Configure a DMZ (Demilitarized Zone) on Your GFiber Network
A DMZ (Demilitarized Zone) is a designated computer or subnet on your network that serves as a completely exposed neutral zone between the open public internet and your private GFiber network. When you configure a DMZ device, your GFiber router bypasses its firewall rules for that specific hardware, forwarding all unknown incoming internet requests directly to that single device's IP address.
When should I use a DMZ?
Most customers do not need a DMZ. It is primarily used for advanced setups for developers or gamers who are hosting direct outward-facing services (like web servers or specific multiplayer game lobbies) and want to prevent outside traffic from getting blocked by the router's hardware firewall.
Crucial Security & Preparation Work
-
Security Risk: Because a DMZ bypasses your router's security baseline, you must ensure your target device has its own robust, software-level firewalls enabled to handle direct web traffic attacks.
-
Port Forwarding Precedence: The router will send traffic to the DMZ except for traffic handled by separate, pre-existing manual port forwarding rules. Set up all your standard manual port forwarding rules for your other devices before enabling the DMZ.
-
Limit: Only one device at a time can serve as the active DMZ for your GFiber network.
How to Designate a Device as Your DMZ
Before turning on the DMZ, make sure the target device is powered on, actively connected to your GFiber network, and has a Reserved IP address assigned to it. If you haven't reserved an IP address yet, see our guide on Managing LAN IP Addresses and DHCP Pools.
To enable a DMZ:
-
Sign in to your GFiber Account using the email and password associated with your GFiber account.
-
Select Network in the upper-left corner. (If the option is hidden, click the primary navigation menu icon to display the selection layout).
-
Open the advanced network settings and navigate to your chosen target device.
-
Locate the DMZ option and switch it to On.
Note: If another device on your home network is already acting as the active DMZ, a prompt alert box will appear asking if you want to switch the DMZ designation over to the current device. - Click Save. The router will immediately begin sending incoming requests to the DMZ.
How to Stop Using a Device as a DMZ
To restore your network's standard security profile and close the exposed zone, follow these steps:
-
Sign in to your GFiber Account using the email and password associated with your GFiber account.
-
Select Network in the upper-left corner.
-
Open the advanced network settings for the currently active DMZ device within your GFiber account.
-
Change the DMZ setting switch to Off.
-
Click Save.
The router will immediately resume its standard security baseline, automatically ignoring or dropping all unknown incoming traffic requests that do not match an explicit manual port forwarding rule.