<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Networking — Things Worth Sharing</title><description>Bài viết gắn tag Networking.</description><link>https://cloudsecop.net/</link><item><title>Network policy L4: chặn non-HTTP, DoH bypass và app rule</title><link>https://cloudsecop.net/blog/network-policy-l4-non-http/</link><guid isPermaLink="true">https://cloudsecop.net/blog/network-policy-l4-non-http/</guid><description>Network policy deep-dive: chặn non-HTTP (SSH, RDP, SMTP), chặn DoH bypass DNS filter, app rule cho SaaS, kết hợp WARP, checklist production và playbook siết chặt.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>Networking</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Magic WAN: kết nối site và cloud qua Cloudflare backbone</title><link>https://cloudsecop.net/blog/magic-wan-va-bgp-over-gre/</link><guid isPermaLink="true">https://cloudsecop.net/blog/magic-wan-va-bgp-over-gre/</guid><description>Magic WAN deep-dive: tunnel network-layer thay SD-WAN/MPLS. 4 tuỳ chọn tunnel (IPsec, GRE, Anycast IP, CNI), BGP peering, multi-cloud, Magic Firewall, playbook chuyển đổi.</description><pubDate>Sat, 26 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Magic WAN</category><category>Networking</category><category>SD-WAN</category><author>KhaVan</author></item><item><title>Cloudflare Tunnel deep-dive: đưa internal service ra ngoài</title><link>https://cloudsecop.net/blog/cloudflare-tunnel-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-tunnel-deep-dive/</guid><description>Kiến trúc daemon cloudflared, ingress rules, HA replicas, protocol non-HTTP (SSH/RDP/SMB), chuyển từ VPN, truy nguyên 6 trường hợp. Tunnel là nền tảng kết nối cho Zero Trust.</description><pubDate>Sun, 30 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Tunnel</category><category>Networking</category><author>KhaVan</author></item><item><title>Pingora vs AWS ALB/NLB — khi nào self-host reverse proxy thắng</title><link>https://cloudsecop.net/blog/pingora-vs-aws-alb-nlb/</link><guid isPermaLink="true">https://cloudsecop.net/blog/pingora-vs-aws-alb-nlb/</guid><description>Pingora xử lý 40M+ req/sec ở Cloudflare. Khi nào self-host bằng pingora-core/pingora-proxy thắng AWS ALB $20/tháng + LCU và NLB managed.</description><pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Networking</category><category>Rust</category><category>AWS</category><category>Performance</category><author>KhaVan</author></item><item><title>cloudflared internals — build from source, ingress patterns, debugging</title><link>https://cloudsecop.net/blog/cloudflared-internals-from-source/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflared-internals-from-source/</guid><description>Build cloudflared từ Go source, ingress.yaml advanced patterns (path routing, HTTP/2, origin cert), tunnel info JSON cho monitoring, top 5 debug technique.</description><pubDate>Sat, 23 Nov 2024 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Tunnel</category><category>Networking</category><author>KhaVan</author></item><item><title>Boringtun: WireGuard userspace cho WARP — tại sao nhanh hơn corporate VPN</title><link>https://cloudsecop.net/blog/boringtun-wireguard-warp/</link><guid isPermaLink="true">https://cloudsecop.net/blog/boringtun-wireguard-warp/</guid><description>Boringtun Rust userspace WireGuard, kiến trúc bên trong WARP client, vì sao userspace WG thắng kernel module ở mobile/edge, MASQUE evolution.</description><pubDate>Tue, 19 Nov 2024 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>WARP</category><category>Networking</category><category>WireGuard</category><author>KhaVan</author></item></channel></rss>