What is DMZ in security?

DMZ: 非军事化区

摘抄自:Firewall with DMZ (lancom-systems.de)

The demilitarized zone (DMZ) represents a special area of the local area network, which is shielded by a firewall both from the Internet and from the LAN itself. Computers or servers that should be accessible from the unsecured network (Internet) should be placed into this network. These include, for example, your own FTP and Web servers.

First and foremost, the firewall protects the DMZ against attacks from the Internet. Additionally, the firewall also protects the LAN against the DMZ. The firewall is configured so that only the following accesses are possible:

  • Stations from the Internet can access the servers in the DMZ, but access to the LAN from the Internet is not possible.
  • The stations on the LAN can access the Internet and the servers in the DMZ.
  • The servers in the DMZ cannot access the stations in the LAN. This ensures that even a "cracked" server in the DMZ does not pose a security risk for the LAN.

 

The direct data exchange between LAN and DMZ is not possible via the LAN bridge if a dedicated DMZ port is used. The path from the LAN to the DMZ and vice versa is therefore only through the router, and thus through the firewall. This in turn shields the LAN against requests from the DMZ as well as against the Internet.

 

posted @   saaspeter  阅读(13)  评论(0编辑  收藏  举报
相关博文:
阅读排行:
· 无需6万激活码!GitHub神秘组织3小时极速复刻Manus,手把手教你使用OpenManus搭建本
· Manus爆火,是硬核还是营销?
· 终于写完轮子一部分:tcp代理 了,记录一下
· 别再用vector<bool>了!Google高级工程师:这可能是STL最大的设计失误
· 单元测试从入门到精通
点击右上角即可分享
微信分享提示