Reading time: about 1 minute
Demilitarized Zone: In theory...
Demilitarized Zone: Have you heard of it before? But in a completely different context? That’s certainly possible. After all, the term originally comes from politics and refers to the buffer zone between North and South Korea. But in the field of networking, the demilitarized zone also has a meaning all its own—and has since become a fundamental component of modern network security.
Wasn’t there something else? That’s right: firewalls. And to protect against hacker attacks, every network should have at least one firewall. But because companies, in particular, are increasingly providing digital services and therefore need to be directly connected to the Internet—think of remote work in this context—the firewall must also increasingly allow a certain level of connection to the outside world. Which, of course, entails certain risks.
To keep these risks as low as possible, a separate network can be set up between the internal network and the internet: the demilitarized zone (DMZ). The services and devices that make parts of the company’s internal communications available to the outside world are then placed in this DMZ: for example, web servers that are also to be accessed from outside the network, database servers, or mail servers.
... and Practice
The DMZ we set up for Deutsche Post AG serves to protect the branch IT system and the partner portal, which supports the approximately 13,000 partner branches in providing customer service. Both applications must be available to their users not only on the intranet but also on the internet. However, given all the confidential data contained in the applications, this isn’t easily possible—or at least not advisable.
The solution? We created “light versions” of the applications and placed the server in the DMZ. On the one hand, this naturally means that the applications have a more limited range of functions. On the other hand, it also means that internal data is safe from hackers. This is because the servers located in the DMZ are not part of the internal network from a security standpoint and therefore cannot transmit any information from it to the outside world.
For Large and Small Companies
You might be thinking: Deutsche Post AG? It’s obvious they need something like this. But us, as a small-to-medium-sized business? Nah. – Wrong! As soon as data is involved, security can’t be emphasized enough. This applies to global corporations just as much as it does to smaller companies. We atpunkt.dealso have a DMZ. And we can only advise other medium-sized businesses to set one up as well. We’d be happy to help:
!