How do you set up a DMZ host for the Telecom optical modem? NAS remote and gaming connection connect all at once, much more hassle-free than switching to bridge

Last month,
accompanied Da Liu to inspect that second-hand Synology. After two weeks of assembly, he called again: at the office, wanting to check photos of the NAS at home, QuickConnect spinning in circles was chilling, and during peak hours, hundreds of KB per second—a single RAW image could make you lose your temper; His son wants to play online with classmates on weekends, but the Switch keeps playing strict NAT, and he can't even get into the lobby. He had set up port forwarding on his router, added three rules, and none worked.
I immediately understood where it was stuck: their optical modem was in router mode, the router was hung below the modem, and any incoming connections were blocked on the modem's layer, so the forwarding rules on the router never came to use. He had heard of one solution—switching to bridge. I explained the benefits and costs of to bridge, saying IPTV easily crashes, configurations might be pushed back at night, and the backend is easily lost. After hearing this, he waved his hand. Actually, there's a middle path, much quieter: DMZ host . My car had already been modified with a bridge, so I couldn't replicate it from my own home. That night, I watched Da Liu's screen on video the whole time. This article reveals the process and pitfalls.
clarify first: the DMZ host hands over the entire key chain to the router
in optical modem routing mode, the home has two layers of NAT: the modem takes the public network address and sends the internal address 192.168.2.x; the router is mounted below the optical modem, the WAN port receives a 192.168.2 internal network address, and then sends a round to the devices below it. When you connect from outside, the first door is the optical modem. The optical modem doesn't recognize the port you're looking for and just throws away the connection. Liu set rules on the router, which meant installing a doorbell on the second door, but the customer didn't even get through the first door.
two old methods. One is to switch to bridge, where the optical modem only performs photovoltaic conversion, and the router directly takes the public network address externally—the most thorough and costly. The other is a port mapping on the optical modem, with a rule opening — but that entry is hidden in the super admin backend, and every time you add a device, you have to log into the telecomadmin interface. The font is small and hierarchical. With Liu Da's personality, by the third point, he'd probably slam the mouse.
DMZ host is the third way: designate a local network machine on the optical modem as the "DMZ host," and the modem transfers all inbound traffic to it. For example, port mapping means a guest provides a room number, and you take them to a room; DMZ hands the entire building's keychain to the router, and whoever enters which room is entirely up to the router. From then on, the optical modem ignored the details; all the rules were set on the router—modern routers have much easier backend and apps, just add a retweet and tap twice. The difference between port forwarding and DMZ: I previously wrote a dedicated here only discussing how to implement the optical modem side.
pass three hurdles before you start: public IP, nailing the router IP, and obtaining the super admin password
first checkpoint: confirm that your home is a public IP address. DMZ is to attract traffic to your home, provided you can really find your address outside. On your phone, open data and search for "IP" to record the exit address, then check the WAN port IP in the backend of the optical modem. If both are consistent and not starting with 100.64, you can start playing. Liu was lucky—the WAN port in his area was the public network address; If you find out it's a carrier's internal network address starting with 100.64, call 10000 first to get a public IP. I'll write the process in the of the public IP verification article. Otherwise, don't bother with DMZ—it's pointless.
second level, pin down the router's WAN port IP. the 192.168.2.x address on the router's WAN port is sent by the optical modem DHCP. Once the lease expires, the number may change. If you change the number, the optical modem's DMZ will point to the wrong person, and forwarding will be completely cut off. Either bind the router's MAC to a fixed address in the DHCP settings of the optical modem, or set it static directly on the router's WAN port. The Da Liu family's staple is 192.168.2.2, easy to remember and easy to get wrong.
Level 3: the super admin password. The DMZ entry is like the port mapping, hidden in the super admin layer, and the useradmin can't access this menu. How to get the telecomadmin password—install the maintenance master, 10000 ID, and the configuration file—I wrote all of these three in the of the super password. After receiving it, don't rush to change it. As usual download a conf backup save it on your computer. If the changes are broken, there's a way out.
the paths of the three common Tianyi gateways, the menu naming differs slightly
Liu's device is a Huawei HS8145V5. After logging into SuperManager, the path is "Application → Advanced NAT Configuration → DMZ Configuration" : check Enable, enter the DMZ host address as 192.168.2.2 on the router's WAN port, and save. The ZTE F7015T is similar. In the "Apps" menu, find DMZ host configuration, and follow the same three steps. TEWA's menu names are not uniform; just follow the DMZ label in "Apps"; If you really can't find it, just search for the specific model plus DMZ—it's faster than blindly searching in the background.
