Capstone: ASA Build

Cisco ASA Firewall EVE-NG — ASAv (CLI + ASDM)

مقصدObjectiveObjective

Scratch سے complete ASA firewall deploy کریں: interfaces، routing، NAT، ACLs، AAA، VPN readiness، اور logging — پھر ہر layer validate کریں۔Scratch se complete ASA firewall deploy karo: interfaces, routing, NAT, ACLs, AAA, VPN readiness, aur logging — phir har layer validate karo.Deploy a complete ASA firewall from scratch: interfaces, routing, NAT, ACLs, AAA, VPN readiness, and logging — then validate every layer.

آسان مثالSimple AnalogySimple Analogy

Firewall بنانا نیا bank branch کھولنے جیسا ہے: vault set کریں (interfaces)، visitor rules لکھیں (ACLs)، phone lines connect کریں (NAT)، staff badges issue کریں (AAA)، armored tunnels کھودیں (VPNs)، اور cameras لگائیں (logging) — پھر customers کے آنے سے پہلے سب test کریں۔Firewall banana naya bank branch kholne jaisa hai: vault set karo (interfaces), visitor rules likho (ACLs), phone lines connect karo (NAT), staff badges issue karo (AAA), armored tunnels khodo (VPNs), aur cameras lagao (logging) — phir customers ke ane se pehle sab test karo.Building a firewall is like opening a new bank branch: set up the vault (interfaces), write the visitor rules (ACLs), connect the phone lines (NAT), issue staff badges (AAA), dig the armored tunnels (VPNs), and install the cameras (logging) — then test everything before customers arrive.

سیٹ اپLab SetupLab Setup

EVE-NG میں fresh ASAv۔ Topology: inside LAN 10.1.1.0/24 (G0/0)، outside 203.0.113.2/24 gw 203.0.113.1 (G0/1)، DMZ 172.16.1.0/24 web server 172.16.1.10 کے ساتھ (G0/2)، mgmt 192.168.10.10/24۔ Public IP 203.0.113.10 web server کے لیے reserved ہے۔EVE-NG mein fresh ASAv. Topology: inside LAN 10.1.1.0/24 (G0/0), outside 203.0.113.2/24 gw 203.0.113.1 (G0/1), DMZ 172.16.1.0/24 web server 172.16.1.10 ke sath (G0/2), mgmt 192.168.10.10/24. Public IP 203.0.113.10 web server ke liye reserved hai.Fresh ASAv in EVE-NG. Topology: inside LAN 10.1.1.0/24 (G0/0), outside 203.0.113.2/24 gw 203.0.113.1 (G0/1), DMZ 172.16.1.0/24 with web server 172.16.1.10 (G0/2), mgmt 192.168.10.10/24. Public IP 203.0.113.10 reserved for the web server.

اقداماتStepsSteps

Step 1

Phase 1 — Foundation: hostname، passwords، اور management interface، بالکل asa-01 کی طرح۔Phase 1 — Foundation: hostname, passwords, aur management interface, bilkul asa-01 ki tarah.Phase 1 — Foundation: hostname, passwords, and the management interface, exactly as in asa-01.

hostname ASA-PROD
domain-name corp.local
enable password Cisc0En4ble
passwd Cisc0Login
interface management 0/0
nameif management
security-level 100
ip address 192.168.10.10 255.255.255.0
no shutdown
exit

Step 2

Phase 2 — Interfaces & routing: تینوں interfaces کو نام دیں، security levels set کریں، IPs assign کریں، اور default route add کریں۔Phase 2 — Interfaces & routing: teeno interfaces ko naam do, security levels set karo, IPs assign karo, aur default route add karo.Phase 2 — Interfaces & routing: name all three interfaces, set security levels, assign IPs, and add the default route.

interface GigabitEthernet0/0
nameif inside
security-level 100
ip address 10.1.1.1 255.255.255.0
no shutdown
exit
interface GigabitEthernet0/1
nameif outside
security-level 0
ip address 203.0.113.2 255.255.255.0
no shutdown
exit
interface GigabitEthernet0/2
nameif dmz
security-level 50
ip address 172.16.1.1 255.255.255.0
no shutdown
exit
route outside 0.0.0.0 0.0.0.0 203.0.113.1 1

