DMZ

A demilitarized zone (DMZ) or perimeter network is a physical or logical boundary between the internal and the external network of an organization. The external network can be the internet. The purpose is to add an additional security layer to the internal network. You don't open any ports from the internal network to the internet, but only to the DMZ. Azure offers multiple features that you can use to create a DMZ, such as Network Security Groups (NSGs), firewalls, and User Defined Routes (UDRs).

The following diagram shows an example of a physical DMZ created using a frontend VNet with two VMs in it. Only this VNet is connected to the internet.

Simple DMZ example

Get Architecting Microsoft Azure Solutions - Exam Guide 70-535 now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.