This document provides guidance on creating a DMZ (demilitarized zone) network on a pfSense firewall. It discusses what a DMZ is, considerations for designing a DMZ like whether to use public or private IP addresses. It also covers steps to set up a DMZ interface on pfSense, configure services and firewall rules to isolate and protect the DMZ network, and considerations for VPN and other network traffic. The overall goal is to add an additional layer of security by housing public servers in a separate DMZ network, isolated from internal private networks.