Step 3

Phase 3 — NAT: inside users کے لیے dynamic PAT، DMZ web server کو اس کے public IP سے map کرنے والا static NAT۔Phase 3 — NAT: inside users ke liye dynamic PAT, DMZ web server ko uske public IP se map karne wala static NAT.Phase 3 — NAT: dynamic PAT for inside users, static NAT mapping the DMZ web server to its public IP.

object network INSIDE_NET
subnet 10.1.1.0 255.255.255.0
nat (inside,outside) dynamic interface
exit
object network DMZ_WEB
host 172.16.1.10
nat (dmz,outside) static 203.0.113.10
exit

Step 4

Phase 4 — Access control: object groups plus ACLs تاکہ دنیا صرف DMZ web server تک 80/443 پر پہنچے، جبکہ inside users کو full outbound access ہو۔Phase 4 — Access control: object groups plus ACLs taake duniya sirf DMZ web server tak 80/443 par pahunche, jabke inside users ko full outbound access ho.Phase 4 — Access control: object groups plus ACLs so the world reaches only the DMZ web server on 80/443, while inside users have full outbound access.

object-group network DMZ_SERVERS
network-object host 172.16.1.10
exit
object-group service WEB_PORTS tcp
port-object eq www
port-object eq https
exit
access-list OUTSIDE_IN extended permit tcp any object-group DMZ_SERVERS object-group WEB_PORTS
access-group OUTSIDE_IN in interface outside
access-list INSIDE_OUT extended permit ip 10.1.1.0 255.255.255.0 any
access-group INSIDE_OUT in interface inside

Step 5

Phase 5 — AAA & management: local admin، SSH/HTTPS کے لیے AAA، RSA keys، اور SSH/ASDM کے لیے management-only access۔Phase 5 — AAA & management: local admin, SSH/HTTPS ke liye AAA, RSA keys, aur SSH/ASDM ke liye management-only access.Phase 5 — AAA & management: local admin, AAA for SSH/HTTPS, RSA keys, and management-only access for SSH and ASDM.

username fwadmin password FwAdm1n! privilege 15
aaa authentication ssh console LOCAL
aaa authentication http console LOCAL
crypto key generate rsa modulus 2048
ssh version 2
ssh 192.168.10.0 255.255.255.0 management
http server enable
http 192.168.10.0 255.255.255.0 management

🖱️ ASDM final review: Configuration > Firewall > Access Rules اور NAT Rules — full policy visually confirm کریں۔ASDM final review: Configuration > Firewall > Access Rules aur NAT Rules — full policy visually confirm karo.ASDM final review: Configuration > Firewall > Access Rules and NAT Rules — confirm the full policy visually.

Step 6

Phase 6 — Visibility: logging اور threat detection enable کریں تاکہ نیا firewall پہلے دن سے خود پر نظر رکھے۔Phase 6 — Visibility: logging aur threat detection enable karo taake naya firewall pehle din se khud par nazar rakhe.Phase 6 — Visibility: enable logging and threat detection so the new firewall watches itself from day one.

logging enable
logging timestamp
logging buffered warnings
threat-detection basic-threat
threat-detection scanning-threat

Step 7

Phase 7 — Validate: DMZ web flow اور inside outbound flow کو packet-trace کریں (دونوں ALLOW ہونے چاہیے)، پھر save کریں۔ Handover کے لیے final config document کریں۔Phase 7 — Validate: DMZ web flow aur inside outbound flow ko packet-trace karo (dono ALLOW hone chahiye), phir save karo. Handover ke liye final config document karo.Phase 7 — Validate: packet-trace the DMZ web flow and an inside outbound flow (both must ALLOW), then save. Document the final config for handover.

packet-tracer input outside tcp 203.0.113.50 40000 203.0.113.10 80 detailed
packet-tracer input inside tcp 10.1.1.50 40001 8.8.8.8 443 detailed
write memory

