Security of DMZ setup: miniupnpd + zapret + https-dns-proxy on Rostelecom S1010 (OpenWrt 25.12.1)

:waving_hand:
Hi all!
I've just installed the new OpenWrt 25.12.1 on my Rostelecom S1010 router. My current setup includes:
Services: miniupnpd (configured with stun.l.google.com), https-dns-proxy, and zapret.
WiFi Security: WPA3-SAE with protection against KRACK attacks enabled.
Storage: I have about 6.0 MB of free space in /overlay (total 8.4 MB), and /var is symlinked to /tmp.
I want to enable DMZ on my main ISP router to point to this S1010 to avoid double NAT issues for gaming, but I'm a bit worried about security.
My questions for the pros:
Is it safe to enable DMZ on the main router in this specific configuration?
Will the 6.0 MB of free overlay be enough for stable operation, or should I be worried about logs/configs filling it up?
Are there any known conflicts between zapret and miniupnpd when running behind another NAT?
Thanks in advance for the help!

That's a question for your ISP, since I'm guessing the main router doesn't run Openwrt ?
DMZ in itself is safe.

No logs are ever written to flash, you're good.

1 Like

Yes, my main router (RV6699) doesn't have OpenWrt firmware installed. I'm just concerned about security—but if DMZ is safe, then thank you! (I used Google Translate.)

And that's the whole point, we can't guarantee you any kind of security on a device we know nothing about.

can I provide some information about this router? (RV6699)

Unless you're willing to add the support for it (assuming supportable), don't bother.

wait, gpon router (rv6699) supports OpenWrt? or did I misunderstand?

You did....

oh, I'll be happy to try it​:smiling_face_with_three_hearts:

You can start by opening it up, and confirming it's not Broadcom based.

ah.... well, I can finish, that’s where this percentage is, I won’t even check, I’m 100 percent sure :disappointed_face:

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.