摘自Stackoverflow,To summarize - there are three "areas" - the big, bad outside world, your pure and virginal inside world, and the well known, trusted, safe DMZ.
The rules are:
Connections from outside can only get to hosts in the DMZ, and on specific ports (80, 443, etc);Connections from the outside to the inside are blocked absolutely;Connections from the inside to either the DMZ or the outside are fine and dandy;Only hosts in the DMZ may establish connections to the inside, and again, only on well known and permitted ports. DMZ区两种主流的设计架构: 单防火墙: 双防火墙:转载于:https://www.cnblogs.com/BlackWizard2016/p/5149977.html
相关资源:JAVA上百实例源码以及开源项目