If you meant that your CSS is not protected by the Firewall, then you are right to want to lock it down as much as possible. Using the physical management interface on a SEPARATE (out of band) LAN connection which in turn is only accessable from firewalled connection inside of DMZ would be appropriate.
Learn, share, save
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.