---
title: "Basic Network for a public facing DataShed5 and LogChiefLite"
canonical: "https://servicedesk.maxgeo.com/space/DS/1429602320/Basic%20Network%20for%20a%20public%20facing%20DataShed5%20and%20LogChiefLite"
format: markdown
---
> ℹ️ This is only to be used as a reference. Implementing a public facing* environment or services should always be carried out by a trained professional.


Basic outline of a network diagram that includes a Web Application Firewall (WAF), Demilitarized Zone (DMZ), Web Server, SQL Server, DNS, and Load Balancer:

1. **Internet**: The starting point where users access the web application.
2. **Cloud DNS Registrar**: Cloud Host for DNS Registrar
3. **Load Balancer**: Distributes incoming traffic across multiple web servers to ensure no single server becomes overwhelmed.
4. **Web Application Firewall (WAF)**: Protects the web servers by filtering and monitoring HTTP traffic between the Internet and the web application.
5. **DMZ**: A buffer zone between the public internet and the internal network. It contains the web servers and other public-facing services.

**Web Server**: Hosts the web application and serves content to users.

**Internal Network**: The secure part of the network where sensitive data is stored.

- **SQL Server**: Stores the application’s data and handles database queries.** **
- **Local DNS Server**: Resolves domain names to IP addresses, directing traffic to the appropriate web server.


![image](media://37de2b1f-2de9-4de9-9fd7-4dd93ea0ad60)


An SSL Certificate is recommended for all public facing sites. [What is an SSL certificate? | Cloudflare](https://www.cloudflare.com/en-gb/learning/ssl/what-is-an-ssl-certificate/)

This setup ensures that the web application is secure and scalable, with the WAF providing protection against common web threats, the DMZ isolating public-facing services, and the load balancer ensuring efficient traffic distribution.

> ⚠️ Any services that will be public facing should always be deployed by a competent  and train IT service provider. All cyber security best practices should be applied.


For more information please view the below links

Load Balancer: [What is Load Balancing? - Load Balancing Algorithm Explained - AWS (amazon.com)](https://aws.amazon.com/what-is/load-balancing/#:~:text=A%20load%20balancer%20is%20a,resource%20servers%20are%20used%20equally.)

Cloud DNS register example: [Cloudflare Application Services Products Portfolio | Cloudflare](https://www.cloudflare.com/en-gb/application-services/products/)

DNZ: [What Is a DMZ Network and Why Would You Use It? | Fortinet](https://www.fortinet.com/resources/cyberglossary/what-is-dmz)

Implementing Certificates, TLS, HTTPS and Opportunistic TLS: [Implementing Certificates, TLS, HTTPS and Opportunistic TLS | Cyber.gov.au](https://www.cyber.gov.au/resources-business-and-government/maintaining-devices-and-systems/system-hardening-and-administration/web-hardening/implementing-certificates-tls-https-and-opportunistic-tls)

Database server Guidelines: [Guidelines for Database Systems | Cyber.gov.au](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-database-systems)

*Public Facing: The term "public facing" is used to describe a type of digital system which is available to the general public. Most websites that can be accessed online fall within this category. Some public facing websites might have members sections or areas that a user can "login" to, which would be classed as an extranet area.