Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

By default, your NETGEAR router’s firewall blocks all inbound traffic (connection attempts by devices on the Internet to devices in your local network). However, in some cases, you might want to allow these connections.

The De-Militarized Zone (DMZ) feature on your router forwards all inbound traffic to a specified IP address on your local network. Unlike port forwarding or UPnP, setting up a DMZ removes all of your router’s firewall protection for a device.

Because the DMZ feature removes your router’s firewall protection, DMZ servers pose a security risk. A computer designated as the default DMZ server is exposed to exploits from the Internet. If compromised, the DMZ server computer can be used to attack other computers on your network.

When possible, we recommend that you use port forwarding to allow these connections so that only the specific ports that are needed are opened for inbound traffic. For more information, see What is port forwarding?

Universal Plug and Play (UPnP) is another option for inbound traffic routing if your devices support it. UPnP is not as secure as port forwarding but preserves more firewall protections than using a DMZ. For more information, see How do I enable Universal Plug and Play on my NETGEAR router?

If you understand the risks of DMZ and want to proceed, you can set up a DMZ server from your router’s web interface. For DMZ setup instructions, see How do I set up a default DMZ server on my NETGEAR router?

Last Updated:07/07/2025 | Article ID: 25891

This article applies to:

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email