Site Tools


advanced-firewall

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
advanced-firewall [2026/09/30 12:09] – [NAT] rs232advanced-firewall [2026/09/30 12:59] (current) – [NAT] rs232
Line 74: Line 74:
  
 Cons: Cons:
-- LAN devices cannot access local servers using public domain names or public IP addresses.+- LAN devices cannot access local servers using public domain names or public IP addresses nor the router admin interface on the WAN.
  
 \\ \\
 \\ \\
  
-2. Forwarded Only +2. Forwarded Only (default) \\
- +
-\\+
  
 Under the Hood (iptables): FreshTomato generates rules that apply loopback translation only to traffic aimed at ports that are explicitly defined in the Port Forwarding rules. Under the Hood (iptables): FreshTomato generates rules that apply loopback translation only to traffic aimed at ports that are explicitly defined in the Port Forwarding rules.
Line 87: Line 85:
 \\ \\
  
-Matches LAN traffic destined for WAN_IP:PORT only if PORT exists in nat PREROUTING / port-forward tables.   +Matches LAN traffic destined for WAN_IP:PORT only if PORT exists in nat PREROUTING / port-forward tables. These are essentially ports you find defined under Port Forwarding.
  
 \\ \\
Line 102: Line 100:
  
 Cons: Cons:
-- Will not work for dynamic or non-forwarded services (e.g., UPnP-opened ports or DMZ configurations depending on implementation).+- Will not work for dynamic or non-forwarded services (e.g., UPnP-opened ports or DMZ configurations depending on implementation). It will not work for the router administration GUI called on its WAN interface from a LAN device.
  
 \\ \\
 \\ \\
  
-3. All +3. All \\
- +
-\\+
  
 Under the Hood (iptables): FreshTomato inserts a blanket PREROUTING NAT rule matching all traffic coming from the LAN interface aimed at the WAN interface IP address, regardless of whether a port forward rule exists. Under the Hood (iptables): FreshTomato inserts a blanket PREROUTING NAT rule matching all traffic coming from the LAN interface aimed at the WAN interface IP address, regardless of whether a port forward rule exists.
Line 115: Line 111:
 \\ \\
  
-Behavior: Any LAN connection sent to the WAN IP is looped back to the router or LAN destination.+Behavior: Any LAN connection sent to the WAN IP (only to the WAN IP, not the Internet!) is looped back to the router or LAN destination.
  
 \\ \\
  
 Pros: Pros:
-- "It just works" convenience—applies to UPnP mapped ports, DMZ hosts, and all services without needing individual port forward rules.+- "It just works" convenience—applies to UPnP mapped ports, DMZ hosts, and all services without needing individual port forward rules. This is the only mode supporting the WAN router administration called from the LAN.
  
 \\ \\
  
 Cons: Cons:
-- Performance Bottlenecks: Every single piece of LAN-to-WAN-IP traffic runs through blanket SNAT/DNAT rule-matching cycles, bypassing hardware NAT/CTF (Cut-Through Forwarding) acceleration on supported chipsets. +- Performance Bottlenecks (minor): Every single piece of LAN-to-"WAN-IP" traffic runs through blanket SNAT/DNAT rule-matching cycles, bypassing hardware NAT/CTF (Cut-Through Forwarding) acceleration on supported chipsets. NOTE: this is to the WAN-IP not the Internet! 
-- Unintended Loops/Routing Anomalies: Can cause severe instability or packet loops when using dual routers, wireless bridges, or complex multi-subnets.+- Unintended Loops/Routing Anomalies (rare): Can cause severe instability or packet loops when using dual routers, wireless bridges, or complex multi-subnets.
  
  \\  \\
advanced-firewall.1790766572.txt.gz · Last modified: by rs232