Hacker News new | ask | show | jobs
by accrual 742 days ago
How about putting the ISP supplied modem in a DMZ? Then the ISP could admin it all they want but still never touch the LAN.
2 comments

That's pretty much the way to go. Keep the ISP modem, but connect it to your own router/firewall and connect your devices to your hardware and not the ISP modem.
So open it up to anyone? DMZ is an open target, not what you want to be doing.
It’s more about protecting your network against a potentially malicious device rather than protecting the device from attackers on the Internet. From that position, placing the isp device on a “DMZ” aka outside your own router/firewall, makes perfect sense.