Ekuxhumaneni kwenethiwekhi, i-De-Militarized Zone (DMZ) iyimishini ekhethekile yendawo yenethiwekhi eyenzelwe ukuthuthukisa ukuphepha ngokuhlukanisa amakhompyutha ohlangothini ngalunye lwe- firewall . I-DMZ ingahle ibekwe kumanethiwekhi wekhaya noma amabhizinisi, nakuba usizo lwabo emakhaya lilinganiselwe.
Uphi i-DMZ Ewusizo?
Enethiwekhi yekhaya, amakhompiyutha namanye amadivaysi ajwayele ukufakwa kunethiwekhi yendawo yendawo (i-LAN) exhunywe kwi-intanethi nge- router broadband . I-router isebenza njenge-firewall, ihlunga ngokukhetha i-traffic kusuka ngaphandle ukuze isize ukuqinisekisa ukuthi imilayezo evumelekile idlula. I-DMZ ihlukanisa ukwahlukana kwenethiwekhi enjalo ibe yizingxenye ezimbili ngokuthatha amadivaysi owodwa noma ngaphezulu ngaphakathi kwe-firewall futhi ibathuthela ngaphandle. Lokhu kulungiselelwa kangcono kuvikela amadivayisi angaphakathi kusuka ekuhlaselweni okungenzeka ngaphandle (futhi ngokuphambene nalokho).
I-DMZ iyasiza emakhaya lapho inethiwekhi isebenza iseva . Iseva ingahle ibekwe ku-DMZ ukuze abasebenzisi be-intanethi bakwazi ukuyifinyelela ngekheli layo le-IP lomphakathi , futhi yonke inethiwekhi yekhaya ivikelwe ekuhlaselweni lapho kwenzeka khona iseva. Eminyakeni edlule, ngaphambi kokuba amasevisi wefu atholakale futhi athandwa kakhulu, abantu bavame ukugijimela iWebhu, i- VoIP noma amaseva wefayela kusuka emakhaya abo kanye nama-DMZ enza umqondo ozwakalayo.
Ngakolunye uhlangothi, amanethiwekhi wekhompiyutha yebhizinisi , angasebenzisa ngokujwayelekile ukusebenzisa i-DMZs ukusiza ukuphatha iWebhu yezinkampani kanye namanye amaseva abheke umphakathi. Amanethiwekhi asekhaya namuhla avame ukuzuza ngokuhlukahluka kwe-DMZ ebizwa ngokuthi i-DMZ hosting (bheka ngezansi).
Ukusekela kwe-DMZ Host Host in Broadband Routers
Ulwazi mayelana nama-DMZ enethiwekhi lungadanisa ukuqonda ekuqaleni ngoba leli gama libhekisela ezinhlotsheni ezimbili zokulungiselela. Isici esiphezulu se- DMZ se-home routers asisunguli i-subnetwork ephelele ye-DMZ kodwa kunalokho iveza idivayisi eyodwa kwinethiwekhi yendawo ekhona ukusebenza ngaphandle kwe-firewall ngenkathi yonke inethiwekhi isebenza njengesijwayelekile.
Ukuze ulungise ukusekelwa kwe-DMZ kumsingathi kunethiwekhi yekhaya, ngena ngemvume ku-console router uphinde unike amandla inketho ye-DMZ yesitoreji ekhutshaziwe ngokuzenzakalelayo. Faka ikheli le-IP langasese ledivaysi yendawo ekhethwe njengomphathi. I-Xbox noma i-PlayStation game consoles ivame ukukhethwa njengezinsizakalo ze-DMZ ukuvimbela i-firewall yasekhaya ukuphazamisa ukugembula kwe-intanethi. Qinisekisa ukuthi umninikhaya usebenzisa ikheli le-IP eliyisimo (kunokuba asebenze ngokuzenzekelayo), ngaphandle kwalokho, idivaysi ehlukile ingase izuze ikheli le-IP elikhethiwe bese liba ngummemezeli we-DMZ esikhundleni.
Ukwesekwa kweqiniso kwe-DMZ
Ngokuphambene nokusingathwa kwe-DMZ, i-DMZ yangempela (ngezinye izikhathi ebizwa ngokuthi i-DMZ yokuthengisa) isungula i-subnetwork entsha ngaphandle kwe-firewall lapho i-computer eyodwa noma ngaphezulu isebenza khona. Lezo amakhompiyutha ngaphandle zifaka ungqimba olwengeziwe lokuvikela amakhompyutha ngemuva kwe-firewall njengoba zonke izicelo ezingenayo zitholwa futhi kumele kuqala zidlule kwi-computer ye-DMZ ngaphambi kokufinyelela ku-firewall. Ama-DMZ eqiniso nawo avimbela amakhompyutha ngemuva kwe-firewall ekukhulumisaneni ngqo namadivaysi e-DMZ, okudinga ukuthi imilayezo ingene kwinethiwekhi yomphakathi kunalokho. Ama-DMZ amazinga amaningi anezingxenye eziningana zokusekela umlilo we-firewall angasethwa ukusekela amanethiwekhi amakhulu ezinkampani.