advanced·20 min·Paid

Web Tier Bypasses App Tier

Security review finds the web servers can talk directly to the database — they shouldn't be able to

Scenario

The customer-facing application is built in three tiers, each on its own subnet: a web tier that talks to the public Internet, an application tier that the web tier talks to for business logic, and a database tier that only the application tier is supposed to reach. A routine security review found that web-tier servers can connect directly to the database tier, completely bypassing the application tier — a serious defense-in-depth violation, since a compromised web server should never be able to touch the database directly.

Learning objectives

  • acl
  • nftables
  • least privilege

Topology and configuration

This environment contains 4 devices (3 Hosts, 1 Router). You configure and troubleshoot the networking skills listed above.

Curriculum topics

Environment

Subnetica labs run FRRouting and Linux networking with Cisco-like syntax, not Cisco IOS. Commands and behavior may differ from Cisco devices.

Addressing is regenerated on every attempt and the environment is graded automatically.

Ready to practice?

Sign in or create an account before launching this lab. Viewing this preview never starts or reserves infrastructure.

subnetica© 2026 · Learn, practice, retain.
CCNA is a registered trademark of Cisco Systems, Inc. CompTIA Network+ and CompTIA Security+ are registered trademarks of CompTIA, Inc. Subnetica is an independent learning platform and is not affiliated with, endorsed by, or sponsored by Cisco Systems, Inc. or CompTIA, Inc.