📝 Section Review: AAA & Management

اہم نکاتKey TakeawaysKey Takeaways

خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)

یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.

❓ AAA کیا ہے اور ASA logins پر کیسے apply ہوتا ہے؟AAA kya hai aur ASA logins par kaise apply hota hai?What is AAA and how is it applied to ASA logins?

Authentication (تم کون ہو)، Authorization (تم کیا کر سکتے ہو)، Accounting (تم نے کیا کیا)۔ ASA پر `aaa authentication ssh console LOCAL` وغیرہ logins کو local user database کی طرف point کرتے ہیں۔Authentication (tum kaun ho), Authorization (tum kya kar sakte ho), Accounting (tumne kya kiya). ASA par `aaa authentication ssh console LOCAL` waghera logins ko local user database ki taraf point karte hain.Authentication (who are you), Authorization (what may you do), Accounting (what did you do). On ASA, `aaa authentication ssh console LOCAL` etc. point logins at the local user database.

❓ Privilege 15 vs lower privilege levels؟Privilege 15 vs lower privilege levels?Privilege 15 vs lower privilege levels?

Privilege 15 = full admin (direct enable mode)۔ Lower levels (جیسے 5) کو restricted command set ملتا ہے — read-only operators کے لیے اچھا؛ `privilege ... level` commands سے extend کریں۔Privilege 15 = full admin (direct enable mode). Lower levels (jaise 5) ko restricted command set milta hai — read-only operators ke liye acha; `privilege ... level` commands se extend karo.Privilege 15 = full admin (straight to enable mode). Lower levels (e.g. 5) get a restricted command set — good for read-only operators; extend with `privilege ... level` commands.

❓ ASA management access کو کیسے lock down کرتے ہیں؟ASA management access ko kaise lock down karte ho?How do you lock down ASA management access?

`ssh <trusted-subnet> <mask> <if-name>` / `http ...` سے restrict کریں تاکہ صرف management network allowed ہو؛ outside interface پر SSH/HTTPS کبھی enable مت کریں؛ SSHv2 اور short idle timeouts use کریں۔`ssh <trusted-subnet> <mask> <if-name>` / `http ...` se restrict karo taake sirf management network allowed ho; outside interface par SSH/HTTPS kabhi enable mat karo; SSHv2 aur short idle timeouts use karo.Restrict with `ssh <trusted-subnet> <mask> <if-name>` / `http ...` so only the management network is allowed; never enable SSH/HTTPS on the outside interface; use SSHv2 and short idle timeouts.