Azure Network Monitoring & Troubleshooting

Microsoft Azure Networking (AZ-700 track) Azure portal — free tier (GUI + CLI)

مقصدObjectiveObjective

Network Watcher enable کرنا، NSG flow logs on کرنا، اور connection troubleshoot اور packet capture tools استعمال کرنا۔Network Watcher enable karna, NSG flow logs on karna, aur connection troubleshoot aur packet capture tools use karna.Enable Network Watcher, turn on NSG flow logs, and use connection troubleshoot and packet capture tools.

آسان مثالSimple AnalogySimple Analogy

Network Watcher سوسائٹی کا CCTV کنٹرول روم ہے۔ NSG flow logs footage ہیں (کون اندر آیا، کب)، Connection Troubleshoot وہ operator ہے جو visitor کا راستہ trace کرتا ہے، اور Packet Capture ایک visit کی recorded video ہے۔Network Watcher society ka CCTV control room hai. NSG flow logs footage hain (kaun andar aaya, kab), Connection Troubleshoot woh operator hai jo visitor ka rasta trace karta hai, aur Packet Capture ek visit ki recorded video hai.Network Watcher is the society's CCTV control room. NSG flow logs are the footage (who entered, when), Connection Troubleshoot is the operator who traces a visitor's path, and Packet Capture is the recorded video of one visit.

سیٹ اپLab SetupLab Setup

rg-netsec-lab، vnet-core اور پچھلی lessons والا nsg-web استعمال کریں۔ Flow logs کے لیے اسی ریجن میں ایک storage account چاہیے۔rg-netsec-lab, vnet-core aur pichli lessons wala nsg-web use karein. Flow logs ke liye usi region mein ek storage account chahiye.Use rg-netsec-lab, vnet-core, and the nsg-web from earlier lessons. Flow logs need a storage account in the same region.

اقداماتStepsSteps

Step 1

اپنے ریجن میں Network Watcher enable کریں۔ یہ regional service ہے اور اس کے نیچے کوئی بھی tool چلانے سے پہلے enable ہونا ضروری ہے۔Apne region mein Network Watcher enable karein. Yeh regional service hai aur is ke neeche koi bhi tool chalane se pehle enable hona zaroori hai.Enable Network Watcher in your region. It is a regional service and must be enabled before any tool under it works.

az network watcher configure --resource-group rg-netsec-lab --locations southeastasia --enabled true

🖱️ Network Watcher > Overview — اپنے ریجن میں status Enabled confirm کریںNetwork Watcher > Overview — apne region mein status Enabled confirm kareinNetwork Watcher > Overview — confirm status Enabled in your region

Step 2

Flow logs رکھنے کے لیے storage account بنائیں۔ Unique نام استعمال کریں — storage account کے نام globally unique ہونے چاہئیں۔Flow logs rakhne ke liye storage account banayein. Unique naam use karein — storage account ke naam globally unique hone chahiyein.Create a storage account to hold the flow logs. Use a unique name — storage account names must be globally unique.

az storage account create --resource-group rg-netsec-lab --name stnetseclogs$RANDOM --location southeastasia --sku Standard_LRS --kind StorageV2

🖱️ Storage accounts > Create — flow log storage کے لیے Standard LRS، StorageV2Storage accounts > Create — flow log storage ke liye Standard LRS, StorageV2Storage accounts > Create — Standard LRS, StorageV2 for flow log storage

Step 3

nsg-web پر NSG flow logs enable کریں، اپنے storage account میں لکھیں۔ Flow logs NSG کے ہر connection decision کو دکھاتے ہیں۔nsg-web par NSG flow logs enable karein, apne storage account mein likhein. Flow logs NSG ke har connection decision ko dikhate hain.Enable NSG flow logs on nsg-web, writing to your storage account. Flow logs show every connection decision the NSG made.

🖱️ Network Watcher > NSG flow logs > nsg-web > Enable — اپنے storage account کی طرف point کریںNetwork Watcher > NSG flow logs > nsg-web > Enable — apne storage account ki taraf point kareinNetwork Watcher > NSG flow logs > nsg-web > Enable — point to your storage account

Step 4

Network Watcher کا Topology view کھولیں اور vnet-core select کریں۔ یہ آپ کے VNet، subnets اور connected resources کا live map بناتا ہے۔Network Watcher ka Topology view kholein aur vnet-core select karein. Yeh aap ke VNet, subnets aur connected resources ka live map banata hai.Open Network Watcher's Topology view and select vnet-core. It draws a live map of your VNet, subnets, and connected resources.

🖱️ Network Watcher > Topology — network map بنانے کے لیے vnet-core select کریںNetwork Watcher > Topology — network map banane ke liye vnet-core select kareinNetwork Watcher > Topology — select vnet-core to draw the network map

Step 5

ایک VM (یا simulated source) سے 8.8.8.8 پر TCP 443 کے لیے Connection troubleshoot چلائیں۔ یہ ہر hop — NSG rules، routes، gateways — چیک کرتا ہے اور blocker pinpoint کرتا ہے۔Ek VM (ya simulated source) se 8.8.8.8 par TCP 443 ke liye Connection troubleshoot chalayein. Yeh har hop — NSG rules, routes, gateways — check karta hai aur blocker pinpoint karta hai.Run Connection troubleshoot from a VM (or simulated source) to 8.8.8.8 on TCP 443. It walks every hop — NSG rules, routes, gateways — and pinpoints the blocker.

