<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cloudflare One — Things Worth Sharing</title><description>Bài viết gắn tag Cloudflare One.</description><link>https://cloudsecop.net/</link><item><title>Email Security: chặn phishing, BEC, và bài toán DMARC forwarder</title><link>https://cloudsecop.net/blog/email-security-area1-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/email-security-area1-deep-dive/</guid><description>Email Security deep-dive cho Cloudflare One: MX inline vs API journaling, bẫy DMARC forwarder/subdomain docs không nói, FP homoglyph, user report → retract &lt; 1h tự động.</description><pubDate>Tue, 08 Jul 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Email Security</category><category>Phishing</category><author>KhaVan</author></item><item><title>DLP: pattern, classification và 55% false positive</title><link>https://cloudsecop.net/blog/dlp-data-loss-prevention-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/dlp-data-loss-prevention-deep-dive/</guid><description>DLP đào sâu cho Cloudflare One: tinh chỉnh từ 55% FP về 3%, regex vs Luhn vs context vs EDM, profile CCCD Việt Nam, Gateway HTTP inline vs CASB API.</description><pubDate>Mon, 30 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DLP</category><category>Data Classification</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>CASB: posture và misconfig SaaS (GWorkspace, M365, SF)</title><link>https://cloudsecop.net/blog/casb-saas-posture-misconfig/</link><guid isPermaLink="true">https://cloudsecop.net/blog/casb-saas-posture-misconfig/</guid><description>CASB deep-dive cho Cloudflare One từ 3 lần triển khai: 4 trụ cột Gartner, inline vs API, phản ứng 8000 finding tuần đầu, shadow IT discovery, tenant lock, khi nào KHÔNG dùng CASB.</description><pubDate>Mon, 23 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>CASB</category><category>SaaS Security</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Browser Isolation (RBI): render risky web trong sandbox remote</title><link>https://cloudsecop.net/blog/browser-isolation-rbi-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/browser-isolation-rbi-deep-dive/</guid><description>Browser Isolation deep-dive cho Cloudflare One: kiến trúc remote browser (NVR), kích hoạt isolation, kiểm soát dữ liệu (copy/paste/print/download/keyboard), compliance, chi phí.</description><pubDate>Thu, 19 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Browser Isolation</category><category>RBI</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Device posture và continuous verification mọi request</title><link>https://cloudsecop.net/blog/device-posture-continuous-verification/</link><guid isPermaLink="true">https://cloudsecop.net/blog/device-posture-continuous-verification/</guid><description>Device posture đào sâu cho Zero Trust: WARP check (OS, mã hóa ổ đĩa, firewall), EDR (CrowdStrike, SentinelOne, Defender), continuous verification trong Access policy, truy nguyên.</description><pubDate>Sat, 07 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Device Posture</category><category>EDR</category><author>KhaVan</author></item><item><title>DEX: Digital Experience Monitoring và proactive SLO</title><link>https://cloudsecop.net/blog/dex-digital-experience-monitoring/</link><guid isPermaLink="true">https://cloudsecop.net/blog/dex-digital-experience-monitoring/</guid><description>DEX đào sâu cho Cloudflare One: khi control plane UP mà người dùng thấy chậm, chẩn đoán từng chặng (DNS/TCP/TLS/TTFB), SLO framework, 5 chế độ hỏng DEX không thấy.</description><pubDate>Fri, 30 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DEX</category><category>Observability</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Logs pipeline: Logpush, R2, SIEM và cross-layer correlation</title><link>https://cloudsecop.net/blog/logs-pipeline-logpush-siem/</link><guid isPermaLink="true">https://cloudsecop.net/blog/logs-pipeline-logpush-siem/</guid><description>Logs deep-dive cho Cloudflare One: các dataset, Logpush (R2/S3/Splunk/Sentinel), tương quan đa tầng, retention hot/warm/cold, kiểm soát chi phí, rule phát hiện SIEM mẫu.</description><pubDate>Fri, 23 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Logs</category><category>SIEM</category><category>Observability</category><author>KhaVan</author></item><item><title>Cloudflare Access vs AWS IAM Identity Center cho team admin</title><link>https://cloudsecop.net/blog/cloudflare-access-vs-aws-iam-idc/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-access-vs-aws-iam-idc/</guid><description>Đừng cố unify Cloudflare Access và AWS IAM Identity Center. Pattern thực dụng: Okta/Entra → SSO cả hai, SCIM provisioning, per-app policy, audit correlation.