DMZ: where the public stuff goes
A semi-trusted zone sits between the internet and the trusted internal network. Public servers (web, mail, DNS) live here so a compromise does not immediately reach internal systems.
Internet
Untrusted, hostile by default.
EVERYONE
→Firewall
DMZ
Semi-trusted. Hosts services reachable from the internet.
Public web, mail relay, public DNS
→Firewall
Internal
Trusted. Workstations, databases, internal apps.
Employees, internal apps
Network defenses cheat sheet
IDS
Detects and alerts. Sits out-of-band. Does not block.
IPS
Detects, alerts, AND blocks. Sits inline in the traffic path.
NAT
Translates private IP addresses to a public IP. Hides internal addressing.
PAT
Many internal hosts share one public IP by tracking source ports. Home routers do this.
Forward proxy
Acts on behalf of clients. Used for content filtering and caching.
Reverse proxy
Acts on behalf of servers. Used for load balancing and TLS handling.
VLAN
Logically splits one switch into multiple broadcast domains for segmentation.
Segmentation
Splits the network into zones so a compromise in one zone does not roam everywhere.