Phần 1: Chuẩn bị Zero Trust Part 1: Zero Trust preparation · Bài 2/2 Lesson 2/2

Danh sách ứng dụng: SaaS và private App inventory: SaaS and private

Ví dụ: Jira, Notion, internal admin, SSH bastion. Ưu tiên 1 app ít rủi ro cho pilot (internal wiki, staging). Examples: Jira, Notion, internal admin, SSH bastion. Pick one low-risk app for pilot (internal wiki, staging).

App inventory: SaaS and private
Minh họa từ Cloudflare Reference Architecture (developers.cloudflare.com) Illustration from Cloudflare Reference Architecture (developers.cloudflare.com)

Các bước thực hiện Step-by-step

  1. Inventory SaaS (Notion, Jira) và private app (admin, SSH). Inventory SaaS (Notion, Jira) and private apps (admin, SSH).
  2. Chọn 1 app ít rủi ro cho pilot (wiki staging). Pick one low-risk app for pilot (staging wiki).
  3. Ghi hostname/IP và protocol (HTTP, SSH, RDP). Record hostname/IP and protocol (HTTP, SSH, RDP).
  4. Xác định ai trong pilot group được truy cập. Define who in the pilot group may access.

Giải thích chi tiết Detailed explanation

Pilot nhỏ giúp học policy và rollback — tránh rollout VPN replacement big-bang. A small pilot teaches policy and rollback — avoid big-bang VPN replacement rollouts.

Lưu ý (best practices) Note (best practices)

App nội bộ có nhiều service phụ thuộc (iframe, embedded) — cân nhắc khai báo nhiều top-level domain trong một Access application thay vì tách rời. Internal apps with interdependent services (iFrames, embedded systems) — consider specifying multiple top-level domains in a single Access application.

Nguồn: Source: Access application — Best practices Access application — Best practices

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Tutorial, solution guide và reference từ developers.cloudflare.com/resources ↗ — gợi ý theo chủ đề bài học. Tutorials, solution guides, and reference docs from developers.cloudflare.com/resources ↗ — matched to this lesson topic.

Sơ đồ kiến trúc Reference architecture diagram Cloudflare One Cloudflare One

Deploy self-hosted VoIP services for hybrid users

/reference-architecture/diagrams/sase/deploying-self-hosted-voip-services-for-hybrid-users

Mở tutorial / guide ↗ Open tutorial / guide ↗
Sơ đồ kiến trúc Reference architecture diagram Cloudflare One Cloudflare One

Secure access to SaaS applications with SASE

/reference-architecture/diagrams/sase/secure-access-to-saas-applications-with-sase

Mở tutorial / guide ↗ Open tutorial / guide ↗

Duyệt toàn bộ catalog → Browse full catalog →

Tài liệu Cloudflare Developers Cloudflare Developer docs

Sơ đồ kiến trúc (Cloudflare Docs) Architecture diagrams (Cloudflare Docs)

Figure 1: Only traffic that has passed the Cloudflare network and relevant policies is authorized to access the SaaS application.

Secure access to SaaS applications with SASE Secure access to SaaS applications with SASE

Zero Trust cho SaaS: policy theo identity, device posture và network context qua Cloudflare One. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications.

Thuật ngữ: Concepts: SASE · Gateway · Access · Device posture · SaaS

Sơ đồ chính thức ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE)

Sản phẩm liên quan Related products

Đọc thêm trong hub → Read more in the hub →