Help Center

Configure a DMZ (Demilitarized Zone) on Your GFiber Network

Learn how to reserve an IP address, set up port forwarding, or configure a DMZ for your device within your GFiber account.

A DMZ (Demilitarized Zone) is a designated computer or subnet on your network that serves as a completely exposed neutral zone between the open public internet and your private GFiber network. When you configure a DMZ device, your GFiber router bypasses its firewall rules for that specific hardware, forwarding all unknown incoming internet requests directly to that single device's IP address.

When should I use a DMZ?

Most customers do not need a DMZ. It is primarily used for advanced setups for developers or gamers who are hosting direct outward-facing services (like web servers or specific multiplayer game lobbies) and want to prevent outside traffic from getting blocked by the router's hardware firewall.

Crucial Security & Preparation Work

  • Security Risk: Because a DMZ bypasses your router's security baseline, you must ensure your target device has its own robust, software-level firewalls enabled to handle direct web traffic attacks.

  • Port Forwarding Precedence: The router will send traffic to the DMZ except for traffic handled by separate, pre-existing manual port forwarding rules. Set up all your standard manual port forwarding rules for your other devices before enabling the DMZ.

  • Limit: Only one device at a time can serve as the active DMZ for your GFiber network.

How to Designate a Device as Your DMZ

alert-red
The advanced DMZ features detailed below are available for the Wi-Fi 6 Router, Multi-Gig Router, Wi-Fi 6E Router, Wi-Fi 7 Router, and the original Network Box. If you use a Google Wifi or Nest Wifi Pro router, you must use the Google Home App to manage your advanced network settings.

Before turning on the DMZ, make sure the target device is powered on, actively connected to your GFiber network, and has a Reserved IP address assigned to it. If you haven't reserved an IP address yet, see our guide on Managing LAN IP Addresses and DHCP Pools.

To enable a DMZ:

  1. Sign in to your GFiber Account using the email and password associated with your GFiber account.

  2. Select Network in the upper-left corner. (If the option is hidden, click the primary navigation menu icon to display the selection layout).

  3. Open the advanced network settings and navigate to your chosen target device.

  4. Locate the DMZ option and switch it to On.

    alert-warning
    Note: If another device on your home network is already acting as the active DMZ, a prompt alert box will appear asking if you want to switch the DMZ designation over to the current device.
  5. Click Save. The router will immediately begin sending incoming requests to the DMZ.
tool-tip
What happens if the device disconnects? If you physically disconnect the DMZ device from your network line, the DMZ state will temporarily pause. However, it will automatically restore itself and resume exposing the device as soon as it reconnects to your network.

How to Stop Using a Device as a DMZ

To restore your network's standard security profile and close the exposed zone, follow these steps:

  1. Sign in to your GFiber Account using the email and password associated with your GFiber account.

  2. Select Network in the upper-left corner. 

  3. Open the advanced network settings for the currently active DMZ device within your GFiber account.

  4. Change the DMZ setting switch to Off.

  5. Click Save.

The router will immediately resume its standard security baseline, automatically ignoring or dropping all unknown incoming traffic requests that do not match an explicit manual port forwarding rule.