A demilitarized zone (DMZ) is a separate network segment that holds systems which must be reachable from the internet, such as a public web server, mail relay or file transfer server, and keeps them apart from the internal network. Firewall rules control traffic between the internet, the DMZ and the internal network, so that if a public-facing server is compromised, the attacker has a harder time reaching internal systems. It is also called a perimeter network or screened subnet.
At a glance
- A DMZ is a buffer zone between the internet and the internal network.
- It holds systems that accept outside connections; internal systems stay in more protected segments.
- Firewall rules typically allow internet traffic in to the DMZ, but tightly limit traffic from the DMZ into the internal network.
- Its protection depends on how restrictive those rules are and how the DMZ servers are maintained.
- Cloud environments apply the same idea with public and private subnets and security groups.
What problem it solves
Servers that accept connections from the internet are routinely scanned and probed for weaknesses. If that server sits on the same network as file servers, finance systems and user laptops, a single flaw in it can give an attacker a foothold right next to everything else, setting up lateral movement across the network.
A DMZ limits that blast radius. Internet-facing systems are placed in their own zone, and the firewall is configured to allow only the specific connections they need into the internal network, such as a web server reaching one database on one port. A compromise of the public server is then more contained, and unusual traffic from the DMZ toward internal systems is easier to spot. It applies the defense in depth principle to the network edge.
How it works
Single-firewall design. One firewall has three or more interfaces: internet, DMZ and internal. Rules control what each zone can reach. This is common in smaller environments.
Dual-firewall design. An outer firewall sits between the internet and the DMZ, and an inner firewall between the DMZ and the internal network. Some designs use firewalls from different vendors so one flaw doesn’t defeat both, at higher cost and management effort.
Rules. Typical rules allow specific inbound services from the internet to DMZ hosts (for example, HTTPS to a web server), allow narrowly defined connections from DMZ hosts to internal systems, and block everything else. Internal users reach DMZ systems through defined paths.
Supporting controls. DMZ servers are hardened, patched promptly and monitored. A web application firewall (WAF) or reverse proxy often sits in front of web services. Logging traffic crossing zone boundaries helps detect compromise.
In the cloud. Public subnets, load balancers and security groups play the DMZ role, separating internet-facing resources from private workloads.
When it matters for buyers
- When hosting anything internet-facing on-site. Web, mail, file transfer, remote access and partner gateways are the usual candidates.
- When choosing or replacing a firewall. Interface count, zone support and throughput between zones matter. Our network firewalls overview covers the options.
- When partners or vendors connect in. A DMZ or similar isolated segment can keep their connections from reaching the whole network.
- When an audit asks about network architecture. Frameworks such as PCI DSS commonly expect internet-facing systems to be separated from sensitive internal ones.
Questions to ask vendors
- How would you design zones for our public-facing systems, and what rules would cross from the DMZ to internal systems?
- Does your firewall support the number of zones and interfaces we need, at the throughput we need between them?
- How are DMZ servers patched and monitored, and who is responsible?
- How is traffic crossing zone boundaries logged, and where do those logs go?
- How would the same separation be achieved for our cloud workloads?
How it differs from network segmentation
Network segmentation is the general practice of dividing a network into zones with controlled traffic between them, for example separating guest Wi-Fi, payment systems and servers. A DMZ is one particular segment: the zone for systems the internet must reach. Zero trust designs go further by checking each connection individually, but many organizations still use a DMZ alongside them for public-facing services.
