advanced·20 min·Payant

Web Tier Bypasses App Tier

Security review finds the web servers can talk directly to the database — they shouldn't be able to

Scénario

The customer-facing application is built in three tiers, each on its own subnet: a web tier that talks to the public Internet, an application tier that the web tier talks to for business logic, and a database tier that only the application tier is supposed to reach. A routine security review found that web-tier servers can connect directly to the database tier, completely bypassing the application tier — a serious defense-in-depth violation, since a compromised web server should never be able to touch the database directly.

Objectifs d'apprentissage

  • acl
  • nftables
  • least privilege

Topologie et configuration

Cet environnement contient 4 appareils (3 Hosts, 1 Router). Vous configurez et dépannez les compétences réseau listées ci-dessus.

Sujets du programme

subnetica© 2026 · Apprenez, pratiquez, retenez.
À proposFAQPolitique de confidentialitéConditions générales et utilisation acceptableAccessibilitécontact@subneti.ca
CCNA est une marque déposée de Cisco Systems, Inc. CompTIA Network+ et CompTIA Security+ sont des marques déposées de CompTIA, Inc. Subnetica est une plateforme d'apprentissage indépendante et n'est affiliée à, approuvée par, ni parrainée par Cisco Systems, Inc. ou CompTIA, Inc.