Analyzing Routers on the DMZ for External Connections

The decision of whether the routers on the DeMilitarized Zone (DMZ) should only run L1 routing or participate in L2 routing depends on the mechanics of advertising these external networks into the core.

If the only connections to external networks were through this DMZ, it would be relatively simple to advertise a single default route into the core; however, there is a backup Internet connection over on the other side of the network. To get a better handle on this, refer to Figure 6-4.

Figure 6-4. External Connections

To optimize this portion of the network, you need to be able to do the ...

Get Advanced IP Network Design (CCIE Professional Development) now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.