network·Cisco-convention topology icons + security-zone topology·cloud, security, infrastructure·complexity 3/3·since v0.6.0
Zero-trust cloud VPC topology
Network topology for a zero-trust SaaS VPC with VPN entry, DMZ, private application subnet, database subnet, firewall segmentation, and annotated VPN/fiber/trunk links.
For the cloud network architect
network·§ —
↘ preview
100%
UTF-8 · LF · 32 lines · 881 chars✓ parsed·4.1 ms·11.8 KB SVG
Scenario
Zero-trust diagrams need to show both the physical/logical topology and the policy boundary: public traffic reaches only the DMZ, administrators enter through VPN and identity checks, and application servers reach the database through a segmented firewall path.
Annotation key
zoneandsubnetgroups distinguish security policy from IP address space.- VPN links are dashed and annotated, making identity/device-posture paths visible.
- VLAN labels document segmentation at the firewall boundary.