Thank all of you for the replies, i have now a good understanding of the subject but before proceed into building the dmz subnet i need to ask something : My ISP assigns me a dynamic ip , therefore, is that a limitation that could not allow me to develop the dmz subnet ? Is that correct or inacurrate ? Visitors shall need to type my ip to access my webpage, but what im interesting is the development of the firewall itselfin terms of securing a network . It will never be used for real casesit is just for me to understand. the script that i have suggesetd uses static ip # 1.1 Internet Configuration. # INET_IP="194.236.50.152" HTTP_IP="194.236.50.153" DNS_IP="194.236.50.154" INET_IFACE="eth0" So, Can i develop dmz subnet without static ip and dmz'ed services to be accessed on the Internet? Regards