What is a DMZ?
Have you ever wondered what a DMZ is when you hear your information security people talking amongst themselves?
The main purpose for a DMZ is to separate hosts that need to be accessed from an external network from the internal network. This is useful for companies that need to offer information and services to external users like Web, DNS, Mail and FTP access to the outside world. In this case, the hosts on the internal network can initiate communication with the hosts on the DMZ network and hosts from the external network can initiate communication with hosts on the DMZ network. However in most cases hosts from the external network cannot initiate communications with hosts on the internal network and hosts on the DMZ network cannot initiate communications with hosts on the internal network.
If you are interested in information assurance then this article is a good place to start. It is a quality overview of some of the basic scenarios that we run in to when consulting with clients interested in deploying network security measures throughout their enterprise.