No, the server in the DMZ does not have an interface in the private LAN.
That is the whole point of making a DMZ. It isolates the DMZ servers from
the LAN clients. The LAN clients can see the router/firewall and it can see
the machine in the DMZ.
The server would only need an interface in both subnets if it was acting
as the firewall between the LAN and the DMZ.
NewsGr wrote:
> if I setup a DMZ with a new subnet(ie 10.10.10.1) with my router,
> which has a second (dmz) interface, will I need to
> put 2 NICs on the server in the DMZ? Will I need any special subnet
> mask for my PCs in the internal Lan(192.168.x.x)?
> The person setting up the router thnks everything will be handled
> thru the router. I thought I would need a multihomed system, or does
> the router serve that purpose.
>
>
> Thanks ALL
>
> CR
|