The DMZ is the “buffer” between these two networks, reducing the likelihood of direct interaction between the enterprise network (or the Internet) and the industrial network. Physically, the DMZ might be implemented using a separate VLAN or isolated network segment, managed by industrial routers and firewalls.