    Physical vs Virtual DMZ

    TheVMinator Master

      I am implementing the vCloud Suite of products in a multi-tenant environment, and currently do not yet have a DMZ.   In looking to define what the DMZ network will look like, should I assume I need one that is defined by physical separation of networks such as the following:

      ( Outside network <-> physical firewall <-> DMZ -<-> Physical Firewall <-> Internal Network)

      Is having a DMZ in a traditional design as above, with two physical firewalls on both sides, always recommended?

      Can I accomplish the same thing with vCNS and when  is it appropriate to define my DMZ in software vs hardware?