Interfaces, Security Levels & Routing
Cisco ASA Firewall EVE-NG — ASAv (CLI + ASDM)
مقصدObjectiveObjective
Interfaces کو نام دیں، security levels assign کریں، اور static routing کنفیگر کریں تاکہ ASA inside، outside اور DMZ networks کے درمیان route کر سکے۔Interfaces ko naam do, security levels assign karo, aur static routing configure karo taake ASA inside, outside aur DMZ networks ke darmiyan route kar sake.Name interfaces, assign security levels, and configure static routing so the ASA can route between inside, outside, and DMZ networks.
آسان مثالSimple AnalogySimple Analogy
Security levels دفتر کی منزلوں جیسے ہیں: منزل 100 (inside) executive suite ہے، منزل 0 (outside) گلی ہے۔ نیچے آرام سے جا سکتے ہیں، لیکن اوپر جانے کے لیے گارڈ کی اجازت (ACL) چاہیے۔Security levels office ki manzilon jaisay hain: manzil 100 (inside) executive suite hai, manzil 0 (outside) gali hai. Neeche aaram se ja sakte ho, lekin upar jane ke liye guard ki ijazat (ACL) chahiye.Security levels are like floors in an office: floor 100 (inside) is the executive suite, floor 0 (outside) is the street. You can walk downstairs freely, but going up needs the guard's permission (an ACL).
سیٹ اپLab SetupLab Setup
ASAv میں تین data interfaces: GigabitEthernet0/0 (inside LAN 10.1.1.0/24)، GigabitEthernet0/1 (outside 203.0.113.0/24 کی طرف، gateway 203.0.113.1)، GigabitEthernet0/2 (DMZ 172.16.1.0/24)۔ASAv mein teen data interfaces: GigabitEthernet0/0 (inside LAN 10.1.1.0/24), GigabitEthernet0/1 (outside 203.0.113.0/24 ki taraf, gateway 203.0.113.1), GigabitEthernet0/2 (DMZ 172.16.1.0/24).ASAv with three data interfaces: GigabitEthernet0/0 (inside LAN 10.1.1.0/24), GigabitEthernet0/1 (outside toward 203.0.113.0/24, gateway 203.0.113.1), GigabitEthernet0/2 (DMZ 172.16.1.0/24).
اقداماتStepsSteps
Step 1
G0/0 کو 'inside' نام دیں، security level 100 (سب سے trusted) دیں، IP assign کریں، اور up کریں۔G0/0 ko 'inside' naam do, security level 100 (sab se trusted) do, IP assign karo, aur up karo.Name G0/0 'inside', give it security level 100 (most trusted), assign its IP, and bring it up.
interface GigabitEthernet0/0 nameif inside security-level 100 ip address 10.1.1.1 255.255.255.0 no shutdown exit
Step 2
G0/1 کو 'outside' نام دیں security level 0 (سب سے کم trusted) کے ساتھ — یہ internet کی طرف والا interface ہے۔G0/1 ko 'outside' naam do security level 0 (sab se kam trusted) ke sath — ye internet ki taraf wala interface hai.Name G0/1 'outside' with security level 0 (least trusted) — this is the interface facing the internet.
interface GigabitEthernet0/1 nameif outside security-level 0 ip address 203.0.113.2 255.255.255.0 no shutdown exit
Step 3
G0/2 کو 'dmz' نام دیں security level 50 کے ساتھ۔ DMZ inside اور outside کے درمیان ہوتا ہے — internet سے زیادہ trusted، LAN سے کم۔G0/2 ko 'dmz' naam do security level 50 ke sath. DMZ inside aur outside ke darmiyan hota hai — internet se zyada trusted, LAN se kam.Name G0/2 'dmz' with security level 50. A DMZ sits between inside and outside — trusted more than the internet, less than the LAN.
interface GigabitEthernet0/2 nameif dmz security-level 50 ip address 172.16.1.1 255.255.255.0 no shutdown exit
Step 4
ISP gateway کی طرف outside interface سے default route add کریں۔ اس کے بغیر ASA internet تک نہیں پہنچ سکتا۔ISP gateway ki taraf outside interface se default route add karo. Iske baghair ASA internet tak nahi pahunch sakta.Add a default route out the outside interface toward the ISP gateway. Without this, the ASA cannot reach the internet.
route outside 0.0.0.0 0.0.0.0 203.0.113.1 1
Step 5
Inside کے remote subnet (192.168.5.0/24) کے لیے inside next-hop 10.1.1.254 via static route add کریں۔Inside ke remote subnet (192.168.5.0/24) ke liye inside next-hop 10.1.1.254 via static route add karo.Add a static route for a remote inside subnet (192.168.5.0/24) via the inside next-hop 10.1.1.254.
route inside 192.168.5.0 255.255.255.0 10.1.1.254 1
🖱️ ASDM: Configuration > Device Setup > Routing > Static Routes — routes graphically add/view کریں۔ASDM: Configuration > Device Setup > Routing > Static Routes — routes graphically add/view karo.ASDM: Configuration > Device Setup > Routing > Static Routes — add/view routes graphically.
