Network DMZ & Firewall Architecture

Free template — view it below, open it in draw.io, or customize it with AI in seconds.

Customize with AI — free Open in draw.io

The prompt behind this diagram

An enterprise network DMZ architecture: internet edge router, external firewall, DMZ with reverse proxy and mail gateway, internal firewall, core switch, internal VLANs for servers, workstations and management, IDS/IPS taps, VPN concentrator for remote access.

Paste your own description (or Terraform / docker-compose / SQL schema) into draft1 and get a diagram like this for your exact system.

What this diagram shows

This diagram shows a layered network security architecture that isolates public-facing services from internal assets using two firewalls and a demilitarized zone (DMZ). Traffic flows from the internet through an edge firewall, then into the DMZ where public services run, then through a second internal firewall to reach trusted networks. Intrusion detection systems monitor suspicious activity across boundaries, and a VPN gateway handles authenticated remote access to internal resources. This separation ensures that if an external attacker compromises a DMZ service, they cannot immediately reach backend databases, user workstations, or core infrastructure.

Key components

When to use it

Use this architecture for any organization operating customer-facing services online. It applies to e-commerce platforms, SaaS applications, web portals, and hybrid infrastructures where external users must access some systems but not others. Mandatory for regulated industries (financial services, healthcare, government) where data isolation and audit trails are required. Also appropriate when your team has capacity to manage two firewall instances and monitor IDS alerts.

Common mistakes

Adapting it to your system

Replace the generic DMZ services box with your actual systems: web server IP ranges, mail server hostnames, DNS servers, or load balancers. Specify the internal firewall rules by listing which DMZ hosts can reach which backend systems (for example, web tier can query database on port 3306, but not SSH). Name your VPN solution if using Cisco ASA, pfSense, or cloud-native endpoints, and indicate the identity provider it uses. Add your SOC or monitoring tool as the consumer of IDS logs. Adjust segment names to match your organization (production, development, admin).

More templates

AWS VPC Multi-AZ Architecture

A production AWS VPC layout template: public/private/data subnets across two AZs with NAT, RDS multi-AZ and S3 endpoin

AWS EKS Cluster Architecture

An EKS reference template: control plane, node groups, ALB ingress, ECR, IAM roles for service accounts and storage.

AWS ECS Fargate Architecture

Serverless containers on AWS: ALB, Fargate services, SQS decoupling, RDS and Redis — a production ECS template.

Azure 3-Tier Web Architecture

The Azure counterpart of the classic 3-tier stack: Front Door, App Gateway, App Services, SQL and Redis in a VNet.

GCP Web Application Architecture

A serverless GCP stack template: Cloud Run, Cloud SQL, Memorystore, Pub/Sub and CDN-fronted load balancing.

Kafka Event Streaming Pipeline

End-to-end event streaming: CDC ingestion, a three-broker cluster, stream processing and analytical sinks.

Data Lakehouse Architecture

Bronze/silver/gold lakehouse template: ingestion, Delta Lake zones, Spark + dbt transforms and a BI serving layer.