I'm considering showing 2 "<<device>> Firewalls" in my Deployment Diagram to represent what is "inside" the DMZ. Ex. Outer firewall -> Web Servers -> Inner Firewall -> Application Servers -> ... as opposed to a single firewall and just labeling the Web Servers as inside the DMZ. It clearly makes it more obvious with the first approach. However, it seems to me that you can set-up a DMZ with a single Router/Firewall in the "real world". I understand that this is just an assignment for the OCMJEA Part 2, so I would argue for clarity, however it should reflect reality (the whole point of a diagram). There is also a cost issue that doesn't seem to come up in the requirements, but does in the real world.
Your thoughts about how to depict this?