• An external firewall is placed at the edge of a local
or enterprise network, just inside the boundary
router that connects to the Internet or some wide
area network (WAN).
• One or more internal firewalls protect the bulk of
the enterprise network.
• Between these two types of firewalls are one or
more networked devices in a region referred to as
a DMZ (demilitarized zone) network.
• Systems that are externally accessible but need
some protections are usually located on DMZ
networks.
• Typically, the systems in the DMZ require or foster
external connectivity, such as a corporate Web
site, an e-mail server, or a DNS server.