AWS Network Monitoring & Troubleshooting
AWS Networking (ANS-C01 track) AWS console — free tier (GUI + CLI)
مقصدObjectiveObjective
VPC Flow Logs آن کرنا، CloudWatch میں ان کا جائزہ لینا، اور Reachability Analyzer سے ایک connectivity مسئلے کی تشخیص کرنا۔VPC Flow Logs on karna, CloudWatch mein un ka jaiza lena, aur Reachability Analyzer se ek connectivity problem ki diagnosis karna.Turn on VPC Flow Logs, explore them in CloudWatch, and use Reachability Analyzer to diagnose a connectivity problem.
آسان مثالSimple AnalogySimple Analogy
VPC Flow Logs آپ کے نیٹ ورک کے CCTV کیمرے ہیں — ریکارڈ کرتے ہیں کہ کون آیا کون گیا۔ CloudWatch وہ watch room ہے جہاں سب کیمرے دیکھے جاتے ہیں۔ Reachability Analyzer وہ ماہر ہے جو کال ناکام ہونے پر دونوں دروازوں کے درمیان راستہ قدم بہ قدم trace کرتا ہے۔VPC Flow Logs aap ke network ke CCTV camray hain — record karte hain ke kaun aaya kaun gaya. CloudWatch woh watch room hai jahan sab camray dekhe jatay hain. Reachability Analyzer woh expert hai jo call fail honay par dono darwazon ke darmiyan rasta qadam ba qadam trace karta hai.VPC Flow Logs are the CCTV cameras of your network — they record who came and went. CloudWatch is the watch room where all cameras are watched. Reachability Analyzer is the expert who traces the road between two doors step by step when a call fails.
سیٹ اپLab SetupLab Setup
پچھلے سبقوں سے LabVPC اور چلتے وسائل موجود ہوں۔ Flow Logs کو ایک IAM role چاہیے جو CloudWatch Logs میں لکھنے کی اجازت دے۔Pichlay lessons se LabVPC aur chaltay resources maujood hon. Flow Logs ko ek IAM role chahiye jo CloudWatch Logs mein likhnay ki ijazat de.You need the LabVPC with the running resources from earlier lessons. Flow Logs need an IAM role that allows publishing to CloudWatch Logs.
اقداماتStepsSteps
Step 1
LabVPC پر flow log بنائیں جس کا Filter All ہو (ACCEPT اور REJECT دونوں ریکارڈ ہوں گے)۔ Log ڈیٹا آنے میں چند منٹ لگتے ہیں۔LabVPC par flow log banayein jis ka Filter All ho (ACCEPT aur REJECT dono record hon ge). Log data anay mein chand minute lagtay hain.Create a flow log on LabVPC with Filter = All (records ACCEPT and REJECT). It takes a few minutes before log data starts appearing.
aws ec2 create-flow-logs --resource-type VPC --resource-ids vpc-0123456789abcdef0 --traffic-type ALL --log-group-name vpc-flow-logs-lab --deliver-logs-permission-arn arn:aws:iam::123456789012:role/flowlogsRole --tag-specifications 'ResourceType=vpc-flow-log,Tags=[{Key=Name,Value=LabFlowLog}]'🖱️ VPC > Your VPCs > LabVPC منتخب کریں > Flow logs tab > Create flow log > نام LabFlowLog، Filter: All، Destination: CloudWatch Logs، Log group: vpc-flow-logs-lab > CreateVPC > Your VPCs > LabVPC select karein > Flow logs tab > Create flow log > Name LabFlowLog, Filter: All, Destination: CloudWatch Logs, Log group: vpc-flow-logs-lab > CreateVPC > Your VPCs > select LabVPC > Flow logs tab > Create flow log > Name LabFlowLog, Filter: All, Destination: CloudWatch Logs, Log group: vpc-flow-logs-lab > Create
Step 2
CloudWatch میں flow log stream کھولیں۔ ہر لائن میں version، account، interface، source، destination، پورٹس، packets، action (ACCEPT/REJECT) اور status دکھائی دے گا۔CloudWatch mein flow log stream kholein. Har line mein version, account, interface, source, destination, ports, packets, action (ACCEPT/REJECT) aur status dikhai de ga.In CloudWatch, open the flow log stream. Each line shows version, account, interface, source, destination, ports, packets, action (ACCEPT/REJECT), and status.
