Network Security Groups & Azure Firewall
Microsoft Azure Networking (AZ-700 track) Azure portal — free tier (GUI + CLI)
مقصدObjectiveObjective
NSG inbound rules سے ٹریفک کنٹرول کرنا اور Azure Firewall tiers اور policies کو سمجھنا۔NSG inbound rules se traffic control karna aur Azure Firewall tiers aur policies ko samajhna.Control traffic with NSG inbound rules and understand Azure Firewall tiers and policies.
آسان مثالSimple AnalogySimple Analogy
NSG سوسائٹی کا گیٹ کیپر ہے جس کے پاس رول بک ہے — کون اندر آ سکتا ہے، کس گلی میں، کس وقت۔ Azure Firewall سیکیورٹی ایجنسی ہے جو ہر گاڑی کی ڈگی اور کاغذات بھی چیک کرتی ہے (deep packet inspection)۔NSG society ka gatekeeper hai jiske paas rulebook hai — kaun andar aa sakta hai, kis gali mein, kis waqt. Azure Firewall security agency hai jo har gari ka diggi aur kagzat bhi check karti hai (deep packet inspection).An NSG is like the society's gatekeeper with a rulebook — who can enter, on which street, at what time. Azure Firewall is the security agency that also checks every car's trunk and papers (deep packet inspection).
سیٹ اپLab SetupLab Setup
پچھلی lessons سے rg-netsec-lab اور vnet-core استعمال کریں۔ تمام ریسورسز Southeast Asia میں رہیں گے۔Pichli lessons se rg-netsec-lab aur vnet-core use karein. Tamam resources Southeast Asia mein rahein ge.Use rg-netsec-lab and vnet-core from the previous lessons. All resources stay in Southeast Asia.
اقداماتStepsSteps
Step 1
nsg-web نام کا Network Security Group بنائیں۔ NSG میں allow/deny security rules کی فہرست ہوتی ہے۔nsg-web naam ka Network Security Group banayein. NSG mein allow/deny security rules ki list hoti hai.Create a Network Security Group named nsg-web. An NSG holds a list of allow/deny security rules.
az network nsg create --resource-group rg-netsec-lab --name nsg-web
🖱️ Network security groups > Create — نام nsg-webNetwork security groups > Create — naam nsg-webNetwork security groups > Create — name nsg-web
Step 2
ایک inbound rule شامل کریں: Internet سے subnet 10.1.1.0/24 پر TCP port 80 allow، priority 100۔ چھوٹا priority number مطلب پہلے evaluate ہوگی۔Ek inbound rule add karein: Internet se subnet 10.1.1.0/24 par TCP port 80 allow, priority 100. Chota priority number matlab pehle evaluate hogi.Add an inbound rule: allow TCP port 80 from the Internet to subnet 10.1.1.0/24, priority 100. Lower priority number means evaluated first.
az network nsg rule create --resource-group rg-netsec-lab --nsg-name nsg-web --name Allow-HTTP --priority 100 --destination-port-ranges 80 --access Allow --protocol Tcp --direction Inbound --source-address-prefixes Internet --destination-address-prefixes 10.1.1.0/24
🖱️ Network security groups > nsg-web > Inbound security rules > Add — priority 100، TCP 80 from Internet allowNetwork security groups > nsg-web > Inbound security rules > Add — priority 100, TCP 80 from Internet allowNetwork security groups > nsg-web > Inbound security rules > Add — priority 100, allow TCP 80 from Internet
Step 3
ایک deny rule شامل کریں: web subnet سے DB subnet پر TCP 1433 (SQL) بلاک، priority 200۔ اس سے web tier database تک براہ راست نہیں پہنچ سکتا۔Ek deny rule add karein: web subnet se DB subnet par TCP 1433 (SQL) block, priority 200. Is se web tier database tak direct nahi pahunch sakta.Add a deny rule: block TCP 1433 (SQL) from the web subnet to the DB subnet, priority 200. This stops the web tier from reaching the database directly.
