EN - FR - DE - ES - IT - PT -

LexiconDream

🚧 Demilitarized Zone

A network segment that separates internal systems from the internet.

Demilitarized Zone

A demilitarized zone is a network segment that sits between the internet and the internal network. Public-facing servers live there: web servers, mail gateways, and reverse proxies. If an attacker compromises one of those servers, the DMZ limits how far they can go. The internal network sits behind another firewall. The DMZ is the buffer.

The design comes from military thinking. Put a neutral strip between the front line and the base. In network terms, the DMZ holds systems that need to be reachable from the internet but should not have direct access to internal resources. A web server in the DMZ can talk to a database in the internal network through a controlled rule. It cannot browse the corporate file shares or reach the HR system. The firewall rules are strict and one-directional. The DMZ absorbs attacks. It also adds complexity. More segments mean more rules to manage and more places to misconfigure. A DMZ with a permissive rule set defeats the purpose. The value is in the restriction, not the architecture.

Typical DMZ hosts

A DMZ is not a magic shield. A compromised server in the DMZ still gives an attacker a foothold. The goal is to make that foothold less useful.

Comments (3)

  1. Alex Chen
    Important to note this is a networking concept borrowed from the military term. DMZs have been a security staple for decades.
  2. Paula R.
    Is a DMZ still relevant with zero trust architecture becoming popular? Seems like the perimeter approach is falling out of favor.
  3. Omar Farouk
    The name always confused me until I realized it's basically a buffer zone. Public facing servers go there, internal network stays protected.

Leave a comment