In order for the Edge to be a proxy and protect the internal infrastructure, two interfaces are required. The first interface will be exposed to the Internet or DMZ with the second interface exposed to the internal network. If both interfaces are on the same network segment (i.e. gateway) the edge separation is eliminated.