Web Tier Bypasses App Tier
Security review finds the web servers can talk directly to the database — they shouldn't be able to
Scenario
The customer-facing application is built in three tiers, each on its own subnet: a web tier that talks to the public Internet, an application tier that the web tier talks to for business logic, and a database tier that only the application tier is supposed to reach. A routine security review found that web-tier servers can connect directly to the database tier, completely bypassing the application tier — a serious defense-in-depth violation, since a compromised web server should never be able to touch the database directly.
Learning objectives
- acl
- nftables
- least privilege
Topology and configuration
This environment contains 4 devices (3 Hosts, 1 Router). You configure and troubleshoot the networking skills listed above.
Curriculum topics
Environment
Subnetica labs run FRRouting and Linux networking with Cisco-like syntax, not Cisco IOS. Commands and behavior may differ from Cisco devices.
Addressing is regenerated on every attempt and the environment is graded automatically.
Ready to practice?
Sign in or create an account before launching this lab. Viewing this preview never starts or reserves infrastructure.