🖱️ Network Watcher > Connection troubleshoot — source VM، destination 8.8.8.8، port 443، TCPNetwork Watcher > Connection troubleshoot — source VM, destination 8.8.8.8, port 443, TCPNetwork Watcher > Connection troubleshoot — source VM, destination 8.8.8.8, port 443, TCP

Step 6

VM network interface پر packet capture session بنائیں، پھر .cap file ڈاؤن لوڈ کر کے Wireshark میں کھولیں۔ آپ کو rules کے پیچھے اصل packets نظر آتے ہیں۔VM network interface par packet capture session banayein, phir .cap file download karke Wireshark mein kholein. Aap ko rules ke peechay asal packets nazar aate hain.Create a packet capture session on a VM network interface, then download the .cap file and open it in Wireshark. You see the real packets behind the rules.

🖱️ Network Watcher > Packet capture — VM کے NIC پر capture بنائیںNetwork Watcher > Packet capture — VM ke NIC par capture banayeinNetwork Watcher > Packet capture — create a capture on the VM's NIC

Step 7

NSG diagnostics سے ایک flow simulate کریں (مثلاً 203.0.113.5 سے 10.1.1.4، TCP 80) nsg-web کے خلاف۔ یہ بتاتا ہے کہ کس rule نے allow یا deny کیا۔NSG diagnostics se ek flow simulate karein (masalan 203.0.113.5 se 10.1.1.4, TCP 80) nsg-web ke khilaf. Yeh batata hai ke kis rule ne allow ya deny kiya.Use NSG diagnostics to simulate a flow (e.g. 203.0.113.5 to 10.1.1.4, TCP 80) against nsg-web. It tells you which rule allowed or denied it.

🖱️ Network Watcher > NSG diagnostics — nsg-web rules کے خلاف ایک flow ٹیسٹ کریںNetwork Watcher > NSG diagnostics — nsg-web rules ke khilaf ek flow test kareinNetwork Watcher > NSG diagnostics — test a flow against nsg-web rules

تصدیقVerifyVerify

Southeast Asia میں Network Watcher enabled ہے، nsg-web کے لیے flow logs on ہیں، اور آپ نے connection troubleshoot اور packet capture کامیابی سے چلائے۔Southeast Asia mein Network Watcher enabled hai, nsg-web ke liye flow logs on hain, aur aap ne connection troubleshoot aur packet capture kamiyabi se chalaye.Network Watcher is enabled in Southeast Asia, flow logs are on for nsg-web, and you ran connection troubleshoot and packet capture successfully.

az network watcher list --resource-group rg-netsec-lab --output table

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Flow logs enabled ہیں لیکن storage میں کوئی فائل نظر نہیں آتیFlow logs enabled hain lekin storage mein koi file nazar nahi aatiFlow logs are enabled but no files appear in storage

✅ Flow logs صرف تب آتے ہیں جب ٹریفک اصل میں بہتا ہے۔ Subnet پر ٹریفک generate کریں، پھر 5–10 منٹ انتظار کریں — logs batches میں لکھے جاتے ہیں۔Flow logs sirf tab aate hain jab traffic asal mein behta hai. Subnet par traffic generate karein, phir 5–10 minute intezar karein — logs batches mein likhe jate hain.Flow logs appear only when traffic actually flows. Generate traffic to the subnet, then wait 5–10 minutes — logs are written in batches.

⚠️ Connection troubleshoot "unreachable" دکھاتا ہے لیکن rules ٹھیک لگتے ہیںConnection troubleshoot "unreachable" dikhata hai lekin rules theek lagte hainConnection troubleshoot shows "unreachable" but rules look fine

✅ Route tables اور effective routes چیک کریں — کوئی user-defined route ٹریفک کو firewall یا NVA بھیج سکتا ہے جو اسے drop کرتا ہے۔ Network Watcher ہر hop کی effective route دکھاتا ہے۔Route tables aur effective routes check karein — koi user-defined route traffic ko firewall ya NVA bhej sakta hai jo use drop karta hai. Network Watcher har hop ki effective route dikhata hai.Check route tables and effective routes — a user-defined route may send traffic to a firewall or NVA that drops it. Network Watcher shows the effective route per hop.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ NSG flow logs کیا record کرتے ہیں اور انہیں کیسے analyze کیا جاتا ہے؟NSG flow logs kya record karte hain aur inhein kaise analyze kiya jata hai?What do NSG flow logs record and how are they analyzed?

NSG flow logs NSG سے گزرنے والے ہر flow کا source، destination، port، protocol اور allow/deny decision ریکارڈ کرتے ہیں۔ یہ storage account میں store ہوتے ہیں اور blocked traffic ڈھونڈنے کے لیے Traffic Analytics میں analyze ہوتے ہیں۔NSG flow logs NSG se guzarne wale har flow ka source, destination, port, protocol aur allow/deny decision record karte hain. Yeh storage account mein store hote hain aur blocked traffic dhoondne ke liye Traffic Analytics mein analyze hote hain.NSG flow logs record the source, destination, port, protocol, and allow/deny decision for each flow through an NSG. They are stored in a storage account and analyzed in Traffic Analytics to find blocked traffic.

❓ Network Watcher سے broken connection کیسے troubleshoot کرتے ہیں؟Network Watcher se broken connection kaise troubleshoot karte hain?How do you troubleshoot a broken connection with Network Watcher?

Network Watcher > Connection troubleshoot کھولیں، source VM، destination IP، port اور protocol چنیں۔ یہ ہر hop (NSG rules، routes، firewall) ٹیسٹ کرتا ہے اور بتاتا ہے کہ connectivity بالکل کہاں ٹوٹ رہی ہے۔Network Watcher > Connection troubleshoot kholein, source VM, destination IP, port aur protocol chunein. Yeh har hop (NSG rules, routes, firewall) test karta hai aur batata hai ke connectivity exactly kahan toot rahi hai.Open Network Watcher > Connection troubleshoot, pick source VM, destination IP, port, and protocol. It tests each hop (NSG rules, routes, firewall) and reports exactly where connectivity breaks.