Lộ trình liên quan Related learning track Related learning track

Cloudflare One Cloudflare One Cloudflare One

Học lộ trình này Study this track Study this track

Kết nối user an toàn (remote & hybrid) Secure user connections (remote & hybrid) Secure user connections (remote & hybrid)

Users làm việc từ nhiều network, dùng SaaS tools, truy cập internal apps và duyệt Internet ngoài office perimeter. Users work from many networks, use SaaS tools, access internal apps, and browse the Internet outside the office perimeter. Users work from many networks, use SaaS tools, access internal apps, and browse the Internet outside the office perimeter.

Tài liệu Cloudflare (use case) → Official Cloudflare use case docs → Official Cloudflare use case docs →

Kiến trúc gợi ý Suggested architecture Suggested architecture

User/device → Cloudflare Zero Trust → SaaS/private app/Internet User/device → Cloudflare Zero Trust → SaaS/private app/Internet User/device → Cloudflare Zero Trust → SaaS/private app/Internet

Sơ đồ tham chiếu (Cloudflare Docs) Reference diagrams (Cloudflare Docs) Reference diagrams (Cloudflare Docs)

Tùy chọn triển khai Cloudflare One Appliance

Tùy chọn triển khai Cloudflare One Appliance Cloudflare One Appliance deployment options Cloudflare One Appliance deployment options

Cách triển khai Cloudflare One Appliance và đánh giá các lựa chọn: uplink H/A, dual connector, hybrid MPLS, split tunnel, segmentation. Learn how to deploy Cloudflare One Appliance and evaluate your various deployment options. Learn how to deploy Cloudflare One Appliance and evaluate your various deployment options.

Thuật ngữ: Concepts: Concepts: Cloudflare One Client · WARP · MDM · On-prem appliance

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE) Secure Access Service Edge (SASE)

Hình 1: Remote browser isolation can provide a secure, controlled browser environment for accessing sensitive company applications.

Zero Trust và hạ tầng desktop ảo (VDI) Zero Trust and Virtual Desktop Infrastructure Zero Trust and Virtual Desktop Infrastructure

Hướng dẫn dùng Zero Trust với VDI — cải thiện so với remote access web app truyền thống, bảo mật cao hơn. This document provides a reference and guidance for using Cloudflare's Zero Trust services. It offers a vast improvement over remote access to web applications with greater security. This document provides a reference and guidance for using Cloudflare's Zero Trust services. It offers a vast improvement over remote access to web applications with greater security.

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE) Secure Access Service Edge (SASE)

Controls & stack Controls & stack Controls & stack

  • Secure Web Gateway: kiểm soát web traffic theo policy Secure Web Gateway: policy-based web traffic control Secure Web Gateway: policy-based web traffic control
  • DNS filtering: chặn domain độc hại sớm DNS filtering: block malicious domains early DNS filtering: block malicious domains early
  • CASB: kiểm soát rủi ro SaaS CASB: manage SaaS risk CASB: manage SaaS risk
  • DLP: giảm rò rỉ dữ liệu DLP: reduce sensitive data leakage DLP: reduce sensitive data leakage
  • ZTNA: access private apps theo identity/device context ZTNA: identity/device-context access for private apps ZTNA: identity/device-context access for private apps
  • Email security: giảm phishing & malware qua email Email security: reduce phishing & email-borne malware Email security: reduce phishing & email-borne malware

Lỗi thường gặp Common mistakes Common mistakes

Chỉ bật SWG mà không có ZTNA cho app nội bộ SWG only without ZTNA for internal apps SWG only without ZTNA for internal apps

Remote user vẫn cần VPN nếu app private chưa publish qua Access. Kết hợp SWG + ZTNA theo use case. Remote users still need VPN if private apps are not published via Access. Combine SWG + ZTNA by use case. Remote users still need VPN if private apps are not published via Access. Combine SWG + ZTNA by use case.

Block quá aggressive gây false positive Over-aggressive blocking causing false positives Over-aggressive blocking causing false positives

DNS/HTTP policy chặn domain hợp pháp (CDN, update server) làm user không làm việc được. Pilot log-only trước. DNS/HTTP policies blocking legitimate domains (CDNs, update servers) block work. Pilot in log-only mode first. DNS/HTTP policies blocking legitimate domains (CDNs, update servers) block work. Pilot in log-only mode first.

Bỏ qua email security trong remote work Ignoring email security for remote work Ignoring email security for remote work

Phishing qua email vẫn là vector chính. Gateway email hoặc Area 1 bổ sung cho SWG browsing. Phishing via email remains a top vector. Add Gateway email or Area 1 alongside SWG browsing. Phishing via email remains a top vector. Add Gateway email or Area 1 alongside SWG browsing.

Tình huống khác (cùng lộ trình) Other scenarios (same track) Other scenarios (same track)

← Tất cả tình huống lộ trình này ← All scenarios in this track ← All scenarios in this track · Ba nhóm tình huống All three groups All three groups

Next step Next step Next step

Tiếp tục hành trình học của bạn. Continue your learning journey. Continue your learning journey.