🖱️ CloudWatch > Logs > Log groups > vpc-flow-logs-lab > Log streams — نئی stream کھولیںCloudWatch > Logs > Log groups > vpc-flow-logs-lab > Log streams — nayi stream kholeinCloudWatch > Logs > Log groups > vpc-flow-logs-lab > Log streams — open the newest stream
Step 3
Logs Insights میں REJECT actions فلٹر کریں۔ Rejected پیکٹس عام طور پر مطلب ہیں کہ سیکیورٹی گروپ یا NACL رول نے ٹریفک روک دی۔Logs Insights mein REJECT actions filter karein. Rejected packets aam taur par matlab hain ke security group ya NACL rule ne traffic rok di.Use Logs Insights to filter for REJECT actions. Rejected packets usually mean a security group or NACL rule blocked the traffic.
aws logs start-query --log-group-name vpc-flow-logs-lab --start-time $(($(date +%s) - 3600)) --end-time $(date +%s) --query-string "fields @timestamp, srcAddr, dstAddr, dstPort, action | filter action = 'REJECT' | sort @timestamp desc | limit 20"
🖱️ CloudWatch > Logs Insights > vpc-flow-logs-lab منتخب کریں > REJECT فلٹر والی query پیسٹ کریں > Run queryCloudWatch > Logs Insights > vpc-flow-logs-lab select karein > REJECT filter wali query paste karein > Run queryCloudWatch > Logs Insights > select vpc-flow-logs-lab > paste query to filter REJECTs > Run query
Step 4
دو انسٹنسز کے درمیان پورٹ 80 پر Reachability Analyzer چلائیں۔ یہ ہر hop (ENI، سیکیورٹی گروپ، روٹ، NACL) دکھاتا ہے اور بتاتا ہے کہ ٹریفک بالکل کہاں رک رہی ہے۔Do instances ke darmiyan port 80 par Reachability Analyzer chalayein. Yeh har hop (ENI, security group, route, NACL) dikhata hai aur batata hai ke traffic bilkul kahan ruk rahi hai.Run Reachability Analyzer between two instances on port 80. It shows each hop (ENI, security group, route, NACL) and tells you exactly where traffic stops.
aws ec2 create-network-insights-path --source i-0123456789abcdef0 --destination i-0987654321fedcba0 --protocol TCP --destination-port 80 --tag-specifications 'ResourceType=network-insights-path,Tags=[{Key=Name,Value=LabPath}]'🖱️ VPC > Reachability Analyzer > Create and analyze path > Source: آپ کا EC2 انسٹنس، Destination: دوسرا انسٹنس، Protocol TCP، Port 80 > Create and analyze pathVPC > Reachability Analyzer > Create and analyze path > Source: aap ka EC2 instance, Destination: doosra instance, Protocol TCP, Port 80 > Create and analyze pathVPC > Reachability Analyzer > Create and analyze path > Source: your EC2 instance, Destination: the other instance, Protocol TCP, Port 80 > Create and analyze path
Step 5
Forward path کا نتیجہ پڑھیں: سبز مطلب reachable، اور جو بھی component سرخ ہو وہی رکاوٹ ہے۔ یہ یہ بھی بتاتا ہے کہ کون سا رول پیکٹ روک رہا تھا۔Forward path ka natija parhein: sabz matlab reachable, aur jo bhi component surkh ho wohi rukawat hai. Yeh yeh bhi batata hai ke kaun sa rule packet rok raha tha.Read the forward path result: green means reachable, and any red component is the blocker. It even explains which rule blocked the packet.
🖱️ VPC > Reachability Analyzer > analysis منتخب کریں > Forward pathVPC > Reachability Analyzer > analysis select karein > Forward pathVPC > Reachability Analyzer > select analysis > Forward path
Step 6
بونس مانیٹرنگ: CloudWatch metrics میں NAT گیٹ وے کی ٹریفک اور پیکٹ ڈراپس دیکھ سکتے ہیں — یہ معلوم کرنے میں مفید ہے کہ NAT گیٹ وے bottleneck تو نہیں۔Bonus monitoring: CloudWatch metrics mein NAT Gateway ki traffic aur packet drops dekh sakte hain — yeh maloom karne mein mufeed hai ke NAT Gateway bottleneck to nahi.Bonus monitoring: in CloudWatch metrics you can watch NAT Gateway traffic and packet drops — useful to see if the NAT Gateway is a bottleneck.
🖱️ CloudWatch > Metrics > NATGateway metrics > LabNAT کے BytesIn/BytesOut، PacketsDropCount دیکھیںCloudWatch > Metrics > NATGateway metrics > LabNAT ke BytesIn/BytesOut, PacketsDropCount dekheinCloudWatch > Metrics > NATGateway metrics > view BytesIn/BytesOut, PacketsDropCount for LabNAT
تصدیقVerifyVerify
Flow log Active ہو، CloudWatch میں log streams میں ACCEPT/REJECT انٹریز دکھائی دیں، اور Reachability Analyzer Reachable رپورٹ کرے forward path کے ساتھ۔Flow log Active ho, CloudWatch mein log streams mein ACCEPT/REJECT entries dikhai dein, aur Reachability Analyzer Reachable report kare forward path ke saath.The flow log is Active, CloudWatch shows log streams with ACCEPT/REJECT entries, and Reachability Analyzer reports Reachable with a visible forward path.
aws ec2 describe-flow-logs --filters Name=tag:Name,Values=LabFlowLog --query 'FlowLogs[*].[FlowLogId,FlowLogStatus]' --output table aws ec2 describe-network-insights-analyses --query 'NetworkInsightsAnalyses[0].[NetworkInsightsPathId,Status]' --output table
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ Flow log بن گیا مگر CloudWatch میں کوئی ڈیٹا نہیں آتا۔Flow log ban gaya magar CloudWatch mein koi data nahi aata.The flow log was created but no data appears in CloudWatch.
