📝 Section Review: Access Control
اہم نکاتKey TakeawaysKey Takeaways
- ACL کچھ نہیں کرتی جب تک `access-group ... in|out` سے interface پر bind نہ ہو۔ACL kuch nahi karti jab tak `access-group ... in|out` se interface par bind na ho.An ACL does nothing until bound to an interface with `access-group ... in|out`.
- ASA ACLs کو top-down evaluate کرتا ہے؛ پہلی matching line جیتتی ہے، اور ہر ACL implicit deny پر ختم ہوتی ہے۔ASA ACLs ko top-down evaluate karta hai; pehli matching line jeet ti hai, aur har ACL implicit deny par khatam hoti hai.ASA evaluates ACLs top-down; the first matching line wins, and an implicit deny ends every ACL.
- Object groups policies کو short رکھتے ہیں: ایک line درجنوں servers یا ports cover کر سکتی ہے۔Object groups policies ko short rakhte hain: ek line darjanon servers ya ports cover kar sakti hai.Object groups keep policies short: one line can cover dozens of servers or ports.
- `show access-list` میں hit counts prove کرتے ہیں real traffic کن rules سے match ہو رہا ہے۔`show access-list` mein hit counts prove karte hain real traffic kin rules se match ho raha hai.Hit counts in `show access-list` prove which rules real traffic is matching.
- Direction matter کرتی ہے: outside پر 'in' کا مطلب internet سے داخل ہونے والا traffic۔Direction matter karti hai: outside par 'in' ka matlab internet se dakhil hone wala traffic.Direction matters: 'in' on outside means traffic entering from the internet.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ ASA پر extended vs standard ACL؟ASA par extended vs standard ACL?Extended vs standard ACL on the ASA?
Extended ACLs source/destination IP، protocol اور ports match کرتی ہیں، اور ہر interface پر ہر direction میں apply ہوتی ہیں۔ Standard ACLs صرف source IP match کرتی ہیں اور ASA پر rarely use ہوتی ہیں۔Extended ACLs source/destination IP, protocol aur ports match karti hain, aur har interface par har direction mein apply hoti hain. Standard ACLs sirf source IP match karti hain aur ASA par rarely use hoti hain.Extended ACLs match source/destination IP, protocol, and ports, and are applied per interface per direction. Standard ACLs match only source IP and are rarely used on ASA.
❓ Object groups کیوں use کرتے ہیں؟Object groups kyun use karte hain?Why use object groups?
Object groups IPs/subnets (network) یا protocols/ports (service) کو ایک نام کے نیچے bundle کرتے ہیں، تاکہ ایک ACL line کئی hosts یا services cover کرے۔ Edits تمام referencing ACLs پر فوراً apply ہوتی ہیں۔Object groups IPs/subnets (network) ya protocols/ports (service) ko ek naam ke neeche bundle karte hain, taake ek ACL line kayi hosts ya services cover kare. Edits tamam referencing ACLs par foran apply hoti hain.Object groups bundle IPs/subnets (network) or protocols/ports (service) under one name, so a single ACL line covers many hosts or services. Edits apply instantly to all referencing ACLs.
❓ Traffic unexpectedly deny ہو رہا ہے — کیا check کریں گے؟Traffic unexpectedly deny ho raha hai — kya check karo ge?Traffic is denied unexpectedly — what do you check?
`show run access-group` check کریں (applied ہے؟ direction صحیح؟)، line order (پہلا match جیتتا ہے)، اور `show access-list` hit counts سے دیکھیں traffic کس line پر لگ رہا ہے۔`show run access-group` check karo (applied hai? direction sahi?), line order (pehla match jeet ta hai), aur `show access-list` hit counts se dekho traffic kis line par lag raha hai.Check `show run access-group` (is it applied, correct direction?), line order (first match wins), and `show access-list` hit counts to see which line the traffic hits.