Cisco CCNA (200-301)Network FundamentalsMedium

A security architect is designing a network segment that will host a public-facing web server. The server must be reachable from the internet but isolated from the internal corporate LAN. Which firewall design concept best fits this requirement?

  1. APlacing the server on the same VLAN as internal users
  2. BEnabling PAT on the internal router only
  3. CAssigning the server a link-local IPv6 address
  4. DConfiguring a demilitarized zone (DMZ) with separate firewall policies
Show answer & explanation

Correct answer: D. Configuring a demilitarized zone (DMZ) with separate firewall policies

A DMZ is a separate network segment, isolated by firewall rules, that hosts public-facing servers. It allows controlled inbound access from the internet while restricting direct access to the internal LAN, providing an additional layer of security.

Why the other options are wrong

  • A. Placing the server on the internal VLAN would expose the internal LAN to direct risk from internet traffic.
  • B. PAT handles address translation, not segmentation or security isolation.
  • C. Link-local addresses are non-routable and would prevent the server from being reachable at all.

DMZ (Demilitarized Zone)

A separate, firewall-isolated network segment used to host public-facing servers, providing a buffer between the internet and the internal LAN.

  • Typically has its own firewall interface/zone
  • Limits exposure of internal LAN to external threats
  • Common hosts: web, email, DNS servers

Memory trick: 'DMZ = no-man's-land between internet and LAN.'

More Network Fundamentals questions