Serv-U Gateway operates in the DMZ and uses a dual-channel architecture: a Gateway Connection Channel for control and Gateway Data Channels for individual client sessions. The internal Serv-U server initiates all connections to the gateway, meaning no inbound connections penetrate from the DMZ to the private network. Authentication and authorization occur on the internal server, and no data is stored in the DMZ zone.