I think that the network between internal router and bastion should also be called DMZ as the internal environment from your own users can be just as hostile as the external one. Lyndon