For your on premises connectivity, define a Gateway Subnet For your internet connectivity, define a DMZ subnet  
Continue Reading