Step 6
Configuration save کریں۔Configuration save karo.Save the configuration.
write memory
تصدیقVerifyVerify
تینوں interfaces correct IPs کے ساتھ up/up ہوں، `show nameif` میں inside/outside/dmz list ہوں، اور `show route` میں default اور static routes نظر آئیں۔Teeno interfaces correct IPs ke sath up/up hon, `show nameif` mein inside/outside/dmz list hon, aur `show route` mein default aur static routes nazar aain.All three interfaces are up/up with correct IPs, `show nameif` lists inside/outside/dmz, and `show route` shows the default and static routes.
show interface ip brief show nameif show route
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ Interface 'administratively down' show ہو رہا ہے اور کوئی traffic نہیں گزر رہا۔Interface 'administratively down' show ho raha hai aur koi traffic nahi guzar raha.Interface shows 'administratively down' and no traffic passes.
✅ ASAv interfaces default طور پر shut down ہوتے ہیں — interface میں جائیں اور `no shutdown` چلائیں۔ `show interface ip brief` سے verify کریں۔ASAv interfaces default tor par shut down hote hain — interface mein jao aur `no shutdown` chalao. `show interface ip brief` se verify karo.ASAv interfaces are shut down by default — enter the interface and run `no shutdown`. Verify with `show interface ip brief`.
⚠️ Inside host outside gateway کو ping کر سکتا ہے لیکن internet سے reply نہیں آتا۔Inside host outside gateway ko ping kar sakta hai lekin internet se reply nahi ata.Inside host can ping the outside gateway but gets no reply from the internet.
✅ Check کریں default route موجود ہے (`show route`) اور NAT configured ہے (asa-04 میں) — NAT کے بغیر private source IP کا return path نہیں ہوتا۔Check karo default route mojood hai (`show route`) aur NAT configured hai (asa-04 mein) — NAT ke baghair private source IP ka return path nahi hota.Check the default route exists (`show route`) and that NAT is configured (covered in asa-04) — without NAT the private source IP has no return path.
⚠️ DMZ server inside سے reachable ہے لیکن outside interface سے نہیں۔DMZ server inside se reachable hai lekin outside interface se nahi.DMZ server is reachable from inside but not from the outside interface.
✅ یہ expected ہے: outside (level 0) سے DMZ (level 50) traffic default deny ہوتا ہے۔ Outside interface پر ACL چاہیے جو اسے permit کرے (asa-03)، اور ضرورت ہو تو NAT بھی۔Ye expected hai: outside (level 0) se DMZ (level 50) traffic default deny hota hai. Outside interface par ACL chahiye jo ise permit kare (asa-03), aur zaroorat ho to NAT bhi.That is expected: outside (level 0) to DMZ (level 50) traffic is denied by default. You need an ACL on the outside interface permitting it (asa-03) plus NAT if applicable.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Security levels کے درمیان default traffic flow rules سمجھائیں۔Security levels ke darmiyan default traffic flow rules samjhao.Explain the default traffic flow rules between security levels.
Higher security level سے lower کی طرف traffic freely جاتا ہے (stateful — return traffic automatically allow ہوتا ہے)۔ Lower سے higher کی طرف traffic deny ہوتا ہے جب تک ACL explicitly permit نہ کرے۔Higher security level se lower ki taraf traffic freely jata hai (stateful — return traffic automatically allow hota hai). Lower se higher ki taraf traffic deny hota hai jab tak ACL explicitly permit na kare.Traffic flows freely from a higher security level to a lower one (stateful — return traffic is automatically allowed). Traffic from lower to higher is denied unless an ACL explicitly permits it.
❓ کیا same security level والے دو interfaces default طور پر communicate کر سکتے ہیں؟Kya same security level wale do interfaces default tor par communicate kar sakte hain?Can two interfaces with the same security level communicate by default?
نہیں۔ Same security level والے interfaces default طور پر آپس میں بات نہیں کر سکتے۔ `same-security-traffic permit inter-interface` command اسے enable کرتی ہے۔Nahi. Same security level wale interfaces default tor par aapas mein baat nahi kar sakte. `same-security-traffic permit inter-interface` command ise enable karti hai.Yes. Interfaces with the same security level cannot talk to each other by default. The command `same-security-traffic permit inter-interface` enables it.