az network nsg rule create --resource-group rg-netsec-lab --nsg-name nsg-web --name Deny-SQL-From-Web --priority 200 --destination-port-ranges 1433 --access Deny --protocol Tcp --direction Inbound --source-address-prefixes 10.1.1.0/24 --destination-address-prefixes 10.1.3.0/24
🖱️ Inbound security rules > Add — priority 200، TCP 1433 from 10.1.1.0/24 to 10.1.3.0/24 denyInbound security rules > Add — priority 200, TCP 1433 from 10.1.1.0/24 to 10.1.3.0/24 denyInbound security rules > Add — priority 200, deny TCP 1433 from 10.1.1.0/24 to 10.1.3.0/24
Step 4
NSG کو subnet snet-web سے attach کریں۔ NSG subnet یا VM کے network interface سے attach ہو سکتا ہے۔NSG ko subnet snet-web se attach karein. NSG subnet ya VM ke network interface se attach ho sakta hai.Attach the NSG to subnet snet-web. An NSG can attach to a subnet or to a VM network interface.
az network vnet subnet update --resource-group rg-netsec-lab --vnet-name vnet-core --name snet-web --network-security-group nsg-web
🖱️ Virtual networks > vnet-core > Subnets > snet-web > Network security group = nsg-webVirtual networks > vnet-core > Subnets > snet-web > Network security group = nsg-webVirtual networks > vnet-core > Subnets > snet-web > Network security group = nsg-web
Step 5
تصدیق کریں کہ rules priority order میں ہیں: Allow-HTTP (100)، Deny-SQL-From-Web (200)، پھر default rules۔ Default rules باقی تمام inbound traffic deny کرتی ہیں۔Verify karein ke rules priority order mein hain: Allow-HTTP (100), Deny-SQL-From-Web (200), phir default rules. Default rules baqi tamam inbound traffic deny karti hain.Verify the rules are listed in priority order: Allow-HTTP (100), Deny-SQL-From-Web (200), then the default rules. Default rules deny all other inbound traffic.
az network nsg rule list --resource-group rg-netsec-lab --nsg-name nsg-web --output table
🖱️ Network security groups > nsg-web > Inbound security rules — rule order verify کریںNetwork security groups > nsg-web > Inbound security rules — rule order verify kareinNetwork security groups > nsg-web > Inbound security rules — verify rule order
Step 6
Firewall Manager کھولیں اور Firewall Policy explore کریں: network rules (IP/port)، application rules (FQDN)، اور NAT rules۔ Standard بمقابلہ Premium tier کا فرق نوٹ کریں — صرف concepts، deploy نہ کریں (لاگت ہوتی ہے)۔Firewall Manager kholein aur Firewall Policy explore karein: network rules (IP/port), application rules (FQDN), aur NAT rules. Standard vs Premium tier ka farq note karein — sirf concepts, deploy na karein (cost hoti hai).Open Firewall Manager and explore a Firewall Policy: network rules (IP/port), application rules (FQDN), and NAT rules. Note Standard vs Premium tier differences — concepts only, do not deploy (costs money).
🖱️ Firewall Manager > Create a firewall policy > Application rules — Standard بمقابلہ Premium tier features کا موازنہ کریںFirewall Manager > Create a firewall policy > Application rules — Standard vs Premium tier features compare kareinFirewall Manager > Create a firewall policy > Application rules — compare Standard vs Premium tier features
Step 7
vnet-core میں AzureFirewallSubnet نام کی dedicated subnet (10.1.0.0/26) بنائیں۔ Azure Firewall کو یہ exact نام چاہیے — انٹرویو کے لیے یاد رکھیں۔vnet-core mein AzureFirewallSubnet naam ki dedicated subnet (10.1.0.0/26) banayein. Azure Firewall ko yeh exact naam chahiye — interview ke liye yaad rakhein.Create a dedicated subnet named exactly AzureFirewallSubnet (10.1.0.0/26) in vnet-core. Azure Firewall requires this exact name — remember it for interviews.
