目标网络访问架构
graph LR
subgraph "用户端"
USER[用户]
ADMIN[管理员]
VPN_USER[VPN用户]
end
subgraph "安全边界"
WAF[Web应用防火墙]
end
subgraph "DMZ区域"
BASTION[堡垒机]
VPN_GW[VPN网关]
DNS_SERVER[Private DNS]
end
subgraph "应用层"
WEB[Web服务器]
APP[应用服务器]
LOG[日志服务器]
MONITOR[监控服务器]
end
subgraph "数据层"
DB[数据库]
CACHE[缓存]
STORAGE[存储]
end
USER --> WAF
ADMIN --> VPN_GW
VPN_USER --> VPN_GW
WAF --> WEB
VPN_GW --> BASTION
BASTION --> DNS_SERVER
BASTION --> WEB
VPN_GW --> WEB
WEB --> APP
APP --> DB
APP --> CACHE
APP --> STORAGE
WEB --> LOG
APP --> LOG
DB --> LOG
WEB --> MONITOR
APP --> MONITOR
DB --> MONITOR
CACHE --> MONITOR
classDef userClass fill:#e1f5fe,stroke:#01579b,stroke-width:2px
classDef securityClass fill:#fff3e0,stroke:#e65100,stroke-width:2px
classDef dmzClass fill:#f3e5f5,stroke:#4a148c,stroke-width:2px
classDef appClass fill:#e8f5e8,stroke:#2e7d32,stroke-width:2px
classDef dataClass fill:#fce4ec,stroke:#c2185b,stroke-width:2px
class USER,ADMIN,VPN_USER userClass
class WAF securityClass
class BASTION,VPN_GW,DNS_SERVER dmzClass
class WEB,APP,LOG,MONITOR appClass
class DB,CACHE,STORAGE dataClass
- WAF → Web服务器:HTTP/HTTPS (80/443)
- VPN网关 → Web服务器:HTTP/HTTPS (80/443)
- 堡垒机 → Web服务器:SSH (22)
- 安全防护:WAF 应用防火墙
- 网络隔离:DMZ区域 + 应用层 + 数据层
- 访问控制:VPN网关 + 堡垒机
- 加密传输:HTTPS/TLS + VPN加密