Capstone: Secure Hub-and-Spoke Network
Microsoft Azure Networking (AZ-700 track) Azure portal — free tier (GUI + CLI)
مقصدObjectiveObjective
اس کیپ اسٹون میں آپ Azure میں ایک محفوظ hub-and-spoke نیٹ ورک بنائیں گے: فائروال والا hub VNet، پیئرنگ والے دو spoke VNets، NSG رولز، اور فری ٹیئر میں محفوظ ایڈمن ایکسیس۔Is capstone mein aap Azure mein ek mehfooz hub-and-spoke network banayenge: firewall wala hub VNet, peering wale do spoke VNets, NSG rules, aur free tier mein mehfooz admin access.In this capstone you will build a secure hub-and-spoke network in Azure: a hub VNet with firewall, two spoke VNets with peering, NSG rules, and safe free-tier admin access.
آسان مثالSimple AnalogySimple Analogy
یہ ایسے ہے جیسے ایک کمپنی کا کیمپس ہو — ایک محفوظ مین گیٹ (hub + firewall)، اس سے پرائیویٹ راستوں سے جڑی دفتری عمارتیں (spokes + peering)، اور ہر کمرے کے لیے سیکیورٹی رولز (NSGs)۔Yeh aisa hai jaise ek company ka campus ho — ek mehfooz main gate (hub + firewall), us se private raaston se juray daftari imaratein (spokes + peering), aur har kamre ke liye security rules (NSGs).This is like a company campus: one guarded main gate (hub + firewall), office buildings connected to it by private roads (spokes + peering), and security rules for each room (NSGs).
سیٹ اپLab SetupLab Setup
آپ کو Azure فری ٹیئر کا اکاؤنٹ درکار ہے۔ East US ریجن میں کام کریں۔ یہ کیپ اسٹون rg-netsec-lab نام کا ایک ریسورس گروپ بناتا ہے اور سب کچھ فری ٹیئر میں محفوظ رکھتا ہے — Azure Firewall اور Bastion ہر گھنٹے کے حساب سے قیمت لیتے ہیں، اس لیے لیب انہیں ٹیسٹ کے فوراً بعد ڈیلیٹ کر دے گا۔Aap ko Azure free tier ka account darkar hai. East US region mein kaam karein. Yeh capstone rg-netsec-lab naam ka ek resource group banata hai aur sab kuch free tier mein mehfooz rakhta hai — Azure Firewall aur Bastion har ghante ke hisab se qeemat lete hain, is liye lab inhen test ke foran baad delete kar dega.You need an Azure account on the free tier. Work in the East US region. This capstone builds one resource group named rg-netsec-lab and keeps everything free-tier safe — Azure Firewall and Bastion are billed per hour, so this lab deletes them right after testing.
اقداماتStepsSteps
Step 1
پہلے ریسورس گروپ اور hub VNet (10.0.0.0/16) بنائیں۔ فائروال کے لیے الگ سب نیٹ درکار ہے جس کا نام بالکل AzureFirewallSubnet ہونا چاہیے — یہ نام لازمی ہے۔Pehle resource group aur hub VNet (10.0.0.0/16) banayen. Firewall ke liye alag subnet darkar hai jis ka naam bilkul AzureFirewallSubnet hona chahiye — yeh naam lazmi hai.First create the resource group and the hub VNet (10.0.0.0/16). The firewall needs its own subnet named exactly AzureFirewallSubnet — the name is mandatory.
az group create -n rg-netsec-lab -l eastus az network vnet create -g rg-netsec-lab -n hub-vnet --address-prefixes 10.0.0.0/16 --subnet-name default --subnet-prefixes 10.0.0.0/24 az network vnet subnet create -g rg-netsec-lab --vnet-name hub-vnet -n AzureFirewallSubnet --address-prefixes 10.0.1.0/26
🖱️ پورٹل میں جائیںPortal mein jayenHome > Virtual networks > Create
Step 2
Hub میں Azure Firewall ڈپلائے کریں۔ خبردار: Azure Firewall بغیر استعمال کے بھی ہر گھنٹے کی قیمت لیتا ہے — اس لیب میں آپ اسے ڈپلائے کریں گے، ٹیسٹ کریں گے اور آخری مرحلے میں ڈیلیٹ کر دیں گے۔ کبھی بھی اسے رات بھر چلتا نہ چھوڑیں۔Hub mein Azure Firewall deploy karein. Khabardar: Azure Firewall baghair istemal ke bhi har ghante ki qeemat leta hai — is lab mein aap ise deploy karenge, test karenge aur aakhri marhale mein delete kar denge. Kabhi bhi ise raat bhar chalta na chhoren.Deploy the Azure Firewall into the hub. Warning: Azure Firewall is billed per hour even when idle — in this lab you deploy it, test it, and delete it in the last step. Never leave it running overnight.
