Hello, friend!
According to your description, you cannot access the HG8245Q2 WebUI because the ISP restricts ONT access.
As the products are customized by carriers, we cannot provide meaningful help.
The solution is to tell the ISP that you need to configure the Wi-Fi network and change the password.
Generally, the Internet access service needs to be configured by the ISP on the OLT after the ONT passes the authentication. Then, the ACS delivers the service.
About the DMZ, the demilitarized zone (DMZ) is a technology that enables the ONT to forward all received packets through a specified internal server. The technology enables a computer in the LAN to be completely exposed to all users on the Internet or enables the mutual communication without restrictions between a host with a specified IP address and other users or other servers on the Internet. In this way, many applications can run on the host with the specified IP address. The host with the specified IP address receives all connections and files that can be identified.
If you do not want to open the DMZ, you can log in to the HG8245Q2 WebUI only, in the navigation tree on the left, choose Forward Rules > DMZ Configuration. In the pane on the right, delete the corresponding DMZ configuration.
Thanks!