Then packets coming in via the 'inside' interface are permitted - this allows hosts on the 'inside' network to establish connections to anywhere, including the Internet and the DMZ. Then any packets coming in via the 'dmz' interface are permitted as long as the router is going to send them out the 'outside' interface - this allows the DMZ hosts to access the Internet, but keeps them out of the 'in