A demilitarized zone is a network segment that sits between the internet and the internal network. Public-facing servers live there: web servers, mail gateways, and reverse proxies. If an attacker compromises one of those servers, the DMZ limits how far they can go. The internal network sits behind another firewall. The DMZ is the buffer.
The design comes from military thinking. Put a neutral strip between the front line and the base. In network terms, the DMZ holds systems that need to be reachable from the internet but should not have direct access to internal resources. A web server in the DMZ can talk to a database in the internal network through a controlled rule. It cannot browse the corporate file shares or reach the HR system. The firewall rules are strict and one-directional. The DMZ absorbs attacks. It also adds complexity. More segments mean more rules to manage and more places to misconfigure. A DMZ with a permissive rule set defeats the purpose. The value is in the restriction, not the architecture.
Typical DMZ hosts
- Web servers — public-facing websites and applications
- Mail gateways — filter inbound and outbound email
- DNS servers — resolve external names
- Reverse proxies — terminate TLS and forward requests
A DMZ is not a magic shield. A compromised server in the DMZ still gives an attacker a foothold. The goal is to make that foothold less useful.
Comments (3)
Leave a comment