3 ms·
> The thing that I would say is a bad idea is what many routers refer to as "DMZ" mode or similar, where you broadly send incoming connections to a system. That
by drpixie 4y ago
> The thing that I would say is a bad idea is what many routers refer to as "DMZ" mode or similar, where you broadly send incoming connections to a system. That's got a lot more risk since you have to be a lot more cautious about what services are listening on your server.
Got to agree with that - realistically the DMZ machine is almost FULLY exposed to the internet. Have a "DMZ machine" but open only the ports specifically required for whatever service is provided.
If you "DMZ machine" can see the rest of your home network, then so can anyone/anything that breaks into your "DMZ machine"!
And see my previous reply re take care with is made accessible.
- pkdpic 4y agoAgain, extremely helpful, thank you (both of you) for all the wisdom here!