Bảo mật Security សុវត្ថិភាព Cơ bản Entry កម្រិតចាប់ផ្តើម ~7 phút đọc · ~826 từ ~7 min read · ~707 words

Cloudflare Access: vào app nội bộ không cần VPN cũ — khởi đầu Zero Trust cho team nhỏ Cloudflare Access: reach internal apps without the old VPN — a gentle Zero Trust start Cloudflare Access: reach internal apps without the old VPN — a gentle Zero Trust start

Access giống bảo vệ từng cửa phòng thay vì mở khóa cả tòa nhà: nhân viên đăng nhập, đúng policy mới vào app admin — không cần “nằm trong mạng VPN” là thấy hết. Access is like guarding each room door instead of unlocking the whole building: staff sign in, policy allows the admin app — no “being on VPN” that exposes everything. Access is like guarding each room door instead of unlocking the whole building: staff sign in, policy allows the admin app — no “being on VPN” that exposes everything.

Hình 1: Chỉ traffic đã qua mạng Cloudflare và policy liên quan mới được phép vào ứng dụng SaaS.

Truy cập SaaS an toàn với SASE Secure access to SaaS applications with SASE Secure access to SaaS applications with SASE

Zero Trust cho SaaS: policy theo identity, device posture và network context qua Cloudflare One. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications.

Thuật ngữ: Concepts: Concepts: SASE · Gateway · Access · Device posture · SaaS

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE) Secure Access Service Edge (SASE)

VPN cũ giải quyết gì — và vì sao nhiều team muốn thay? What the old VPN solved — and why many teams want to replace it What the old VPN solved — and why many teams want to replace it

VPN truyền thống cho phép nhân viên “ở trong mạng công ty” từ xa: máy tính tạo đường hầm tới datacenter, rồi truy cập nội bộ như ngồi văn phòng. Cách này từng hợp lý khi hầu hết app nằm trong LAN và người làm việc chủ yếu tại chỗ. A traditional VPN lets staff “be on the company network” remotely: the laptop tunnels into the datacenter, then reaches internal apps as if at the office. That made sense when most apps lived on the LAN and people worked on-site. A traditional VPN lets staff “be on the company network” remotely: the laptop tunnels into the datacenter, then reaches internal apps as if at the office. That made sense when most apps lived on the LAN and people worked on-site.

Vấn đề hiện đại: một khi vào VPN, attacker có thể quét toàn mạng nội bộ; SaaS (Google, Notion, GitHub) không nằm trong VPN; và quản lý quyền theo “ở trong hay ngoài mạng” quá thô. Zero Trust (không tin mặc định) đảo ngược: mỗi ứng dụng kiểm tra ai bạn là, thiết bị có đủ điều kiện không, rồi mới cho vào — không mở cả tòa nhà. Modern problems: once on VPN, an attacker may scan the whole internal network; SaaS (Google, Notion, GitHub) is not inside the VPN; and “inside vs outside the network” is too coarse for permissions. Zero Trust flips the model: each application checks who you are and whether the device qualifies before access — without unlocking the whole building. Modern problems: once on VPN, an attacker may scan the whole internal network; SaaS (Google, Notion, GitHub) is not inside the VPN; and “inside vs outside the network” is too coarse for permissions. Zero Trust flips the model: each application checks who you are and whether the device qualifies before access — without unlocking the whole building.

Cloudflare Access là lớp ZTNA (Zero Trust Network Access) trên nền Cloudflare One. Trên blog.cloudflare.com, các bài về Access và Zero Trust thường mô tả pattern: người dùng xác thực qua IdP (Google, Microsoft, Okta…), policy quyết định app nào được phép, traffic đi qua Cloudflare thay vì mở port RDP/SSH ra Internet. Cloudflare Access is a ZTNA (Zero Trust Network Access) layer on Cloudflare One. Cloudflare Blog posts on Access and Zero Trust often describe the pattern: users authenticate via an IdP (Google, Microsoft, Okta…), policy decides which apps are allowed, and traffic flows through Cloudflare instead of exposing RDP/SSH ports to the Internet. Cloudflare Access is a ZTNA (Zero Trust Network Access) layer on Cloudflare One. Cloudflare Blog posts on Access and Zero Trust often describe the pattern: users authenticate via an IdP (Google, Microsoft, Okta…), policy decides which apps are allowed, and traffic flows through Cloudflare instead of exposing RDP/SSH ports to the Internet.

