
π Cybersecurity Β· Network
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
Drawing diagramβ¦
DMZ network architecture: internet traffic passes a DDoS protection service and an outer firewall/WAF into the DMZ, which holds the reverse proxy/load balancer, mail relay and VPN gateway. An inner firewall allows only specific ports from the DMZ to the internal app servers; databases are in a restricted data zone behind another firewall rule set. Administrators reach servers only through a bastion host with MFA; the office LAN reaches internal apps.
flowchart LR
NET((Internet)) --> DDOS[DDoS Protection]
DDOS --> FW1{{Outer Firewall + WAF}}
subgraph DMZ[DMZ]
RP[Reverse Proxy / Load Balancer]
MAIL[Mail Relay]
VPN[VPN Gateway]
end
FW1 --> RP
FW1 --> MAIL
FW1 --> VPN
RP --> FW2{{Inner Firewall}}
VPN --> FW2
subgraph INT[Internal Zone]
APP[App Servers]
BAST[Bastion Host - MFA]
end
subgraph DATA[Restricted Data Zone]
DB[(Databases)]
end
FW2 --> APP
FW2 --> BAST
APP --> FW3{{Data Firewall}} --> DB
BAST --> APP
LAN[Office LAN] --> FW2A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.
The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.