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>AWS</category><category>Identity</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Network policy L4: chặn non-HTTP, DoH bypass và app rule</title><link>https://cloudsecop.net/blog/network-policy-l4-non-http/</link><guid isPermaLink="true">https://cloudsecop.net/blog/network-policy-l4-non-http/</guid><description>Network policy deep-dive: chặn non-HTTP (SSH, RDP, SMTP), chặn DoH bypass DNS filter, app rule cho SaaS, kết hợp WARP, checklist production và playbook siết chặt.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>Networking</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Gateway HTTP filtering và TLS decryption: khi DNS không đủ</title><link>https://cloudsecop.net/blog/gateway-http-filtering-va-tls-decryption/</link><guid isPermaLink="true">https://cloudsecop.net/blog/gateway-http-filtering-va-tls-decryption/</guid><description>HTTP inspection deep-dive: cài root CA (MDM, GPO), cạm bẫy cert pinning, mẫu DLP, tenant CASB, lan can pháp lý/quyền riêng tư, playbook triển khai, checklist production.</description><pubDate>Sun, 11 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>TLS</category><category>DLP</category><category>CASB</category><author>KhaVan</author></item><item><title>Gateway DNS filtering: lớp đầu tiên của Secure Web Gateway</title><link>https://cloudsecop.net/blog/gateway-dns-filtering/</link><guid isPermaLink="true">https://cloudsecop.net/blog/gateway-dns-filtering/</guid><description>Gateway DNS deep-dive: kiến trúc resolver, thứ tự policy, DoH per-device vs DNS location per-site, threat intel category, custom list, log SIEM, checklist production.</description><pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>DNS</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Magic WAN: kết nối site và cloud qua Cloudflare backbone</title><link>https://cloudsecop.net/blog/magic-wan-va-bgp-over-gre/</link><guid isPermaLink="true">https://cloudsecop.net/blog/magic-wan-va-bgp-over-gre/</guid><description>Magic WAN deep-dive: tunnel network-layer thay SD-WAN/MPLS. 4 tuỳ chọn tunnel (IPsec, GRE, Anycast IP, CNI), BGP peering, multi-cloud, Magic Firewall, playbook chuyển đổi.</description><pubDate>Sat, 26 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Magic WAN</category><category>Networking</category><category>SD-WAN</category><author>KhaVan</author></item><item><title>WARP client và device enrollment flow</title><link>https://cloudsecop.net/blog/warp-client-va-device-enrollment/</link><guid isPermaLink="true">https://cloudsecop.net/blog/warp-client-va-device-enrollment/</guid><description>Kiến trúc WARP, enrollment, device posture (built-in vs CrowdStrike/Intune), split tunnel 2 chế độ, Local Domain Fallback, DNS, triển khai MDM, truy nguyên 6 trường hợp.</description><pubDate>Thu, 10 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>WARP</category><category>Device Posture</category><author>KhaVan</author></item><item><title>Cloudflare Tunnel deep-dive: đưa internal service ra ngoài</title><link>https://cloudsecop.net/blog/cloudflare-tunnel-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-tunnel-deep-dive/</guid><description>Kiến trúc daemon cloudflared, ingress rules, HA replicas, protocol non-HTTP (SSH/RDP/SMB), chuyển từ VPN, truy nguyên 6 trường hợp. Tunnel là nền tảng kết nối cho Zero Trust.</description><pubDate>Sun, 30 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Tunnel</category><category>Networking</category><author>KhaVan</author></item><item><title>SCIM và group sync: tự động off-board khi nhân viên nghỉ</title><link>https://cloudsecop.net/blog/scim-va-group-sync/</link><guid isPermaLink="true">https://cloudsecop.net/blog/scim-va-group-sync/</guid><description>SCIM giải quyết cửa sổ lỗi thời: IdP đẩy cập nhật thời gian thực thay vì CF kéo claim khi đăng nhập. Thiết lập SCIM cho Okta/Entra/Google, vòng đời người dùng, xung đột.