🎤 AWS Networking — Interview Q&A

❓ VPC کیا ہے؟VPC kya hai?What is a VPC?

VPC AWS میں آپ کا isolated ورچوئل نیٹ ورک ہے۔ یہ ایک ریجن میں ہوتا ہے اور سب نیٹس رکھتا ہے، ہر سب نیٹ ایک ایویلیبلٹی زون میں۔VPC AWS mein aap ka isolated virtual network hai. Yeh ek region mein hota hai aur subnets rakhta hai, har subnet ek Availability Zone mein.A VPC is your isolated virtual network in AWS. It spans a region and holds subnets, each subnet living in one Availability Zone.

❓ سیکیورٹی گروپ بمقابلہ NACL؟Security Group vs NACL?Security Group vs NACL?

سیکیورٹی گروپ stateful ہوتا ہے اور انسٹنس لیول پر لگتا ہے (صرف ALLOW)۔ NACL stateless ہوتا ہے، سب نیٹ لیول پر لگتا ہے، اور ALLOW اور DENY دونوں سپورٹ کرتا ہے۔Security Group stateful hota hai aur instance level par lagta hai (sirf ALLOW). NACL stateless hota hai, subnet level par lagta hai, aur ALLOW aur DENY dono support karta hai.A Security Group is stateful and sits at the instance level (ALLOW only). A NACL is stateless, sits at the subnet level, and supports ALLOW and DENY.

❓ NAT گیٹ وے کیا ہے اور کیسے کام کرتا ہے؟NAT Gateway kya hai aur kaise kaam karta hai?What is a NAT Gateway and how does it work?

NAT گیٹ وے پرائیویٹ سب نیٹس کو آؤٹ باؤنڈ-اونلی انٹرنیٹ رسائی دیتا ہے۔ یہ پبلک سب نیٹ میں بنتا ہے Elastic IP کے ساتھ، اور پرائیویٹ روٹ ٹیبل میں 0.0.0.0/0 اس کی طرف لگتا ہے۔NAT Gateway private subnets ko outbound-only internet access deta hai. Yeh public subnet mein banta hai Elastic IP ke saath, aur private route table mein 0.0.0.0/0 is ki taraf lagta hai.A NAT Gateway gives private subnets outbound-only internet access. It lives in a public subnet with an Elastic IP, and the private route table points 0.0.0.0/0 at it.

❓ VPC peering بمقابلہ Transit Gateway؟VPC peering vs Transit Gateway?VPC peering vs Transit Gateway?

Peering دو VPCs کے درمیان آسان مفت سیدھا لنک ہے، مگر transitive نہیں۔ Transit Gateway بہت سے VPCs اور آن پریمیسس نیٹ ورکس کے لیے مرکزی ہب ہے — جب peering میش بن جائے تو اسے استعمال کریں۔Peering do VPCs ke darmiyan aasaan muft seedha link hai, magar transitive nahi. Transit Gateway buhat se VPCs aur on-premises networks ke liye central hub hai — jab peering mesh ban jaye to isay istemaal karein.Peering is a simple free direct link between two VPCs, but not transitive. Transit Gateway is a central hub for many VPCs and on-premises networks — use it when peering becomes a mesh.

❓ ALB بمقابلہ NLB — ویب ایپ کے لیے کون سا چنیں گے؟ALB vs NLB — web app ke liye kaun sa choose karenge?ALB vs NLB — which do you pick for a web app?

ALB لیئر 7 (HTTP/HTTPS) پر کام کرتا ہے path اور host based routing کے ساتھ — ویب ایپس کے لیے بہترین۔ NLB لیئر 4 (TCP/UDP) پر ہے، ultra fast ہے اور static IP addresses رکھتا ہے۔ALB layer 7 (HTTP/HTTPS) par kaam karta hai path aur host based routing ke saath — web apps ke liye behtreen. NLB layer 4 (TCP/UDP) par hai, ultra fast hai aur static IP addresses rakhta hai.ALB works at layer 7 (HTTP/HTTPS) with path and host-based routing — best for web apps. NLB works at layer 4 (TCP/UDP), is ultra-fast, and keeps static IP addresses.

❓ VPC Flow Logs کیا بتاتے ہیں؟VPC Flow Logs kya batatay hain?What do VPC Flow Logs tell you?

Flow Logs VPC/subnet/ENI لیول پر نیٹ ورک ٹریفک ریکارڈ کرتے ہیں — source، destination، پورٹس اور ACCEPT/REJECT۔ یہ بتاتے ہیں کہ کون سے سیکیورٹی گروپ یا NACL رول نے ٹریفک روکی۔Flow Logs VPC/subnet/ENI level par network traffic record kartay hain — source, destination, ports aur ACCEPT/REJECT. Yeh batatay hain ke kaun se security group ya NACL rule ne traffic roki.Flow Logs record network traffic at the VPC/subnet/ENI level — source, destination, ports, and ACCEPT/REJECT. They reveal which security group or NACL rule blocked traffic.

❓ EC2 انسٹنس دوسرے انسٹنس تک نہیں پہنچتا — ٹربل شوٹ کیسے کریں گے؟EC2 instance doosre instance tak nahi pahunchta — troubleshoot kaise karenge?An EC2 instance cannot reach another instance — how do you troubleshoot?

Endpoint سے شروع کریں: پہلے روٹ ٹیبل، پھر سیکیورٹی گروپ، پھر NACL چیک کریں۔ REJECTs دیکھنے کے لیے Flow Logs اور exact blocking hop کے لیے Reachability Analyzer استعمال کریں۔Endpoint se shuru karein: pehle route table, phir security group, phir NACL check karein. REJECTs dekhnay ke liye Flow Logs aur exact blocking hop ke liye Reachability Analyzer istemaal karein.Start from the endpoint: check the route table, then the security group, then the NACL. Use Flow Logs to see REJECTs and Reachability Analyzer to find the exact blocking hop.