I am trying to plan where to place the SDP server. I need to have internal and external access to SDP. We also use AD and want SDP to link to it. We have a security rule that nothing in the DMZ can initiate a connection into the production network (such as a sync to AD), but the reverse is ok.