• Basically they are the same thing, both types of host are exposed to an untrusted network and any access from the untrusted to the trusted network must pass through the host. A bastion host is typically a screened host firewall combining packet filtering functions, with a separate dedicated firewall – generally to minimize network traffic. A sacrificial host is a sole network defender on the network perimeter.