Flux rss

DMZ (Demilitarized Zone)

ProtectionNetwork SecuritySystem SecurityData SecurityElectrical ProtectionMore information

The Concept of Isolation

Firewall systems allow for the definition of access rules between two networks. However, in practice, companies generally have several subnetworks with different security policies. This is why it is necessary to set up firewall architectures that isolate a company's different networks. This is called "network isolation".

DMZ Architecture

While some machines of the internal network need to be externally accessible (web servers, e-mail servers, FTP servers), sometimes it is necessary to create a new interface to a separate network that is accessible both from the internal network and externally without the risk of compromising company security. The term "demilitarised zone" or DMZ refers to this isolated zone that hosts the applications made available to the public. The DMZ acts as a "buffer zone" between the network that needs protecting and the hostile network.

DMZ - Demilitarized Zone

The servers in the DMZ are called "bastion hosts" because they act as an outpost in the company's network.

The security policy for the DMZ is generally the following:

  • Traffic from the external network to the DMZ is autorised
  • Traffic from the external network to the internal network is prohibited
  • Traffic from the internal network to the DMZ is autorised
  • Traffic from the internal network to the external network is authorised
  • Traffic from the DMZ to the internal network is prohibited
  • Traffic from the DMZ to the external network is denied

Thus, the DMZ possesses an intermediate security level that is not high enough for storing critical company data.

It should be noted that DMZs can be set up internally in order to isolate the internal network with varying levels of protection and avoid internal intrusions.

Last update on Thursday October 16, 2008 02:43:22 PM.

This document entitled « DMZ (Demilitarized Zone) » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.
Zone alarm and Avast are not compatible Zone alarm and Avast are not compatible Myth Reality Myth ZoneAlarm and Avast are not compatible.They must not be installed on the same PC Reality You can run both Avast and ZoneAlarm on the same PC. Explanation: If you... en.kioskea.net/faq/sujet-464-zone-alarm-and-avast-are-not-compatible
Download ZoneAlarm ZoneAlarm is a firewall easy to use which identifies and blocks hackers and other unknown threats , it can also make your computer invisible to anyone on the Internet. NB : ZoneAlarm is FREE for individual and not for profit charitable entity use... en.kioskea.net/telecharger/telecharger-41-zonealarm
Download ZoneAlarm ZoneAlarm is a user friendly antivirus that gives a hard time to hackers and other unknown threats. In addition, ZoneAlarm: Identifies systematically hackers and blocks access attempts Make your computer automatically "invisible" to... en.kioskea.net/telecharger/telecharger-897-zonealarm
Blank Page: Unable to connect to HotmailBlank Page: Unable to connect to Hotmail 1. Account name and Password 2. Browser settings set to enable cookies. 3. SSL configurations Configure your Cipher Strength Enable SSL and TLS Clear History and delete Cookies Disable Third Party... en.kioskea.net/faq/sujet-152-blank-page-unable-to-connect-to-hotmail
What are Pop-up Ads and how to block themWhat are Pop-up Ads and how to block them Pop-up ads (a.k.a popups) are windows that contain advertisements for various online services and usually show up when some websites are opened. They are meant to attract web traffic but can also collect... en.kioskea.net/faq/sujet-104-what-are-pop-up-ads-and-how-to-block-them
A connected PC will be infected within the first 5 minutes.A connected PC will be infected within the first 5 minutes. Myth Truth Myth Your PC gets infected during the first 5 minutes of internet connection. Truth In fact all operating system possess flaws and bugs due to programming errors... en.kioskea.net/faq/sujet-455-a-connected-pc-will-be-infected-within-the-first-5-minutes
No Internet Access with Zone Alarm Stealth MoHi, I have Zone Alarm 7.0.470, Windows XP professional ( all patches etc I believe ) I have the same problem on both Desktop and Laptop via wireless router ( BT Voyager ). I could not access the internet, but could access the router. I have reset the... en.kioskea.net/forum/affich-14297-no-internet-access-with-zone-alarm-stealth-mo
Avast or Zone AlarmHello, My friend told me not to install Zone Alarm on my PC because I will get a lot of error messages and to install Avast because it is better, but another friend told me to install Zone Alarm as he thinks it is the best antivirus ever. I dont know... en.kioskea.net/forum/affich-42092-avast-or-zone-alarm
ZonealarmHello, anyone can tell me where can i find zonealarm antivirus for free? en.kioskea.net/forum/affich-19088-zonealarm
Download Taskbar Repair Tool Plus!Taskbar Repair Tool Plus! an only valid software for Windows XP is. He allows you to personalize the task bar, the zone of notification and the bar of quick launching. In spite of the making that it is in English, its interface is clear and... en.kioskea.net/telecharger/telecharger-387-taskbar-repair-tool-plus
Download FastStone CaptureThis software of capture is light, effective and simple to use. You can capture a full-featured screen, a window, a bounded zone (rectangle or freehand) or even a scrolling page (very useful for example to capture a complete web page). Integrated... en.kioskea.net/telecharger/telecharger-1396-faststone-capture
Download InstantShotInstantShot is an application it captures of very simple but efficient screen. InstantShot notably allows: to re-size the zone of capture from initial selection, to use a rectangle of selection predefined, to make successive captures or in... en.kioskea.net/telecharger/telecharger-1049-instantshot
Processes - vsmon - vsmon.exe vsmon.exe (vsmon stands for True Vector Monitor) is a process which corresponds to a component of the firewall ZoneAlarm. It is an application which can safely be terminated. However, it is recommended that you not do so, in order to ensure that the... en.kioskea.net/processus/vsmon-exe.php3
Processes - zlclient - zlclient.exe zlclient.exe (zlclient stands for Zone Labs Client) is a process which corresponds to the firewall ZoneAlarm. It is an application which can safely be terminated. However, it is recommended that you not do so, in order to ensure that the firewall... en.kioskea.net/processus/zlclient-exe.php3
Installing a firewall with ZoneAlarm When a computer is connected to the Internet (or any other network), it is a potential target for attacks. Numerous data packets are randomly sent by hackers to spot connected machines. The latter are looking for a security hole to exploit it and... en.kioskea.net/configuration-reseau/zonealarm.php3