You're missing the point. There is no internal network in this new model.
So as I said previously, for most organizations, it would be crazy to the point of lunacy of their infosec team to allow the internet access to internal corporate systems and just rely on those to have been individually secured.
I would dare to say that nobody does this or I'll ask you to please give me the IP address of Google's internal DVCS server.