I-De-Militarized Zone ku-Computer Networking

Ekuxhumaneni kwenethiwekhi, i-De-Militarized Zone (DMZ) iyimishini ekhethekile yendawo yenethiwekhi eyenzelwe ukuthuthukisa ukuphepha ngokuhlukanisa amakhompyutha ohlangothini ngalunye lwe- firewall . I-DMZ ingahle ibekwe kumanethiwekhi wekhaya noma amabhizinisi, nakuba usizo lwabo emakhaya lilinganiselwe.

Uphi i-DMZ Ewusizo?

Enethiwekhi yekhaya, amakhompiyutha namanye amadivaysi ajwayele ukufakwa kunethiwekhi yendawo yendawo (i-LAN) exhunywe kwi-intanethi nge- router broadband . I-router isebenza njenge-firewall, ihlunga ngokukhetha i-traffic kusuka ngaphandle ukuze isize ukuqinisekisa ukuthi imilayezo evumelekile idlula. I-DMZ ihlukanisa ukwahlukana kwenethiwekhi enjalo ibe yizingxenye ezimbili ngokuthatha amadivaysi owodwa noma ngaphezulu ngaphakathi kwe-firewall futhi ibathuthela ngaphandle. Lokhu kulungiselelwa kangcono kuvikela amadivayisi angaphakathi kusuka ekuhlaselweni okungenzeka ngaphandle (futhi ngokuphambene nalokho).

I-DMZ iyasiza emakhaya lapho inethiwekhi isebenza iseva . Iseva ingahle ibekwe ku-DMZ ukuze abasebenzisi be-intanethi bakwazi ukuyifinyelela ngekheli layo le-IP lomphakathi , futhi yonke inethiwekhi yekhaya ivikelwe ekuhlaselweni lapho kwenzeka khona iseva. Eminyakeni edlule, ngaphambi kokuba amasevisi wefu atholakale futhi athandwa kakhulu, abantu bavame ukugijimela iWebhu, i- VoIP noma amaseva wefayela kusuka emakhaya abo kanye nama-DMZ enza umqondo ozwakalayo.

Ngakolunye uhlangothi, amanethiwekhi wekhompiyutha yebhizinisi , angasebenzisa ngokujwayelekile ukusebenzisa i-DMZs ukusiza ukuphatha iWebhu yezinkampani kanye namanye amaseva abheke umphakathi. Amanethiwekhi asekhaya namuhla avame ukuzuza ngokuhlukahluka kwe-DMZ ebizwa ngokuthi i-DMZ hosting (bheka ngezansi).

Ukusekela kwe-DMZ Host Host in Broadband Routers

Ulwazi mayelana nama-DMZ enethiwekhi lungadanisa ukuqonda ekuqaleni ngoba leli gama libhekisela ezinhlotsheni ezimbili zokulungiselela. Isici esiphezulu se- DMZ se-home routers asisunguli i-subnetwork ephelele ye-DMZ kodwa kunalokho iveza idivayisi eyodwa kwinethiwekhi yendawo ekhona ukusebenza ngaphandle kwe-firewall ngenkathi yonke inethiwekhi isebenza njengesijwayelekile.

Ukuze ulungise ukusekelwa kwe-DMZ kumsingathi kunethiwekhi yekhaya, ngena ngemvume ku-console router uphinde unike amandla inketho ye-DMZ yesitoreji ekhutshaziwe ngokuzenzakalelayo. Faka ikheli le-IP langasese ledivaysi yendawo ekhethwe njengomphathi. I-Xbox noma i-PlayStation game consoles ivame ukukhethwa njengezinsizakalo ze-DMZ ukuvimbela i-firewall yasekhaya ukuphazamisa ukugembula kwe-intanethi. Qinisekisa ukuthi umninikhaya usebenzisa ikheli le-IP eliyisimo (kunokuba asebenze ngokuzenzekelayo), ngaphandle kwalokho, idivaysi ehlukile ingase izuze ikheli le-IP elikhethiwe bese liba ngummemezeli we-DMZ esikhundleni.

Ukwesekwa kweqiniso kwe-DMZ

Ngokuphambene nokusingathwa kwe-DMZ, i-DMZ yangempela (ngezinye izikhathi ebizwa ngokuthi i-DMZ yokuthengisa) isungula i-subnetwork entsha ngaphandle kwe-firewall lapho i-computer eyodwa noma ngaphezulu isebenza khona. Lezo amakhompiyutha ngaphandle zifaka ungqimba olwengeziwe lokuvikela amakhompyutha ngemuva kwe-firewall njengoba zonke izicelo ezingenayo zitholwa futhi kumele kuqala zidlule kwi-computer ye-DMZ ngaphambi kokufinyelela ku-firewall. Ama-DMZ eqiniso nawo avimbela amakhompyutha ngemuva kwe-firewall ekukhulumisaneni ngqo namadivaysi e-DMZ, okudinga ukuthi imilayezo ingene kwinethiwekhi yomphakathi kunalokho. Ama-DMZ amazinga amaningi anezingxenye eziningana zokusekela umlilo we-firewall angasethwa ukusekela amanethiwekhi amakhulu ezinkampani.