What Is DMZ (Demilitarized Zone)?

Also called: Perimeter network, Screened subnet

Related problems: Public-facing servers sit on the same network as everything else; Need to host a website, mail or file transfer server on-site; Partner connections reach too far into our network; Auditor asking how internet-facing systems are isolated

A demilitarized zone (DMZ) is a separate network segment that holds systems which must be reachable from the internet, such as a public web server, mail relay or file transfer server, and keeps them apart from the internal network. Firewall rules control traffic between the internet, the DMZ and the internal network, so that if a public-facing server is compromised, the attacker has a harder time reaching internal systems. It is also called a perimeter network or screened subnet.

At a glance

  • A DMZ is a buffer zone between the internet and the internal network.
  • It holds systems that accept outside connections; internal systems stay in more protected segments.
  • Firewall rules typically allow internet traffic in to the DMZ, but tightly limit traffic from the DMZ into the internal network.
  • Its protection depends on how restrictive those rules are and how the DMZ servers are maintained.
  • Cloud environments apply the same idea with public and private subnets and security groups.

What problem it solves

Servers that accept connections from the internet are routinely scanned and probed for weaknesses. If that server sits on the same network as file servers, finance systems and user laptops, a single flaw in it can give an attacker a foothold right next to everything else, setting up lateral movement across the network.

A DMZ limits that blast radius. Internet-facing systems are placed in their own zone, and the firewall is configured to allow only the specific connections they need into the internal network, such as a web server reaching one database on one port. A compromise of the public server is then more contained, and unusual traffic from the DMZ toward internal systems is easier to spot. It applies the defense in depth principle to the network edge.

How it works

Single-firewall design. One firewall has three or more interfaces: internet, DMZ and internal. Rules control what each zone can reach. This is common in smaller environments.

Dual-firewall design. An outer firewall sits between the internet and the DMZ, and an inner firewall between the DMZ and the internal network. Some designs use firewalls from different vendors so one flaw doesn’t defeat both, at higher cost and management effort.

Rules. Typical rules allow specific inbound services from the internet to DMZ hosts (for example, HTTPS to a web server), allow narrowly defined connections from DMZ hosts to internal systems, and block everything else. Internal users reach DMZ systems through defined paths.

Supporting controls. DMZ servers are hardened, patched promptly and monitored. A web application firewall (WAF) or reverse proxy often sits in front of web services. Logging traffic crossing zone boundaries helps detect compromise.

In the cloud. Public subnets, load balancers and security groups play the DMZ role, separating internet-facing resources from private workloads.

When it matters for buyers

  • When hosting anything internet-facing on-site. Web, mail, file transfer, remote access and partner gateways are the usual candidates.
  • When choosing or replacing a firewall. Interface count, zone support and throughput between zones matter. Our network firewalls overview covers the options.
  • When partners or vendors connect in. A DMZ or similar isolated segment can keep their connections from reaching the whole network.
  • When an audit asks about network architecture. Frameworks such as PCI DSS commonly expect internet-facing systems to be separated from sensitive internal ones.

Questions to ask vendors

  • How would you design zones for our public-facing systems, and what rules would cross from the DMZ to internal systems?
  • Does your firewall support the number of zones and interfaces we need, at the throughput we need between them?
  • How are DMZ servers patched and monitored, and who is responsible?
  • How is traffic crossing zone boundaries logged, and where do those logs go?
  • How would the same separation be achieved for our cloud workloads?

How it differs from network segmentation

Network segmentation is the general practice of dividing a network into zones with controlled traffic between them, for example separating guest Wi-Fi, payment systems and servers. A DMZ is one particular segment: the zone for systems the internet must reach. Zero trust designs go further by checking each connection individually, but many organizations still use a DMZ alongside them for public-facing services.

Frequently Asked Questions

Do we still need a DMZ if everything is in the cloud?
The same idea still applies, often under different names. Cloud networks commonly use public subnets, security groups and load balancers to separate internet-facing resources from private ones. If you host nothing on-premises that the internet reaches, you may not need a traditional on-site DMZ.
What typically goes in a DMZ?
Systems that must accept connections from outside: public web servers, reverse proxies, mail relays, file transfer servers, VPN or remote access gateways in some designs, and partner connection points.
What is a DMZ setting on a home or small office router?
On many consumer routers, "DMZ host" forwards all unsolicited internet traffic to one device. That is not the same as a business DMZ and leaves that device largely unprotected, so it is generally best avoided.
Is a DMZ the same as network segmentation?
A DMZ is one specific use of segmentation: a segment for internet-facing systems. Network segmentation is the broader practice of dividing a network into zones with controlled traffic between them.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.