will not work for the router administration GUI called on its WAN interface from a LAN device. | ||
| + | |||
| + | \\ | ||
| + | \\ | ||
| + | |||
| + | 3. All \\ | ||
| + | |||
| + | Under the Hood (iptables): FreshTomato inserts a blanket PREROUTING NAT rule matching all traffic coming from the LAN interface aimed at the WAN interface IP address, regardless of whether a port forward rule exists. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Behavior: Any LAN connection sent to the WAN IP (only to the WAN IP, not the Internet!) is looped back to the router or LAN destination. | ||
| + | |||
| + | \\ | ||
| + | |||
| + | Pros: | ||
| + | - "It just works" convenience—applies to UPnP mapped ports, DMZ hosts, and all services without needing individual port forward rules. This is the only mode supporting the WAN router administration called from the LAN. | ||
| + | |||
| + | \\ | ||
| - | * All | + | Cons: |
| - | * Forwarded Only | + | - Performance Bottlenecks (minor): Every single piece of LAN-to-" |
| - | * Disabled | + | - Unintended Loops/ |
| \\ | \\ | ||