Hình 1: Chỉ traffic đã qua mạng Cloudflare và policy liên quan mới được phép vào ứng dụng SaaS.

Truy cập SaaS an toàn với SASE Secure access to SaaS applications with SASE Secure access to SaaS applications with SASE

Zero Trust cho SaaS: policy theo identity, device posture và network context qua Cloudflare One. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications.

Thuật ngữ: Concepts: Concepts: SASE · Gateway · Access · Device posture · SaaS

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE) Secure Access Service Edge (SASE)

Access hoạt động như thế nào (không cần biết hết acronym SASE) How Access works (without memorizing every SASE acronym) How Access works (without memorizing every SASE acronym)

Bạn đăng ký ứng dụng nội bộ với Access — ví dụ `admin.company.internal` hoặc self-hosted tool. Nhân viên mở URL, Access chuyển họ tới đăng nhập công ty (SSO). Sau khi xác thực, Access kiểm tra policy: nhóm nào được vào, có cần MFA không, thiết bị có WARP/posture đạt chuẩn không. Chỉ khi pass, request mới tới app phía sau — thường qua Cloudflare Tunnel, không cần mở firewall inbound. You register an internal app with Access — for example `admin.company.internal` or a self-hosted tool. Staff open the URL; Access sends them to company login (SSO). After authentication, Access checks policy: which groups may enter, whether MFA is required, whether device WARP/posture is compliant. Only then does the request reach the app behind — often via Cloudflare Tunnel, without opening inbound firewall holes. You register an internal app with Access — for example `admin.company.internal` or a self-hosted tool. Staff open the URL; Access sends them to company login (SSO). After authentication, Access checks policy: which groups may enter, whether MFA is required, whether device WARP/posture is compliant. Only then does the request reach the app behind — often via Cloudflare Tunnel, without opening inbound firewall holes.

Tunnel (đường hầm outbound) giống ống thoát một chiều từ server nội bộ ra Cloudflare: app không lộ IP public. Kết hợp Access + Tunnel là pattern phổ biến SME thay VPN cho vài app quan trọng (admin, Grafana, Jenkins) trước khi rollout toàn công ty. Tunnel is an outbound-only pipe from internal servers to Cloudflare: the app does not expose a public IP. Access + Tunnel is a common SME pattern to replace VPN for a few critical apps (admin, Grafana, Jenkins) before a company-wide rollout. Tunnel is an outbound-only pipe from internal servers to Cloudflare: the app does not expose a public IP. Access + Tunnel is a common SME pattern to replace VPN for a few critical apps (admin, Grafana, Jenkins) before a company-wide rollout.

Đừng nhầm Access với WAF website public: WAF bảo vệ site khách truy cập; Access bảo vệ app chỉ dành cho nhân viên/đối tác. Cả hai có thể cùng tồn tại trên một tài khoản Cloudflare — vai trò khác nhau. Do not confuse Access with a public website WAF: WAF protects customer-facing sites; Access protects employee/partner-only apps. Both can live on one Cloudflare account — different jobs. Do not confuse Access with a public website WAF: WAF protects customer-facing sites; Access protects employee/partner-only apps. Both can live on one Cloudflare account — different jobs.

