Hi Sascha, Your first impression is correct. Put the external interface in the DMZ and the internal interface on the internal LAN. It works like a charm and even though the Juniper box is hardened, it also gains the benefit of your Internet firewall helping to protect it. We also have an IPS protecting our devices in the DMZ, so if you are using any type of IPS/IDS, the IPS would sit between your DMZ port on the firewall and the Juniper external interface. Hope this helps, Roy Kestler
... View more