✅ Flow log پر لگی IAM role چیک کریں — اسے CloudWatch Logs میں لکھنے کی اجازت ہونی چاہیے۔ چند منٹ انتظار کریں اور پہلے کچھ ٹریفک چلائیں۔Flow log par lagi IAM role check karein — isay CloudWatch Logs mein likhnay ki ijazat honi chahiye. Chand minute intezar karein aur pehle kuch traffic chalayein.Check the IAM role attached to the flow log has permission to publish to CloudWatch Logs. Also wait a few minutes and generate some traffic first.
⚠️ Logs Insights query پر کوئی نتیجہ نہیں آتا۔Logs Insights query par koi natija nahi aata.Logs Insights returns no results for your query.
✅ تصدیق کریں کہ log group درست ہے اور time range ٹریفک کو cover کرتا ہے۔ Query syntax سخت ہوتی ہے — پہلے simple fields @timestamp query چلا کر دیکھیں۔Tasdeeq karein ke log group durust hai aur time range traffic ko cover karta hai. Query syntax sakht hoti hai — pehle simple fields @timestamp query chala kar dekhein.Confirm you selected the right log group and a time range that covers the traffic. Query syntax is strict — re-run with a simple fields @timestamp query first.
⚠️ Reachability Analyzer Not reachable کہتا ہے مگر سمجھ نہیں آتا کہ کون سا رول روک رہا ہے۔Reachability Analyzer Not reachable kehta hai magar samajh nahi aata ke kaun sa rule rok raha hai.Reachability Analyzer says Not reachable but you cannot tell which rule blocked it.
✅ Forward path کھولیں اور ہر hop expand کریں۔ جس hop پر unreachable لکھا ہو وہ exact blocking component دکھائے گا — روٹ ٹیبل، سیکیورٹی گروپ یا NACL۔Forward path kholein aur har hop expand karein. Jis hop par unreachable likha ho woh exact blocking component dikhayega — route table, security group ya NACL.Open the forward path and expand each hop. The hop marked unreachable shows the exact blocking component — route table, security group, or NACL.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ VPC Flow Logs کیا ریکارڈ کرتے ہیں اور ان کا کیا استعمال ہے؟VPC Flow Logs kya record karte hain aur in ka kya istemaal hai?What do VPC Flow Logs capture, and what do you use them for?
Flow Logs VPC، سب نیٹ یا ENI لیول پر نیٹ ورک ٹریفک کا ریکارڈ رکھتے ہیں (source/destination IPs، پورٹس، allowed یا rejected)۔ یہ CloudWatch Logs یا S3 میں محفوظ ہوتے ہیں۔ یہ سیکیورٹی گروپس اور NACLs کے REJECT دکھاتے ہیں۔Flow Logs VPC, subnet ya ENI level par network traffic ka record rakhtay hain (source/destination IPs, ports, allowed ya rejected). Yeh CloudWatch Logs ya S3 mein store hotay hain. Yeh security groups aur NACLs ke REJECT dikhatay hain.Flow Logs record network traffic (source/destination IPs, ports, allowed or rejected) at the VPC, subnet, or ENI level. They are stored in CloudWatch Logs or S3. They show REJECTs from security groups and NACLs.
❓ Flow Logs اور Reachability Analyzer میں کیا فرق ہے؟Flow Logs aur Reachability Analyzer mein kya farq hai?What is the difference between Flow Logs and Reachability Analyzer?
Flow Logs تاریخی ثبوت ہیں — بعد میں بتاتے ہیں کہ کیا reject ہوا۔ Reachability Analyzer خودکار تشخیص ہے جو دو endpoints کے درمیان راستہ ٹیسٹ کرتا ہے اور hop-by-hop بتاتا ہے کہ کہاں ٹوٹ رہا ہے۔Flow Logs tareekhi saboot hain — bad mein batatay hain ke kya reject hua. Reachability Analyzer automated diagnosis hai jo do endpoints ke darmiyan rasta test karta hai aur hop-by-hop batata hai ke kahan toot raha hai.Flow Logs are historical evidence — they tell you what was rejected after the fact. Reachability Analyzer is an automated diagnostic that tests a path between two endpoints and shows hop-by-hop where it breaks.