Hi
In reply to:
A good thing to do for enhanced security is to set up your router to create a DMZ entry for a network address that doesn't exist on your local network. Then if people try to scan ports at your IP address, you're effectively stealthed, because all port attacks get sent to the address in your network that doesn't exist.
You don't need to do this as this what NAT is already doing. The big danger with doing this is you may find later you end up with the DMZ IP address issued out to you by DHCP. You could of course use fixed IP addresses or tell DHCP to tie an IP address to a MAC but it's simply not needed and adds more complication to your setup.
Essentially what you are doing by suggesting this is actually give a route for traffic to get through to your network, whereas not doing this means NAT never passes the traffic through. The DMZ trick is less secure not more secure.