Cisco CCNA (200-301)Network FundamentalsMedium
A security architect is designing a network segment that will host a public-facing web server. The server must be reachable from the internet but isolated from the internal corporate LAN. Which firewall design concept best fits this requirement?
- APlacing the server on the same VLAN as internal users
- BEnabling PAT on the internal router only
- CAssigning the server a link-local IPv6 address
- DConfiguring a demilitarized zone (DMZ) with separate firewall policies
Show answer & explanationAnswer & explanation
Correct answer: D. Configuring a demilitarized zone (DMZ) with separate firewall policies
A DMZ is a separate network segment, isolated by firewall rules, that hosts public-facing servers. It allows controlled inbound access from the internet while restricting direct access to the internal LAN, providing an additional layer of security.
Why the other options are wrong
- A. Placing the server on the internal VLAN would expose the internal LAN to direct risk from internet traffic.
- B. PAT handles address translation, not segmentation or security isolation.
- C. Link-local addresses are non-routable and would prevent the server from being reachable at all.
DMZ (Demilitarized Zone)
A separate, firewall-isolated network segment used to host public-facing servers, providing a buffer between the internet and the internal LAN.
- Typically has its own firewall interface/zone
- Limits exposure of internal LAN to external threats
- Common hosts: web, email, DNS servers
Memory trick: 'DMZ = no-man's-land between internet and LAN.'