🎤 Cisco ASA Firewall — Interview Q&A
❓ ASA security levels اور ان کے درمیان default traffic rules سمجھائیں۔ASA security levels aur unke darmiyan default traffic rules samjhao.Explain ASA security levels and the default traffic rules between them.
0 سب سے کم trusted (outside)، 100 سب سے زیادہ trusted (inside)، 50 DMZ کے لیے typical ہے۔ Higher سے lower تک traffic freely جاتا ہے؛ lower-to-higher deny ہوتا ہے جب تک ACL permit نہ کرے۔0 sab se kam trusted (outside), 100 sab se zyada trusted (inside), 50 DMZ ke liye typical hai. Higher se lower tak traffic freely jata hai; lower-to-higher deny hota hai jab tak ACL permit na kare.0 is least trusted (outside), 100 is most trusted (inside), 50 is typical for DMZ. Traffic flows freely from higher to lower levels; lower-to-higher is denied unless an ACL permits it.
❓ ASA پر NAT کی تین types کون سی ہیں؟ASA par NAT ki teen types kaun si hain?What are the three NAT types on the ASA?
Auto NAT network object پر ہی configured ہوتا ہے (simple، جیسے inside users کے لیے PAT)۔ Manual NAT NAT table section میں لکھا جاتا ہے اور complex cases کے لیے top-down process ہوتا ہے۔ Twice NAT ایک ہی rule میں source اور destination translation configure کرتا ہے، اکثر NAT exemption کے لیے۔Auto NAT network object par hi configured hota hai (simple, jaise inside users ke liye PAT). Manual NAT NAT table section mein likha jata hai aur complex cases ke liye top-down process hota hai. Twice NAT ek hi rule mein source aur destination translation configure karta hai, aksar NAT exemption ke liye.Auto NAT is configured on the network object itself (simple, e.g. PAT for inside users). Manual NAT is written in the NAT table section and processed top-down for complex cases. Twice NAT configures source and destination translation in a single rule, often used for NAT exemption.
❓ MPF کیا ہے اور FTP کو inspection کیوں چاہیے؟MPF kya hai aur FTP ko inspection kyun chahiye?What is MPF and why does FTP need inspection?
Modular Policy Framework: class-map traffic classify کرتا ہے، policy-map ہر class کے لیے actions (inspect، police، connection limits) define کرتا ہے، اور service-policy policy کو interface یا globally attach کرتی ہے۔ Example: `inspect ftp` FTP data channels کو کام کرنے دیتا ہے۔Modular Policy Framework: class-map traffic classify karta hai, policy-map har class ke liye actions (inspect, police, connection limits) define karta hai, aur service-policy policy ko interface ya globally attach karti hai. Example: `inspect ftp` FTP data channels ko kaam karne deta hai.Modular Policy Framework: class-map classifies traffic, policy-map defines actions (inspect, police, connection limits) per class, and service-policy attaches the policy to an interface or globally. Example: `inspect ftp` lets FTP data channels work.
❓ ASA پر IKEv2 site-to-site VPN بنانے کا طریقہ بتائیں۔ASA par IKEv2 site-to-site VPN banane ka tareeqa batao.Walk me through building an IKEv2 site-to-site VPN on the ASA.
IKEv2 policy (Phase 1: encryption، integrity، DH group)، IPsec proposal (Phase 2: ESP transforms)، crypto ACL (interesting traffic)، crypto map (ACL + peer + proposal کو outside interface سے bind کرتا ہے)، matching pre-shared keys والا tunnel-group، outside پر enabled IKEv2، اور NAT exemption تاکہ VPN traffic translate نہ ہو۔IKEv2 policy (Phase 1: encryption, integrity, DH group), IPsec proposal (Phase 2: ESP transforms), crypto ACL (interesting traffic), crypto map (ACL + peer + proposal ko outside interface se bind karta hai), matching pre-shared keys wala tunnel-group, outside par enabled IKEv2, aur NAT exemption taake VPN traffic translate na ho.IKEv2 policy (Phase 1: encryption, integrity, DH group), IPsec proposal (Phase 2: ESP transforms), crypto ACL (interesting traffic), crypto map (binds ACL + peer + proposal to the outside interface), tunnel-group with matching pre-shared keys, IKEv2 enabled on outside, and a NAT exemption so VPN traffic isn't translated.
❓ AnyConnect remote-access VPN components سمجھائیں۔AnyConnect remote-access VPN components samjhao.Explain AnyConnect remote-access VPN components.
