4
Address Translation
79
Using a DMZ
At
this
point,
it
is
important
to
understand
the
role
of
networks
designated
as
a
DMZ
as
SAT
IP
rules
are
of
often
used
with
them.
The
DMZ’s
purpose
is
to
act
as
a
network
where
resources,
such
as
servers,
are
placed
for
access
by
external,
untrusted
clients,
typically
across
the
public
Internet.
This
network,
therefore,
has
the
maximum
exposure
to
external
threats.
By
isolating
the
DMZ
network,
a
clear
security
separation
is
created
from
sensitive
internal
networks.
SEG
security
policies
can
then
control
traffic
flows
between
the
DMZ
and
internal
networks,
isolating
any
security
problems
occurring
in
the
DMZ.
The
illustration
below
shows
a
typical
network
arrangement
with
a
SEG
mediating
communications
between
the
public
Internet
and
servers
in
a
DMZ
and
between
the
DMZ
and
local
clients
on
an
internal
network
called
LAN
.
Figure 4. The role of the DMZ