This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revision | |||
| advanced-firewall [2026/09/30 12:16] – [NAT] rs232 | advanced-firewall [2026/09/30 12:59] (current) – [NAT] rs232 | ||
|---|---|---|---|
| Line 74: | Line 74: | ||
| Cons: | Cons: | ||
| - | - LAN devices cannot access local servers using public domain names or public IP addresses. | + | - LAN devices cannot access local servers using public domain names or public IP addresses |
| \\ | \\ | ||
| \\ | \\ | ||
| - | 2. Forwarded Only \\ | + | 2. Forwarded Only (default) |
| Under the Hood (iptables): FreshTomato generates rules that apply loopback translation only to traffic aimed at ports that are explicitly defined in the Port Forwarding rules. | Under the Hood (iptables): FreshTomato generates rules that apply loopback translation only to traffic aimed at ports that are explicitly defined in the Port Forwarding rules. | ||
| Line 85: | Line 85: | ||
| \\ | \\ | ||
| - | Matches LAN traffic destined for WAN_IP:PORT only if PORT exists in nat PREROUTING / port-forward tables. | + | Matches LAN traffic destined for WAN_IP:PORT only if PORT exists in nat PREROUTING / port-forward tables. |
| \\ | \\ | ||
| Line 100: | Line 100: | ||
| Cons: | Cons: | ||
| - | - Will not work for dynamic or non-forwarded services (e.g., UPnP-opened ports or DMZ configurations depending on implementation). | + | - Will not work for dynamic or non-forwarded services (e.g., UPnP-opened ports or DMZ configurations depending on implementation). It will not work for the router administration GUI called on its WAN interface from a LAN device. |
| \\ | \\ | ||
| Line 111: | Line 111: | ||
| \\ | \\ | ||
| - | Behavior: Any LAN connection sent to the WAN IP is looped back to the router or LAN destination. | + | Behavior: Any LAN connection sent to the WAN IP (only to the WAN IP, not the Internet!) |
| \\ | \\ | ||
| Pros: | Pros: | ||
| - | - "It just works" convenience—applies to UPnP mapped ports, DMZ hosts, and all services without needing individual port forward rules. | + | - "It just works" convenience—applies to UPnP mapped ports, DMZ hosts, and all services without needing individual port forward rules. This is the only mode supporting the WAN router administration called from the LAN. |
| \\ | \\ | ||
| Cons: | Cons: | ||
| - | - Performance Bottlenecks: | + | - Performance Bottlenecks |
| - | - Unintended Loops/ | + | - Unintended Loops/ |
| \\ | \\ | ||