Liu made a mistake the first time. When he entered the router's backend, the first address he saw was 192.168.3.1 on the router's own LAN port, and he casually entered it—the modem didn't recognize this address at all, so it was like handing the key to someone in the neighboring community. What you need to fill in is the address of the router's WAN port , which is the 192.168.2.2 sent by the optical modem. You can see it on the router's "Internet Settings" or "WAN Port Status" page. After making changes, save and the optical modem takes effect within one minute without restarting.
the light modem is done, the three things on the router end are the final touches
first item, all rules are applied to routers. On Liu's Synology DS920+, add a forwarder line on the router to map the NAS port 5001 to the high-level port 18081—using the high bit for external ports is the old habit; low-level ports like 22, 3389, and 8080 are the top tier in scanner dictionaries. the importance of port numbers discussed before. Switch doesn't need to manually open any ports; UPnP will set the rules themselves. This time, the rule is applied to the router, and with a double-tap in the app, it takes effect immediately. You no longer need to enter the bottomless backend of the optical modem.
second item, DDNS. Public IPs are dynamic and may drift every few months. The DDNS function on the router shows the real public address (it asks for external services, not its own network card). Just add a free domain name. router DDNS settings I've written the full process.
third, verification must be done using mobile data. This is the easiest misjudgment: sitting at home on WiFi, using a public IP to test your port, nine times out of ten it shows no connection—not because it's mismatched, but because NAT backflow is that most optical modems don't support looping back from the internal network to your own public address. Switching to mobile data and testing showed green. On the night of direct connection, Liu's NAS reached over 5 megabytes per second, hitting his home ceiling of 50 Mbps, which is more than ten times faster than QuickConnect's peak period. The reason why relays are slow is explained thoroughly in Synology QuickConnect . His son's Switch connection test was also smooth, and the strict NAT prompt never appeared again.
DMZ. Bridge, optical modem port mapping—how do you choose among these three routes
the night I finished dubbing, I made a table for Da Liu of the three routes, and I also put it here:
| Comparison Items | Optical modem port mapping | DMZ host | bridge |
| hands-on difficulty | every rule is entered into the hypertransducer | set once, a one-time fix | the worst |
| IPTV | copying VLANs to change dialing | Unaffected | prone to failure, rescue |
| setups are pushed back | rules may be lost | which is rare, Be cautious | bridge to the high-risk |
| optical modem backend | normal access | normal access | need static IP recovery |
| rule management | interface is hard to use | double-tap the router app | double-tap the router app |
DMZ is not without cost; the cost lies in safety. With DMZ enabled, the router shifts from being a 'device hiding in the internal network' to a 'gatekeeper directly facing public network scanning,' with probes from all ports hitting it. So there are three things you must do during self-checking: change the router management password to 16-bit, turn off remote management on the WAN side, and upgrade the firmware to the latest version. If the security guard is weak, handing over the whole batch of keys is a disaster. signs that the router was hacked and the self-inspection can be reviewed in person. There's another pitfall most tutorials don't cover: DMZ only covers the router's leg. If there are other devices connected to the modem's own WiFi, those devices are neither protected nor can they enjoy forwarding. The cleanest approach is to turn off the optical modem's WiFi, have all family devices run through the router, turn off the optical modem WiFi for five minutes.
who you are, don't touch them. Wrap up and give me an order
three situations to avoid DMZ: if you find out it's a 100.64 IP with no public IPs; the router is an old antique that's been parked for years and can't withstand full-port scanning; or you don't have any devices at home to connect to—if you don't need it, don't open the door. Every extra door you open adds another door to worry about. Also, after a week of setup, check the light modem's backend to see if DMZ is still there. Some regions may reject the configuration drop, and if it really gets pushed back, just follow the ITMS method of pushing back to that .
order: check the public IP for mobile data, pin the router's WAN port IP, use the ultra-secret conf guide, set the DMZ on the optical modem to point to the router, add the rules to the router, switch to mobile data for verification, and check it after one week. After completing these seven steps, Da Liu's "Remote Access Family Bucket" diagram is now complete. DMZ isn't abandoning security; it's shifting the gatekeeping responsibility from the optical modem to the router—before moving, consider if your new gatekeeper is strong.