</description><pubDate>Sat, 22 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Identity</category><category>SCIM</category><category>Lifecycle</category><author>KhaVan</author></item><item><title>Service tokens và mTLS: authentication cho CI/CD, bot, device</title><link>https://cloudsecop.net/blog/service-tokens-mtls-cho-non-human/</link><guid isPermaLink="true">https://cloudsecop.net/blog/service-tokens-mtls-cho-non-human/</guid><description>Khi client không phải người dùng. Phân biệt service token vs mTLS, cách thiết lập cả hai, chiến lược rotate, audit log, và anti-pattern phổ biến.</description><pubDate>Tue, 11 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Access</category><category>mTLS</category><category>DevOps</category><author>KhaVan</author></item><item><title>Integrate IdP: Okta, Entra ID, Google Workspace, SAML generic</title><link>https://cloudsecop.net/blog/identity-provider-integration/</link><guid isPermaLink="true">https://cloudsecop.net/blog/identity-provider-integration/</guid><description>Ma trận 4 IdP phổ biến với Cloudflare Access: OIDC vs SAML, cạm bẫy group claim, claim mapping, group sync timing, pattern multi-IdP, checklist trước production.</description><pubDate>Fri, 07 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Identity</category><category>Okta</category><category>Entra ID</category><author>KhaVan</author></item><item><title>Cloudflare Access: ZTNA cơ bản trong 30 phút</title><link>https://cloudsecop.net/blog/cloudflare-access-ztna-co-ban/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-access-ztna-co-ban/</guid><description>Thay VPN cho ứng dụng nội bộ bằng Cloudflare Access: giải phẫu, luồng đăng nhập, 5 bước thiết lập (app, IdP, policy, Tunnel, test), thứ tự đánh giá policy, truy nguyên.</description><pubDate>Sun, 23 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Access</category><category>ZTNA</category><author>KhaVan</author></item><item><title>Mental model 4 tầng: Client, Identity, Policy, Resource</title><link>https://cloudsecop.net/blog/mental-model-client-identity-policy-resource/</link><guid isPermaLink="true">https://cloudsecop.net/blog/mental-model-client-identity-policy-resource/</guid><description>Khung tư duy cho mọi tính năng Cloudflare One: mỗi request đi qua 4 tầng sinh tín hiệu, policy đánh giá rồi đi tới 1 trong 5 kết quả. Triển khai và truy nguyên dễ hơn nhiều.</description><pubDate>Sat, 15 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Architecture</category><author>KhaVan</author></item><item><title>SASE, SSE, Zero Trust, ZTNA: phân biệt thuật ngữ trước khi sa lầy</title><link>https://cloudsecop.net/blog/sase-sse-zero-trust-thuat-ngu/</link><guid isPermaLink="true">https://cloudsecop.net/blog/sase-sse-zero-trust-thuat-ngu/</guid><description>Ba thuật ngữ dễ dùng lẫn lộn trong RFP, design doc và tiếp thị. Phân biệt phạm vi, thời điểm xuất hiện, cách dùng đúng, và decision tree nhỏ để chọn đúng từ trong từng ngữ cảnh.</description><pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>SSE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Cloudflare One là gì, và vì sao SASE quan trọng</title><link>https://cloudsecop.net/blog/cloudflare-one-la-gi/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-one-la-gi/</guid><description>Một tổng quan thực dụng về Cloudflare One: SASE, SSE, Zero Trust, 6 nhóm sản phẩm chính, cách so sánh với Zscaler/Netskope, và mô hình tư duy cần có trước khi triển khai.</description><pubDate>Sat, 04 Jan 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>cloudflared internals — build from source, ingress patterns, debugging</title><link>https://cloudsecop.net/blog/cloudflared-internals-from-source/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflared-internals-from-source/</guid><description>Build cloudflared từ Go source, ingress.yaml advanced patterns (path routing, HTTP/2, origin cert), tunnel info JSON cho monitoring, top 5 debug technique.</description><pubDate>Sat, 23 Nov 2024 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Tunnel</category><category>Networking</category><author>KhaVan</author></item><item><title>Boringtun: WireGuard userspace cho WARP — tại sao nhanh hơn corporate VPN</title><link>https://cloudsecop.net/blog/boringtun-wireguard-warp/</link><guid isPermaLink="true">https://cloudsecop.net/blog/boringtun-wireguard-warp/</guid><description>Boringtun Rust userspace WireGuard, kiến trúc bên trong WARP client, vì sao userspace WG thắng kernel module ở mobile/edge, MASQUE evolution.</description><pubDate>Tue, 19 Nov 2024 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>WARP</category><category>Networking</category><category>WireGuard</category><author>KhaVan</author></item></channel></rss>