What is the real function and use of a DMZ on a network? For example a Database would exist in the DMZ for your web server in the DMZ that is publicly accessible But that database would be shielded from remote public connections, and only people on the trusted private network could reach the database
To DMZ, or not to DMZ - Information Security Stack Exchange The DMZ is a containment area so that a subverted server does not gain immediate access to your most valuable data (which will be presumably kept in the inner network) Your AD and SQL servers are meant to be used only by machines from your network, not by machines from the outside, so you put them in the inner network