The network is divided into three main zones:
- WAF (Web Application Firewall)
- Public-facing Web Server
- Segregated from the internal network using firewall rules
- Directory Server (authentication)
- File Server (internal storage)
- Only partially reachable from the DMZ
- Database Server
- FTP Server (secured)
- Only reachable from internal services
- Strongest segmentation policies
- Firewall protecting external perimeter
- WAF filtering malicious HTTP/S traffic
- Network Segmentation into DMZ / Internal / Restricted
- Least Privilege flow (DMZ β Internal β Restricted)
- SIEM for log collection and monitoring
- No direct access from Internet or DMZ to the Restricted Area
- Separation of duties between servers
Internet β Firewall β WAF β Web Server β Internal Network β Restricted Area β SIEM