RuleTrafficPolicyResult
WAN PERIMETER
Inbound — WAN
Any → Public IP
No open ports at WAN. All traffic handled by Cloudflare edge. Origin IP not advertised.
Enforced
Admin panel
Any → /ghost/
Cloudflare Access — Zero Trust. Email authentication required before request reaches origin.
Enforced
DMZ SEGMENT
DMZ → RFC1918
Outbound
Block all private address space. No lateral movement path from public-facing segment to internal network.
Enforced
DMZ → Internet
Outbound
Permit HTTPS (443), HTTP (80), DNS (53) to specific destinations only. All other outbound denied.
Enforced
DMZ host firewall
Host-level
UFW active on web server. Permits only SSH from management segment and tunnel process. Default deny.
Enforced
MANAGEMENT ACCESS
Admin → DMZ
SSH inbound
SSH permitted from management segment to web server only. Scoped to single host, key auth required.
Enforced
Inter-segment
Default
All inter-segment traffic blocked by default. Explicit allow rules required. First-match evaluation.
Enforced
SECURITY POSTURE
Default policy
All interfaces
Implicit deny on all interfaces. No rule = no access. Principle of least privilege throughout.
Policy
Rule scope
All rules
Rules scoped to specific source/destination hosts where possible — not broad subnet allows.
Policy