🖱️ Virtual networks > vnet-core > Subnets > + Subnet — AzureFirewallSubnet 10.1.0.0/26 بنائیںVirtual networks > vnet-core > Subnets > + Subnet — AzureFirewallSubnet 10.1.0.0/26 banayeinVirtual networks > vnet-core > Subnets > + Subnet — create AzureFirewallSubnet 10.1.0.0/26
تصدیقVerifyVerify
nsg-web snet-web سے attach ہے priority order میں rules کے ساتھ، اور future firewall deployment کے لیے AzureFirewallSubnet موجود ہے۔nsg-web snet-web se attach hai priority order mein rules ke saath, aur future firewall deployment ke liye AzureFirewallSubnet maujood hai.nsg-web is attached to snet-web with rules in priority order, and the AzureFirewallSubnet exists for a future firewall deployment.
az network vnet subnet show --resource-group rg-netsec-lab --vnet-name vnet-core --name snet-web --query networkSecurityGroup.id
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ Rule expected طریقے سے کام نہیں کر رہی — ٹریفک اب بھی بلاکڈRule expected tarike se kaam nahi kar rahi — traffic ab bhi blockedRule not working as expected — traffic still blocked
✅ Rule priorities چیک کریں: higher-priority (کم نمبر) Deny پہلے match ہو سکتی ہے۔ تصدیق کریں کہ NSG صحیح subnet یا NIC سے attach ہے۔Rule priorities check karein: higher-priority (kam number) Deny pehle match ho sakti hai. Tasdeeq karein ke NSG sahi subnet ya NIC se attach hai.Check rule priorities: a higher-priority (lower number) Deny may match first. Also confirm the NSG is attached to the right subnet or NIC.
⚠️ Default rules custom deny سے ٹکراتی ہیںDefault rules custom deny se takrati hainDefault rules conflict with custom deny
✅ Defaults (priority 65000+) سب سے آخر میں evaluate ہوتی ہیں، اس لیے custom rules ہمیشہ جیتتی ہیں۔ کبھی صرف defaults پر بھروسا نہ کریں — ضروری ٹریفک کے لیے explicit allow rules لکھیں۔Defaults (priority 65000+) sab se aakhir mein evaluate hoti hain, is liye custom rules hamesha jeet-ti hain. Kabhi sirf defaults par bharosa na karein — zaroori traffic ke liye explicit allow rules likhein.Defaults (priority 65000+) are evaluated last, so custom rules always win. Never rely on defaults alone — write explicit allow rules for needed traffic.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ NSG اور Azure Firewall میں کیا فرق ہے؟NSG aur Azure Firewall mein kya farq hai?What is the difference between an NSG and Azure Firewall?
NSG Layer 3–4 پر ٹریفک فلٹر کرتا ہے — IPs، ports اور protocols پر allow/deny rules کے ساتھ — یہ سستا اور تیز ہے۔ Azure Firewall managed، stateful Layer 7 firewall ہے جس میں FQDN filtering، threat intelligence اور TLS inspection ہوتی ہے۔NSG Layer 3–4 par traffic filter karta hai — IPs, ports aur protocols par allow/deny rules ke saath — yeh sasta aur tez hai. Azure Firewall managed, stateful Layer 7 firewall hai jismein FQDN filtering, threat intelligence aur TLS inspection hoti hai.An NSG filters traffic at Layers 3–4 with allow/deny rules on IPs, ports, and protocols — it is cheap and fast. Azure Firewall is a managed, stateful Layer 7 firewall with FQDN filtering, threat intelligence, and TLS inspection.
❓ NSG rules کیسے evaluate ہوتی ہیں؟NSG rules kaise evaluate hoti hain?How are NSG rules evaluated?
Rules priority number کے حساب سے evaluate ہوتی ہیں، سب سے کم نمبر پہلے۔ پہلی matching rule لاگو ہوتی ہے۔ Rules stateful ہوتی ہیں — return traffic خود بخود allow ہو جاتا ہے۔Rules priority number ke hisab se evaluate hoti hain, sab se kam number pehle. Pehli matching rule lagoo hoti hai. Rules stateful hoti hain — return traffic khud-b-khud allow ho jata hai.Rules are evaluated by priority number, lowest first. The first matching rule wins. Rules are stateful — return traffic is automatically allowed.