SuperDMZ creates encrypted tunnels between the internet and your internal machines in seconds — no router config, no fixed IP, no VPN. Reach local services like HTTP, Terminal, FTP and any custom TCP/UDP port.
Active nodes worldwide
How it works
No router config. No open ports. No firewall setup.
Sign up for free, access the dashboard and create a tunnel in less than a minute.
Download and install superdmz-client.exe on the internal machine with the generated token.
Your tunnel is available at the generated subdomain. Access RDP, SSH, web apps or any TCP port.
Features
HTTP, RDP, SSH, databases — if it runs on your network, it works with SuperDMZ.
Expose websites, dashboards and APIs with a custom subdomain and automatic SSL (Let's Encrypt).
Access Windows from anywhere via custom TCP port. No VPN, no firewall config.
SSH connection to your internal network through the tunnel. Keys or password — you choose.
MySQL, PostgreSQL, MongoDB — connect external tools to your internal database securely.
Access IP cameras, DVRs and NVRs on your network from anywhere in the world.
If it uses TCP, SuperDMZ tunnels it. No protocol or port restriction.
Restrict tunnel access by IP or CIDR range. Security in layers.
Track data usage and tunnel status in real time on the dashboard.
Install as a Windows service with a single command. Starts automatically with the system.
Comparison
| Feature | SuperDMZ | ngrok | Tailscale | Own VPN |
|---|---|---|---|---|
| No fixed IP required | ||||
| Installs as a system service (no extra config) | ||||
| RDP / TCP / SSH support | ||||
| Persistent HTTPS subdomain on Free plan | ||||
| Node in Brazil (low local latency) | ||||
| Useful free plan | ||||
| Pricing in BRL, no FX fee | ||||
| Interface + support in EN/PT/ES/FR | ||||
| End-to-end encryption by default | ||||
| Mature third-party integration ecosystem |
Pricing
Start free, upgrade when you need. No setup fee. Cancel anytime.
FAQ
No. The SuperDMZ client initiates an outgoing connection to our server — just like a normal HTTPS connection. Your router needs no configuration.
Yes. The client is available for Windows (as a service), Linux and macOS. On Linux and macOS it can run as a daemon via systemd or launchd.
Traffic passes through our proxy, which acts only as a TCP/HTTP intermediary. We do not inspect, store or modify the content of your tunnel traffic.
Yes, on Starter, Pro and Business plans. You point a CNAME or A record of your domain to our server and configure it on the dashboard.
The tunnel is automatically marked offline. When the client reconnects, the tunnel returns to online status with the same address.
Paid plans are monthly with no lock-in. You can upgrade, downgrade or cancel at any time from the dashboard.
Create your free account in less than 1 minute. No credit card, no complex setup.
A quick tour through the main features
Free signup in seconds. No credit card. Free plan includes 2 tunnels so you can try it out.
Choose the hostname (e.g. my-site), the server (BR, USA, EU or ASIA), the protocol and the local port of your service.
Download for Windows, Linux or macOS. Paste the token on the internal machine — the tunnel comes up in about 2 seconds.
Access via a friendly subdomain (e.g. my-site.dmzgate.com) with automatic HTTPS (Let's Encrypt). Ideal for internal websites, dashboards and APIs.
Any TCP port: SSH, RDP, databases, MQTT, FTP, IP cameras, NVRs… You get a friendly host + port (e.g. my-srv.dmzgate.com:18136).
Each tunnel can use one of three modes. Switch any time without reinstalling anything.
Anyone with the link can access it. Ideal for public sites, demos, webhooks, payment callbacks — anything that needs to be open.
Allowlist of up to 50 IPs or ranges. Anyone not in the list is blocked at the edge — never reaches your service. Perfect for SSH, RDP and databases.
Issue access keys (up to 20 per tunnel), one per person/service. The edge requires an Authorization: Bearer KEY header or cookie. Revoke any key anytime without affecting the others.
Traffic per tunnel, online/offline status, 24h and 7-day charts in your dashboard.
Point a CNAME from your domain (e.g. app.yourcompany.com) — automatic SSL.
Get notified when a tunnel goes down (10min and 1h) or a node becomes unavailable.
Brazil, USA, Europe, Asia. Pick the closest one for minimum latency.