advanced·20 min·Paid

Web Tier Bypasses App Tier

Security review finds the web servers can talk directly to the database — they shouldn't be able to

Scenario

The customer-facing application is built in three tiers, each on its own subnet: a web tier that talks to the public Internet, an application tier that the web tier talks to for business logic, and a database tier that only the application tier is supposed to reach. A routine security review found that web-tier servers can connect directly to the database tier, completely bypassing the application tier — a serious defense-in-depth violation, since a compromised web server should never be able to touch the database directly.

Learning objectives

  • acl
  • nftables
  • least privilege

Topology and configuration

This environment contains 4 devices (3 Hosts, 1 Router). You configure and troubleshoot the networking skills listed above.

Curriculum topics

subnetica© 2026 · Learn, practice, retain.
AboutFAQPrivacy PolicyTerms & Acceptable UseAccessibilitycontact@subneti.ca
CCNA is a registered trademark of Cisco Systems, Inc. CompTIA Network+ and CompTIA Security+ are registered trademarks of CompTIA, Inc. Subnetica is an independent learning platform and is not affiliated with, endorsed by, or sponsored by Cisco Systems, Inc. or CompTIA, Inc.