Skip to main content

Topic index

Network and Infrastructure

Learn the network boundaries, traffic paths, and infrastructure patterns behind private access.

Topic index

Understand this domain

Pomerium coverage

Pomerium operates at the application access path. It accepts a named user-facing route, evaluates identity-aware policy, and connects approved traffic to a reachable private upstream. The deployment still needs correct DNS, TLS, load balancing, and private network reachability.

Limits

  • Application access policy does not replace firewalls, private routing, segmentation, or endpoint controls.
  • An HTTP proxy in front of a TCP tunnel must support CONNECT. UDP needs CONNECT-UDP support.
  • Network location does not prove user identity or permission to use an application resource.

Primary sources

2 learning paths

Paths for this topic

22 related guides

Guides in this topic

37 related terms

Concepts in this topic

Application and Service AccessNetwork and Infrastructure

Bastion Host

A bastion host is a hardened system that provides controlled administrative access to a more protected network or resource.

Learn this term
Application and Service AccessNetwork and Infrastructure

Clientless Zero Trust Access

Distinguish browser or native-client access from broad network tunnels and state which protocols still require a local connector.

Learn this term
Network and Infrastructure

Cloud Network Security

Cloud network security protects data, workloads, identities, and communication paths in cloud environments. It follows a shared responsibility model.

Learn this term
Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term
Security Operations and RiskNetwork and Infrastructure

Denial of Service

Model how traffic, expensive valid work, state, queues, dependencies, identity, and recovery controls can make a service unavailable.

Learn this term
Network and Infrastructure

East-West Traffic

East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments.

Learn this term
Network and Infrastructure

Firewall

A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy.

Learn this term
Application and Service AccessNetwork and Infrastructure

Gateway Bypass Path

Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.

Learn this term
Standards and ProtocolsNetwork and Infrastructure

HTTPS and TLS

Explain HTTPS as HTTP over an authenticated, encrypted TLS channel with explicit names, endpoints, and termination boundaries.

Learn this term
Zero TrustNetwork and Infrastructure

Implicit Trust Zone

An implicit trust zone grants authority from location, membership, or prior access without a resource-specific decision.

Learn this term
Network and Infrastructure

Ingress and Egress

Place controls on traffic entering and leaving a workload boundary without treating direction or network location as identity.

Learn this term
Network and InfrastructureAuthorization and Policy

Kubernetes RBAC

Grant Kubernetes API verbs on exact resources and namespaces without broad roles, aggregation, bind, or escalation paths.

Learn this term
Network and InfrastructureIdentity and Authentication

Kubernetes Service Account

Use bounded, short-lived Kubernetes service-account tokens for a workload and avoid static namespace-wide credentials.

Learn this term
Zero TrustNetwork and Infrastructure

Micro-segmentation

The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise.

Learn this term
Network and Infrastructure

North-South Traffic

North-south traffic crosses an environment or trust boundary, such as traffic between a user and an application or between a private service and the internet.

Learn this term
Network and InfrastructureStandards and Protocols

OSI Layers

The OSI model is a seven-layer reference model, not a guarantee that each protocol provides reliability.

Learn this term
Network and Infrastructure

Perimeter

A security perimeter is a boundary where controls inspect or restrict communication. NIST zero trust does not remove firewalls or all network boundaries.

Learn this term
Network and InfrastructureStandards and Protocols

Software-Defined Networking (SDN)

Software-defined networking separates programmable control functions from the packet-forwarding plane through defined abstractions and interfaces.

Learn this term
Privacy EngineeringNetwork and Infrastructure

Traffic Analysis

Infer participants, relationships, activity, protocol, content class, and events from communication timing, direction, size, frequency, and routes.

Learn this term
Application and Service AccessNetwork and Infrastructure

Upstream and Downstream

Upstream and downstream describe direction relative to one intermediary, so the reference point must be explicit.

Learn this term
Network and Infrastructure

Virtual Private Network (VPN)

A VPN creates an encrypted tunnel over another network. Remote-access VPNs connect an endpoint to a private network. Site-to-site VPNs connect networks.

Learn this term
Network and InfrastructureIdentity and Authentication

Workload Attestation

Use platform evidence to select a workload identity without treating mutable labels or network location as proof.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo