advanced·20 min·付费

Web Tier Bypasses App Tier

Security review finds the web servers can talk directly to the database — they shouldn't be able to

场景

The customer-facing application is built in three tiers, each on its own subnet: a web tier that talks to the public Internet, an application tier that the web tier talks to for business logic, and a database tier that only the application tier is supposed to reach. A routine security review found that web-tier servers can connect directly to the database tier, completely bypassing the application tier — a serious defense-in-depth violation, since a compromised web server should never be able to touch the database directly.

学习目标

  • acl
  • nftables
  • least privilege

拓扑与配置

此环境包含 4 台设备(3 Hosts, 1 Router)。你将配置并排查上方列出的网络技能。

课程主题

subnetica© 2026 · 学习,练习,掌握。
关于我们常见问题隐私政策条款与可接受使用政策无障碍声明contact@subneti.ca
CCNA 是 Cisco Systems, Inc. 的注册商标。CompTIA Network+ 和 CompTIA Security+ 是 CompTIA, Inc. 的注册商标。Subnetica 是一个独立的学习平台,与 Cisco Systems, Inc. 或 CompTIA, Inc. 没有任何关联,也未获得其认可或赞助。