Lợi ích dễ cảm nhận khi team nhỏ bắt đầu Zero Trust Easy-to-feel benefits when a small team starts Zero Trust Easy-to-feel benefits when a small team starts Zero Trust

Một: giảm “mở toàn mạng” — nhân viên nghỉ việc chỉ cần thu hồi quyền app/IdP, không lo họ vẫn nằm trong VPN. Hai: truy cập từng app trên trình duyệt, ít phần mềm VPN client nặng nề (tùy kiến trúc). Ba: log ai vào app nào, lúc nào — hữu ích audit và incident response. One: less “whole network access” — when someone leaves, revoke app/IdP access without worrying they are still on VPN. Two: per-app browser access, less heavy VPN client software (depending on architecture). Three: logs of who reached which app and when — helpful for audit and incident response. One: less “whole network access” — when someone leaves, revoke app/IdP access without worrying they are still on VPN. Two: per-app browser access, less heavy VPN client software (depending on architecture). Three: logs of who reached which app and when — helpful for audit and incident response.

Bốn: không expose port quản trị ra Internet — giảm bề mặt tấn công brute force. Năm: nền tảng mở rộng sang Gateway (lọc web), CASB (SaaS), DLP khi công ty lớn hơn — bạn không phải đổi hướng hoàn toàn. Four: no exposed admin ports on the Internet — smaller brute-force surface. Five: the platform grows into Gateway (web filtering), CASB (SaaS), and DLP as the company scales — without a full rip-and-replace. Four: no exposed admin ports on the Internet — smaller brute-force surface. Five: the platform grows into Gateway (web filtering), CASB (SaaS), and DLP as the company scales — without a full rip-and-replace.

Hub này có lộ trình Cloudflare One và use case thay VPN. Nếu bạn đã đọc bài WAF/CDN, hãy coi Access là “cánh cửa nội bộ” trong cùng hệ sinh thái bảo mật — không phải sản phẩm lạ tách rời. This hub has a Cloudflare One track and a replace-VPN use case. If you have read the WAF/CDN posts, treat Access as the “internal door” in the same security ecosystem — not a disconnected product. This hub has a Cloudflare One track and a replace-VPN use case. If you have read the WAF/CDN posts, treat Access as the “internal door” in the same security ecosystem — not a disconnected product.

Khởi đầu an toàn: ba bước trong tuần đầu A safe start: three steps in the first week A safe start: three steps in the first week

Bước 1: chọn một app ít rủi ro nhưng hữu ích (dashboard nội bộ, wiki) — không bắt đầu bằng database production. Bước 2: kết nối IdP công ty (Google Workspace/Microsoft 365) và bật MFA cho nhóm admin. Bước 3: triển khai Tunnel từ server nội bộ, gắn Access policy “chỉ email @company.com”. Step 1: pick one low-risk but useful app (internal dashboard, wiki) — do not start with the production database. Step 2: connect company IdP (Google Workspace/Microsoft 365) and enable MFA for admin groups. Step 3: deploy Tunnel from the internal server and attach an Access policy like “only @company.com email.” Step 1: pick one low-risk but useful app (internal dashboard, wiki) — do not start with the production database. Step 2: connect company IdP (Google Workspace/Microsoft 365) and enable MFA for admin groups. Step 3: deploy Tunnel from the internal server and attach an Access policy like “only @company.com email.”

Test với vài người dùng thật trước khi tắt VPN cho app đó. Chuẩn bị runbook: IdP down thì làm gì, ai có break-glass account. Đọc trang Zero Trust và Access trên hub; mở bài gốc blog.cloudflare.com khi cần chi tiết device posture hoặc SaaS integration. Test with real users before turning off VPN for that app. Prepare a runbook: what if IdP is down, who has break-glass accounts. Read the Zero Trust and Access pages on this hub; open original blog.cloudflare.com posts when you need device posture or SaaS integration detail. Test with real users before turning off VPN for that app. Prepare a runbook: what if IdP is down, who has break-glass accounts. Read the Zero Trust and Access pages on this hub; open original blog.cloudflare.com posts when you need device posture or SaaS integration detail.

