在构建 n 层应用程序时是否必须考虑防火墙?

发布于 2024-08-24 05:00:46 字数 85 浏览 2 评论 0原文

在构建任何 n 层 Intranet 应用程序时,我是否必须考虑有关组织中的防火墙的任何事情?是否有任何特殊的考虑因素需要主动解决,或者可能是事后才想到的。

While architecting any n-tier intranet applications, do I have to consider anything about firewalls in the organization? Are there any special considerations which needs to be proactively addressed or it could be an afterthought.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(3

晨光如昨 2024-08-31 05:00:46

如果您的设计方式是防火墙位于各层之间,那么这绝对是一个考虑因素。

话虽这么说,这应该只是配置防火墙以允许服务之间进行通信的问题,但在实施之前(而不是实施之后)与维护硬件的 IT 人员协作将是一件好事......

If you're designing in a way that the firewalls will sit between your tiers, this is definitely a consideration.

That being said, it should just be a matter of configuring your firewall to allow communication between your services, but collaboration with the IT staff maintaining the hardware would be a good thing to do prior to implementation, instead of after implementation...

寄与心 2024-08-31 05:00:46

如果您跨越不同的子网,那么是的,您应该考虑防火墙,因为将来用户可能希望通过 VPN(虚拟专用网络 - 这将具有安全性)远程访问系统,就像“在家工作”一样因数据包通过 WAN 进行加密而被切断)...请与负责和维护防火墙的 IT 人员保持联系,以尽量减少日后可能造成高昂代价的麻烦!

这并不是说,立即执行,而是以某种方式使其足够灵活,以便系统在不久的将来能够跨防火墙工作......您将获得不错的奖金,让老板高兴,最重要的是让用户高兴!

希望这有帮助,
此致,
汤姆.

If you are crossing different subnets, then yes, you should consider the firewall, as maybe in the future a user would want to access the system remotely a la 'working from home' via VPN (Virtual Private Network - that would have the security aspect cut out as packets are encrypted over the WAN)...keep touching base with the IT Personnel who look after and maintain the firewall in order to minimize headaches later on which could be costly!

That is not to say, do it immediately, but somehow make it flexible enough for the system to work over the firewall in the near future...you'll get a nice bonus and make the bosses happy and above all, the user!

Hope this helps,
Best regards,
Tom.

笔芯 2024-08-31 05:00:46

另一个考虑因素是防火墙可能会做一些意想不到的“聪明”事情,例如关闭长期存在的 TCP 连接。

此类问题往往在构建的后期突然出现,因为开发和测试环境很少复制最终环境的精确网络配置。

因此,是的,计划尽快使用尽可能接近“真实”的配置进行测试,包括防火墙。

Another consideration is that firewalls can do unintended 'clever' things like closing long-lived TCP connections.

Such issues tend to crop up very late in the build, as development and test environments rarely replicate the exact network configuration of the final environment.

So, yes, plan to test with as close to the 'real' configuration as soon as possible, including firewalls.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文