Network DMZ & Firewall Architecture
Free template — view it below, open it in draw.io, or customize it with AI in seconds.
The prompt behind this diagram
An enterprise network DMZ architecture: internet edge router, external firewall, DMZ with reverse proxy and mail gateway, internal firewall, core switch, internal VLANs for servers, workstations and management, IDS/IPS taps, VPN concentrator for remote access.
Paste your own description (or Terraform / docker-compose / SQL schema) into draft1 and get a diagram like this for your exact system.
What this diagram shows
This diagram shows a layered network security architecture that isolates public-facing services from internal assets using two firewalls and a demilitarized zone (DMZ). Traffic flows from the internet through an edge firewall, then into the DMZ where public services run, then through a second internal firewall to reach trusted networks. Intrusion detection systems monitor suspicious activity across boundaries, and a VPN gateway handles authenticated remote access to internal resources. This separation ensures that if an external attacker compromises a DMZ service, they cannot immediately reach backend databases, user workstations, or core infrastructure.
Key components
- Edge Firewall — Filters internet traffic before it enters the network, blocking malicious packets and enforcing initial ingress rules based on source, destination, and protocol.
- DMZ Segment — Isolated network zone hosting publicly accessible services such as web servers, mail relays, and DNS resolvers that require external connectivity.
- Internal Firewall — Second perimeter that controls traffic from the DMZ into trusted internal networks, enforcing strict allow-lists for backend communication.
- IDS/IPS Sensor — Inspects traffic flows at the network boundary to detect and optionally block exploit signatures, anomalous behaviour, and known attack patterns.
- Remote Access VPN Gateway — Authenticates and encrypts connections from external users, tunneling traffic into the internal network only after credential verification.
- Internal Network Segment — Protected trust zone containing databases, file servers, user workstations, and management interfaces separated by firewall rules from the DMZ.
When to use it
Use this architecture for any organization operating customer-facing services online. It applies to e-commerce platforms, SaaS applications, web portals, and hybrid infrastructures where external users must access some systems but not others. Mandatory for regulated industries (financial services, healthcare, government) where data isolation and audit trails are required. Also appropriate when your team has capacity to manage two firewall instances and monitor IDS alerts.
Common mistakes
- Placing internal databases or administrative consoles in the DMZ on the assumption that firewalls make them safe to expose directly.
- Failing to restrict DMZ-to-internal firewall rules, allowing any DMZ service to freely query backend systems and thus spreading breach impact.
- Not monitoring or acting on IDS alerts, leaving the detection layer as a silent logger rather than an active defence that informs incident response.
Adapting it to your system
Replace the generic DMZ services box with your actual systems: web server IP ranges, mail server hostnames, DNS servers, or load balancers. Specify the internal firewall rules by listing which DMZ hosts can reach which backend systems (for example, web tier can query database on port 3306, but not SSH). Name your VPN solution if using Cisco ASA, pfSense, or cloud-native endpoints, and indicate the identity provider it uses. Add your SOC or monitoring tool as the consumer of IDS logs. Adjust segment names to match your organization (production, development, admin).
More templates
AWS VPC Multi-AZ Architecture
A production AWS VPC layout template: public/private/data subnets across two AZs with NAT, RDS multi-AZ and S3 endpoin
AWS EKS Cluster Architecture
An EKS reference template: control plane, node groups, ALB ingress, ECR, IAM roles for service accounts and storage.
AWS ECS Fargate Architecture
Serverless containers on AWS: ALB, Fargate services, SQS decoupling, RDS and Redis — a production ECS template.
Azure 3-Tier Web Architecture
The Azure counterpart of the classic 3-tier stack: Front Door, App Gateway, App Services, SQL and Redis in a VNet.
GCP Web Application Architecture
A serverless GCP stack template: Cloud Run, Cloud SQL, Memorystore, Pub/Sub and CDN-fronted load balancing.
Kafka Event Streaming Pipeline
End-to-end event streaming: CDC ingestion, a three-broker cluster, stream processing and analytical sinks.
Data Lakehouse Architecture
Bronze/silver/gold lakehouse template: ingestion, Delta Lake zones, Spark + dbt transforms and a BI serving layer.