Câu hỏi tự kiểm tra: “Nếu laptop nhân viên bị đánh cắp khi đã đăng nhập, attacker vào được những app nào?” Nếu câu trả lời là “quá nhiều”, thu hẹp policy và bật session timeout/MFA step-up cho app nhạy cảm. Self-check: “If an employee laptop is stolen while logged in, which apps can an attacker reach?” If the answer is “too many,” tighten policy and add session timeout/MFA step-up for sensitive apps. Self-check: “If an employee laptop is stolen while logged in, which apps can an attacker reach?” If the answer is “too many,” tighten policy and add session timeout/MFA step-up for sensitive apps.

Hình minh họa Cloudflare Cloudflare visuals Cloudflare visuals

Sơ đồ Reference Architecture chính thức và (khi có) ảnh Dashboard — giúp đối chiếu khi học. Official Reference Architecture diagrams and (when available) Dashboard screenshots — useful while you learn. Official Reference Architecture diagrams and (when available) Dashboard screenshots — useful while you learn.

Hình 1: Request tới tài nguyên nội bộ và chỗ Access tùy biến AuthZ / AuthN

Mở rộng ZTNA bằng ủy quyền ngoài và serverless Extend ZTNA with external authorization and serverless computing Extend ZTNA with external authorization and serverless computing

ZTNA tăng cường policy Access bằng gọi API ngoài và Workers — xác thực và ủy quyền user trước khi vào tài nguyên được bảo vệ. Cloudflare's ZTNA enhances access policies using external API calls and Workers for robust security. It verifies user authentication and authorization, ensuring only legitimate access to protected resources. Cloudflare's ZTNA enhances access policies using external API calls and Workers for robust security. It verifies user authentication and authorization, ensuring only legitimate access to protected resources.

Thuật ngữ: Concepts: Concepts: Access · External Evaluation · Workers · ZTNA

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE) Secure Access Service Edge (SASE)

Câu hỏi thường gặp Frequently asked questions Frequently asked questions

Access có thay hoàn toàn VPN không? Can Access fully replace VPN? Can Access fully replace VPN?

Nhiều team thay dần VPN cho truy cập app/web. Một số workload (legacy LAN, in-office printer) có thể vẫn cần VPN hoặc mạng riêng. Lộ trình phổ biến: ZTNA cho app trước, VPN thu hẹp sau. Many teams gradually replace VPN for app/web access. Some workloads (legacy LAN, office printers) may still need VPN or private network. A common path: ZTNA for apps first, shrink VPN later. Many teams gradually replace VPN for app/web access. Some workloads (legacy LAN, office printers) may still need VPN or private network. A common path: ZTNA for apps first, shrink VPN later.

Access khác WAF thế nào? How is Access different from a WAF? How is Access different from a WAF?

WAF bảo vệ website/API public khỏi tấn công web. Access kiểm soát ai được vào ứng dụng riêng (thường nội bộ) qua identity và policy. Cả hai bổ sung nhau. A WAF protects public websites/APIs from web attacks. Access controls who may reach private apps (usually internal) via identity and policy. They complement each other. A WAF protects public websites/APIs from web attacks. Access controls who may reach private apps (usually internal) via identity and policy. They complement each other.

Cần WARP trên máy nhân viên không? Do employees need WARP on their devices? Do employees need WARP on their devices?

Tùy policy. Nhiều triển khai Access chỉ cần trình duyệt + SSO. WARP/device posture hữu ích khi bạn yêu cầu thiết bị đạt chuẩn trước khi vào app nhạy cảm — xem docs Cloudflare One cho chi tiết. Depends on policy. Many Access deployments need only browser + SSO. WARP/device posture helps when you require compliant devices before sensitive apps — see Cloudflare One docs for detail. Depends on policy. Many Access deployments need only browser + SSO. WARP/device posture helps when you require compliant devices before sensitive apps — see Cloudflare One docs for detail.