تصدیقVerifyVerify

سارے interfaces up، default route موجود، `show nat` اور `show xlate` correct، دونوں packet-traces ALLOW، ASDM management سے reachable، اور config saved — lab میں firewall production-ready ہے۔Sare interfaces up, default route mojood, `show nat` aur `show xlate` correct, dono packet-traces ALLOW, ASDM management se reachable, aur config saved — lab mein firewall production-ready hai.All interfaces up, default route present, `show nat` and `show xlate` correct, both packet-traces ALLOW, ASDM reachable from management, and config saved — the firewall is production-ready in the lab.

show interface ip brief
show route
show nat
show access-list
show run | include aaa authentication

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Capstone validation unexpected phase پر fail ہو رہا ہے۔Capstone validation unexpected phase par fail ho raha hai.Capstone validation fails at an unexpected phase.

✅ Checklist کو الٹا چلائیں: packet-tracer dropping phase کا نام بتاتا ہے، پھر اس phase کا lesson check کریں (ACL → asa-03، NAT → asa-04، route → asa-02)۔ Fix کریں، دوبارہ trace کریں، پھر ہی آگے بڑھیں۔Checklist ko ulta chalao: packet-tracer dropping phase ka naam batata hai, phir us phase ka lesson check karo (ACL → asa-03, NAT → asa-04, route → asa-02). Fix karo, dobara trace karo, phir hi aage barho.Work the checklist backwards: packet-tracer names the dropping phase, then check that phase's lesson (ACL → asa-03, NAT → asa-04, route → asa-02). Fix, re-trace, and only then move forward.

⚠️ `write memory` بھول گئے اور ASAv reload ہو گیا۔`write memory` bhool gaye aur ASAv reload ho gaya.`write memory` was forgotten and the ASAv reloaded.

✅ Reload پر unsaved config lost ہو جاتی ہے — اپنی documented checklist سے دوبارہ بنائیں۔ سبق: capstone میں صرف آخر میں نہیں، ہر phase کے بعد save کریں۔Reload par unsaved config lost ho jati hai — apni documented checklist se dobara banao. Sabak: capstone mein sirf aakhir mein nahi, har phase ke baad save karo.Unsaved config is lost on reload — rebuild from your documented checklist. Lesson: save after every phase during the capstone, not just at the end.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ اپنی firewall deployment checklist سمجھائیں۔Apni firewall deployment checklist samjhao.Walk me through your firewall deployment checklist.

میری checklist order: پہلے interfaces اور routing (ان کے بغیر کچھ نہیں چلتا)، پھر NAT، پھر ACLs، پھر management/AAA hardening، پھر VPNs، اور logging ہر step پر۔ ہر layer کو show commands اور packet-tracer سے verify کرکے آگے بڑھتا ہوں۔Meri checklist order: pehle interfaces aur routing (inke baghair kuch nahi chalta), phir NAT, phir ACLs, phir management/AAA hardening, phir VPNs, aur logging har step par. Har layer ko show commands aur packet-tracer se verify karke aage barhta hun.My checklist order: interfaces and routing first (nothing works without them), then NAT, then ACLs, then management/AAA hardening, then VPNs, and logging throughout. I verify each layer with show commands and packet-tracer before moving on.

❓ ASA سے نہ گزرنے والے traffic کو کیسے troubleshoot کرو گے؟ASA se na guzarne wale traffic ko kaise troubleshoot karoge?How would you troubleshoot traffic that fails to pass through the ASA?

میں failing flow کو packet-tracer کروں گا dropping phase ڈھونڈنے کے لیے، `show access-list` hit counts اور `show nat`/`show xlate` check کروں گا، `show route` سے routing verify کروں گا، اور `show logging` سے confirm کروں گا کون سا event fire ہوا۔ ایک وقت میں ایک layer fix کروں گا۔Main failing flow ko packet-tracer karunga dropping phase dhoondne ke liye, `show access-list` hit counts aur `show nat`/`show xlate` check karunga, `show route` se routing verify karunga, aur `show logging` se confirm karunga kaun sa event fire hua. Ek waqt mein ek layer fix karunga.I'd packet-tracer the failing flow to find the dropping phase, check `show access-list` hit counts and `show nat`/`show xlate`, verify routing with `show route`, and confirm with `show logging` which event fired. Fix one layer at a time.