In doing some reading I see that it's usually recommended to put a Front end for Exchange in a DMZ, and allow it to communicate with the backend. Also to put a Secure Gateway for Citrix products into a DMZ, and then let it communicate with the actual Citrix server from there.
My question is, when talking about this DMZ. Are we talking about a seperate physical network, which then has the ability to forward ports? Or are we talking about just a different server in the network?
I'm using a Watchguard x55 (Just about to upgrade to a x750), and it has the ability to create seperate physical networks.. Since we have multiple WAN IP's, I would guess that you would direct traffic to the DMZ over one IP, then forward it to the IP of the main network? Or am I missing something here?
Thanks
David
Start Free Trial