AnyConnect SSL/TLS remote-access client ہے۔ Key pieces: login پر select ہونے والا connection profile (tunnel group type remote-access)، group policy (IP pool، DNS، split tunnel، timeouts)، client addresses کے لیے `ip local pool`، اور outside interface پر `webvpn`۔ SSL اس لیے choose ہوتا ہے کیونکہ یہ ان networks سے گزر جاتا ہے جو IPsec block کرتے ہیں۔AnyConnect SSL/TLS remote-access client hai. Key pieces: login par select hone wala connection profile (tunnel group type remote-access), group policy (IP pool, DNS, split tunnel, timeouts), client addresses ke liye `ip local pool`, aur outside interface par `webvpn`. SSL is liye choose hota hai kyunke ye un networks se guzar jata hai jo IPsec block karte hain.AnyConnect is the SSL/TLS remote-access client. Key pieces: connection profile (tunnel group type remote-access) chosen at login, group policy (IP pool, DNS, split tunnel, timeouts), `ip local pool` for client addresses, and `webvpn` on the outside interface. SSL is chosen because it passes through networks that block IPsec.
❓ Packet-tracer tool کیسے use کرتے ہیں؟Packet-tracer tool kaise use karte ho?How do you use the packet-tracer tool?
`packet-tracer input <in-if> <proto> <src-ip> <src-port> <dst-ip> <dst-port> detailed` packet simulate کرتا ہے اور ہر phase دکھاتا ہے — ACL check، NAT، route lookup — آخر میں ALLOW یا DROP exact reason کے ساتھ۔ کسی بھی ASA issue پر یہ پہلا tool ہے جو میں اٹھاتا ہوں۔`packet-tracer input <in-if> <proto> <src-ip> <src-port> <dst-ip> <dst-port> detailed` packet simulate karta hai aur har phase dikhata hai — ACL check, NAT, route lookup — aakhir mein ALLOW ya DROP exact reason ke sath. Kisi bhi ASA issue par ye pehla tool hai jo main uthata hun.`packet-tracer input <in-if> <proto> <src-ip> <src-port> <dst-ip> <dst-port> detailed` simulates a packet and shows every phase — ACL check, NAT, route lookup — ending in ALLOW or DROP with the exact reason. It's the first tool I reach for on any ASA issue.
❓ FirePOWER کیا ہے اور ASA میں کیا add کرتا ہے؟FirePOWER kya hai aur ASA mein kya add karta hai?What is FirePOWER and what does it add to the ASA?
FirePOWER (SFR module) ASA میں next-gen IPS، URL filtering اور advanced malware protection add کرتا ہے؛ traffic MPF `sfr` action سے اس کی طرف redirect ہوتا ہے۔ یہ stateful ASA کو next-generation firewall بناتا ہے۔FirePOWER (SFR module) ASA mein next-gen IPS, URL filtering aur advanced malware protection add karta hai; traffic MPF `sfr` action se uski taraf redirect hota hai. Ye stateful ASA ko next-generation firewall banata hai.FirePOWER (SFR module) adds next-gen IPS, URL filtering, and advanced malware protection to the ASA; traffic is redirected to it with an MPF `sfr` action. It turns the stateful ASA into a next-generation firewall.
❓ ایک user ASA سے server تک نہیں پہنچ سکتا — troubleshoot کیسے کریں گے؟Ek user ASA se server tak nahi pahunch sakta — troubleshoot kaise karo ge?A user can't reach a server through the ASA — how do you troubleshoot?
میرا method: failing flow کو packet-tracer کریں dropping phase ڈھونڈنے کے لیے، اس feature کو check کریں (`show access-list` hits، `show nat`/`show xlate`، `show route`)، exact event ID کے لیے `show logging` پڑھیں، ایک وقت میں ایک layer fix کریں، اور دوبارہ trace کریں۔ Common culprits: missing `access-group`، NAT rule order، اور بھولا ہوا `write memory`۔Mera method: failing flow ko packet-tracer karo dropping phase dhoondne ke liye, us feature ko check karo (`show access-list` hits, `show nat`/`show xlate`, `show route`), exact event ID ke liye `show logging` parho, ek waqt mein ek layer fix karo, aur dobara trace karo. Common culprits: missing `access-group`, NAT rule order, aur bhoola hua `write memory`.My method: packet-tracer the failing flow to find the dropping phase, check that feature (`show access-list` hits, `show nat`/`show xlate`, `show route`), read `show logging` for the exact event ID, fix one layer at a time, and re-trace. Common culprits: missing `access-group`, NAT rule order, and forgotten `write memory`.