A DMZ (demilitarised zone) in network security is a subnetwork that sits between an organisation's private internal network and the public internet, hosting servers that must be externally accessible — such as web, email, and FTP servers — while shielding the internal network from direct external access.

Why does a DMZ exist?

Many organisations need to run servers that are accessible to the public internet: a company website, an email server, or a public-facing file server. But placing those servers directly on the internal private network would be dangerous — anyone who compromised a public server would gain direct access to sensitive internal systems: employee databases, financial records, source code.

A DMZ solves this by creating a security buffer zone. Public servers sit in the DMZ where they can be reached from the internet, but the internal network is behind a second firewall that the public (and even a compromised DMZ server) cannot cross freely. The name comes from military terminology — a demilitarised zone is a buffer between two territories where neither side deploys weapons.

What does the DMZ architecture look like?

The standard double-firewall DMZ architecture has three distinct network zones:

[Internet]
    |
[Outer Firewall]      ← filters incoming/outgoing internet traffic
    |
[DMZ]                 ← public-facing servers: web, email, FTP, DNS
    |
[Inner Firewall]      ← strictly controls traffic to the internal network
    |
[Internal Network]    ← employee workstations, databases, internal servers
Zone What it contains Who can access it
Internet All external traffic Public (anyone)
DMZ Web server, email server, DNS server, FTP server Internet (controlled) + internal network
Internal network Employee desktops, HR database, financial systems Internal users only

An attacker who compromises the web server in the DMZ gains access to the DMZ — but the inner firewall blocks their path to the internal network, limiting the damage they can do.

What traffic do the firewalls allow?

Each firewall has rules (an access control list) that specify which traffic is permitted:

Outer firewall rules (example):

  • Allow: HTTP (port 80) and HTTPS (port 443) from internet to web server in DMZ.
  • Allow: SMTP (port 25) from internet to email server in DMZ.
  • Deny: all other traffic from internet to DMZ.
  • Allow: responses to outbound connections initiated from inside.

Inner firewall rules (example):

  • Allow: database queries from web server in DMZ to database server on internal network (specific port, specific source IP only).
  • Allow: internal users to access internet via web proxy.
  • Deny: all direct connections from DMZ to internal network (except the specific database exception above).
  • Deny: all traffic from internet to internal network.

The inner firewall's rules are deliberately strict. Even traffic from the DMZ is treated as semi-trusted — a compromised DMZ server should not be able to reach sensitive internal systems.

Are there simpler DMZ alternatives?

Some organisations use a single-firewall with three interfaces (one facing the internet, one facing the DMZ, one facing the internal network) rather than two separate firewalls. This is cheaper and simpler to manage but provides weaker security: if the single firewall is compromised, all three zones are exposed simultaneously. The double-firewall approach means an attacker must compromise two separate devices before reaching the internal network.

Architecture Cost Security level Risk if firewall is compromised
No DMZ Low Poor — all servers on internal network Full access to everything
Single firewall with DMZ Medium Good All zones exposed
Double firewall with DMZ Higher Best Only the perimeter zone exposed

What servers typically live in a DMZ?

  • Web server — serves the public website (HTTP/HTTPS).
  • Mail server (SMTP) — receives inbound email from the internet.
  • DNS server — resolves external domain queries (a separate authoritative DNS server for the organisation's public domain).
  • FTP server — allows partners or customers to upload/download files.
  • VPN concentrator — the termination point for remote workers' VPN connections; once authenticated, users connect to the internal network through the inner firewall.
  • Reverse proxy — forwards requests from the internet to internal servers, translating external URLs to internal addresses.

Frequently asked questions

Is a DMZ the same as a firewall?

No. A firewall is a device that enforces access control rules on network traffic. A DMZ is a network zone — a segment of the network architecture. The DMZ is protected by firewalls (usually two), but it is not itself a firewall. They work together: the firewalls control what traffic may enter or leave the DMZ.

Does a home network need a DMZ?

Home routers often have a "DMZ host" feature, which forwards all incoming internet traffic to one specific device on the home network. This is useful for game consoles or servers you want to access from the internet, but it provides no security isolation — it is not a true DMZ. In a genuine DMZ, the server is on a separate network segment with its own firewall. Home users should only enable the router's DMZ host feature if they understand the security implications.

What happens if a web server in the DMZ is hacked?

The attacker now controls a server in the DMZ. With a well-configured inner firewall, they can access only the DMZ — not the internal network. The inner firewall should allow only the specific database connection the web server legitimately needs, so the attacker cannot reach other internal services. This principle of giving each component only the access it genuinely requires is called the principle of least privilege, and it limits the blast radius when any component is compromised.

How does a DMZ relate to the principle of defence in depth?

Defence in depth means layering multiple security controls so that an attacker must defeat several independent barriers to reach the most sensitive assets. A DMZ is one layer of this strategy: even if the outer firewall and the web server in the DMZ are compromised, the inner firewall remains. Other layers include intrusion detection systems, encryption of internal data, strong authentication for internal systems, and monitoring and logging that detects suspicious activity after a breach occurs.


Master network security architecture with Professor Turing's GCSE Computer Science tutoring at aitutors.me.