Học tiếp trên hub (on-page backlinks) Keep learning on this hub (on-page links) Keep learning on this hub (on-page links)

Nguồn tham khảo (blog.cloudflare.com) Sources (blog.cloudflare.com) Sources (blog.cloudflare.com)

Nội dung được viết lại để dễ hiểu hơn; luôn đọc bài gốc trên blog.cloudflare.com và docs chính thức khi cần chi tiết kỹ thuật hoặc cập nhật mới nhất. Content is rewritten for clarity; always read the original posts on blog.cloudflare.com and official docs for technical detail or the latest updates. Content is rewritten for clarity; always read the original posts on blog.cloudflare.com and official docs for technical detail or the latest updates.

What is a WAF? Cloudflare website protection explained for non-specialists
Bảo mật Security សុវត្ថិភាព Cơ bản Entry កម្រិតចាប់ផ្តើម ~7 phút ~7 min ~7 នាទី

WAF là gì? Bảo vệ website Cloudflare theo cách người không chuyên IT cũng hiểu What is a WAF? Cloudflare website protection explained for non-specialists What is a WAF? Cloudflare website protection explained for non-specialists

WAF giống bảo vệ cửa ra vào của website: xem ai đang gõ cửa, chặn hành vi đáng ngờ, rồi mới cho vào bên trong (origin). A WAF is like a doorman for your website: it checks who is knocking, blocks suspicious behavior, then lets safe traffic through to your origin. A WAF is like a doorman for your website: it checks who is knocking, blocks suspicious behavior, then lets safe traffic through to your origin.

Đọc bài → Read post → អានអត្ថបទ →

What is a CDN? Understanding Cloudflare Cache in plain language
CDN CDN CDN Cơ bản Entry កម្រិតចាប់ផ្តើម ~6 phút ~6 min ~6 នាទី

CDN là gì? Hiểu Cloudflare Cache như đang giải thích cho bạn bè What is a CDN? Understanding Cloudflare Cache in plain language What is a CDN? Understanding Cloudflare Cache in plain language

CDN giống mạng kho hàng gần người dùng. Cloudflare Cache giữ bản sao nội dung tĩnh gần bạn — trang mở nhanh hơn, server gốc đỡ “mệt”. Think of a CDN as warehouses near your users. Cloudflare Cache keeps copies of static content close by — pages load faster and origin servers work less. Think of a CDN as warehouses near your users. Cloudflare Cache keeps copies of static content close by — pages load faster and origin servers work less.

Đọc bài → Read post → អានអត្ថបទ →

Cloudflare Developer Platform: build global apps without managing servers yourself
Developer Platform Developer Platform Developer Platform Trung cấp Intermediate កម្រិតមធ្យម ~9 phút ~9 min ~9 នាទី

Cloudflare Developer Platform: xây ứng dụng toàn cầu mà không tự quản lý server Cloudflare Developer Platform: build global apps without managing servers yourself Cloudflare Developer Platform: build global apps without managing servers yourself

Developer Platform giống bộ lego edge: compute (Workers), hộp đựng (R2/KV/D1), AI, và lớp bảo vệ — lắp theo use case thay vì mua cả trung tâm dữ liệu. The Developer Platform is like an edge Lego set: compute (Workers), storage boxes (R2/KV/D1), AI, and protection layers — assemble by use case instead of buying a whole data center. The Developer Platform is like an edge Lego set: compute (Workers), storage boxes (R2/KV/D1), AI, and protection layers — assemble by use case instead of buying a whole data center.

Đọc bài → Read post → អានអត្ថបទ →

Xem tất cả bài blog Browse all blog posts Browse all blog posts

Chuỗi bài AI · Security · CDN · Workers · Developer Platform — viết lại cho người mới và trung cấp. AI · Security · CDN · Workers · Developer Platform — rewritten for entry and intermediate learners. AI · Security · CDN · Workers · Developer Platform — rewritten for entry and intermediate learners.