📝 Section Review: VPNs
اہم نکاتKey TakeawaysKey Takeaways
- Site-to-site VPNs کو mirror-image configs چاہیے: crypto ACLs swapped، دونوں peers پر identical PSKs اور proposals۔Site-to-site VPNs ko mirror-image configs chahiye: crypto ACLs swapped, dono peers par identical PSKs aur proposals.Site-to-site VPNs need mirror-image configs: crypto ACLs swapped, identical PSKs and proposals on both peers.
- NAT exemption (identity twice-NAT) mandatory ہے — NAT ہوا VPN traffic tunnel توڑ دیتا ہے۔NAT exemption (identity twice-NAT) mandatory hai — NAT hua VPN traffic tunnel tor deta hai.NAT exemption (identity twice-NAT) is mandatory — NATed VPN traffic breaks the tunnel.
- Phase 1 failure = policy/PSK/connectivity problem؛ Phase 2 failure = crypto ACL یا proposal mismatch۔Phase 1 failure = policy/PSK/connectivity problem; Phase 2 failure = crypto ACL ya proposal mismatch.Phase 1 failure = policy/PSK/connectivity problem; Phase 2 failure = crypto ACL or proposal mismatch.
- AnyConnect group policies user experience control کرتی ہیں: pools، DNS، split tunnel، timeouts۔AnyConnect group policies user experience control karti hain: pools, DNS, split tunnel, timeouts.AnyConnect group policies control the user experience: pools, DNS, split tunnel, timeouts.
- Split tunnel (bandwidth-friendly) vs tunnel-all (most secure) ایک deliberate design trade-off ہے۔Split tunnel (bandwidth-friendly) vs tunnel-all (most secure) ek deliberate design trade-off hai.Split tunnel (bandwidth-friendly) vs tunnel-all (most secure) is a deliberate design trade-off.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ IKEv2 site-to-site VPN کے building blocks list کریں۔IKEv2 site-to-site VPN ke building blocks list karo.List the building blocks of an IKEv2 site-to-site VPN.
IKEv2 policy (encryption/integrity/DH group)، IPsec proposal (ESP transform)، crypto ACL (interesting traffic)، crypto map (ACL + peer + proposal bind، outside پر applied)، matching PSKs والا tunnel-group، outside پر IKEv2 enabled، VPN traffic کے لیے NAT exemption۔IKEv2 policy (encryption/integrity/DH group), IPsec proposal (ESP transform), crypto ACL (interesting traffic), crypto map (ACL + peer + proposal bind, outside par applied), matching PSKs wala tunnel-group, outside par IKEv2 enabled, VPN traffic ke liye NAT exemption.IKEv2 policy (encryption/integrity/DH group), IPsec proposal (ESP transform), crypto ACL (interesting traffic), crypto map (bind ACL + peer + proposal, applied to outside), tunnel-group with matching PSKs, IKEv2 enabled on outside, NAT exemption for VPN traffic.
❓ Phase 1 vs Phase 2؟Phase 1 vs Phase 2?Phase 1 vs Phase 2?
Phase 1 peers کے درمیان secure IKE channel بناتا ہے (`show crypto ikev2 sa`)؛ Phase 2 child SAs negotiate کرتا ہے جو user traffic encrypt کرتے ہیں (`show crypto ipsec sa`)۔Phase 1 peers ke darmiyan secure IKE channel banata hai (`show crypto ikev2 sa`); Phase 2 child SAs negotiate karta hai jo user traffic encrypt karte hain (`show crypto ipsec sa`).Phase 1 builds the secure IKE channel between peers (`show crypto ikev2 sa`); Phase 2 negotiates the child SAs that encrypt user traffic (`show crypto ipsec sa`).
❓ AnyConnect remote-access VPN: key components اور SSL/TLS کیوں؟AnyConnect remote-access VPN: key components aur SSL/TLS kyun?AnyConnect remote-access VPN: key components and why SSL/TLS?
Login پر select ہونے والا connection profile (tunnel group)، authentication method، group policy (IP pool، DNS، timeouts، split tunnel)، client addresses کے لیے `ip local pool`، اور outside interface پر enabled `webvpn`۔ SSL/TLS ان firewalls سے گزر جاتا ہے جو IPsec block کرتے ہیں۔Login par select hone wala connection profile (tunnel group), authentication method, group policy (IP pool, DNS, timeouts, split tunnel), client addresses ke liye `ip local pool`, aur outside interface par enabled `webvpn`. SSL/TLS un firewalls se guzar jata hai jo IPsec block karte hain.Connection profile (tunnel group) selected at login, authentication method, group policy (IP pool, DNS, timeouts, split tunnel), `ip local pool` for client addresses, and `webvpn` enabled on the outside interface. SSL/TLS passes through firewalls that block IPsec.