Best practice is not to expose any management interfaces to the internet. Use a VPN for remote access
Quote from: bartjsmit on April 14, 2023, 08:24:51 amBest practice is not to expose any management interfaces to the internet. Use a VPN for remote accessThat's understood in general cases and pretty well known. I'm more curious about the process of using NAT Port Forward from WAN -> LAN side of the gateway and then open the firewall for LAN access. Is there any benefit from doing this?
Yes. To have the same URL from inside and out.
Then why don't you follow the suggestion to use a VPN? You can set-up a secure connection with Wireguard and only the allowed users will be able to access the LAN interface from the internet - much more secure and works a treat, I've been using it for years without problems.It would certainly bother me if I exposed my LAN interface to the interface via NAT, I'm sure there's plenty of hackers that would find that config a challenge.