az network firewall create -g rg-netsec-lab -n hub-fw --sku AZFW_VNet
🖱️ پورٹل میں جائیںPortal mein jayenHome > Firewalls > Create
Step 3
اب دو spoke VNets بنائیں اور ہر ایک کو hub کے ساتھ دونوں طرف سے پیئر کریں۔ پیئرنگ خود بخود نہیں بنتی — آپ کو دونوں طرف سے بنانا پڑتا ہے، ورنہ یہ Disconnected کی حالت میں رہتی ہے۔Ab do spoke VNets banayen aur har ek ko hub ke saath dono taraf se peer karein. Peering khud-b-khud nahi banti — aap ko dono taraf se banana parta hai, warna yeh Disconnected ki halat mein rehti hai.Now create two spoke VNets and peer each one with the hub in both directions. Peering is not automatic — you must create it from both sides, otherwise it stays in Disconnected state.
az network vnet create -g rg-netsec-lab -n spoke1-vnet --address-prefixes 10.1.0.0/16 --subnet-name default --subnet-prefixes 10.1.0.0/24 az network vnet create -g rg-netsec-lab -n spoke2-vnet --address-prefixes 10.2.0.0/16 --subnet-name default --subnet-prefixes 10.2.0.0/24 az network vnet peering create -g rg-netsec-lab -n hub-to-spoke1 --vnet-name hub-vnet --remote-vnet spoke1-vnet --allow-vnet-access --allow-forwarded-traffic az network vnet peering create -g rg-netsec-lab -n spoke1-to-hub --vnet-name spoke1-vnet --remote-vnet hub-vnet --allow-vnet-access az network vnet peering create -g rg-netsec-lab -n hub-to-spoke2 --vnet-name hub-vnet --remote-vnet spoke2-vnet --allow-vnet-access --allow-forwarded-traffic az network vnet peering create -g rg-netsec-lab -n spoke2-to-hub --vnet-name spoke2-vnet --remote-vnet hub-vnet --allow-vnet-access
🖱️ پورٹل میں جائیںPortal mein jayenVirtual networks > hub-vnet > Peerings > Add
Step 4
ایک NSG بنائیں اور SSH صرف اپنے پبلک IP سے allow کریں۔ Default deny رول کو نیچے رہنے دیں۔ یہ ہر VM سے پہلے آپ کا آخری دروازہ ہے — کیمپس میں بھی دفتر کے دروازوں پر تالے ہوتے ہیں۔Ek NSG banayen aur SSH sirf apne public IP se allow karein. Default deny rule ko neeche rehne dein. Yeh har VM se pehle aap ka aakhri darwaza hai — campus mein bhi daftar ke darwazon par tale hote hain.Create an NSG and allow SSH only from your own public IP. Keep the default deny rule below it. This is your last gate before each VM — even a campus needs locks on office doors.
az network nsg create -g rg-netsec-lab -n spoke-nsg az network nsg rule create -g rg-netsec-lab --nsg-name spoke-nsg -n allow-ssh-myip --priority 100 --source-address-prefixes <your-public-ip>/32 --destination-port-ranges 22 --access Allow --protocol Tcp --direction Inbound
🖱️ پورٹل میں جائیںPortal mein jayenHome > Network security groups > Create
Step 5
ایڈمن ایکسیس کے لیے Azure Bastion پورٹل کے ذریعے پرائیویٹ RDP/SSH دیتا ہے — لیکن اس کی قیمت ہر گھنٹے ہوتی ہے۔ فری ٹیئر میں پچھلے مرحلے کا NSG رول (صرف آپ کے IP سے SSH) مفت اور محفوظ راستہ ہے۔ فی الحال Bastion کا راستہ صرف نظریہ طور پر سمجھ لیں۔Admin access ke liye Azure Bastion portal ke zariye private RDP/SSH deta hai — lekin is ki qeemat har ghante hoti hai. Free tier mein pichhle marhale ka NSG rule (sirf aap ke IP se SSH) muft aur mehfooz rasta hai. Filhal Bastion ka rasta sirf nazriya tor par samajh lein.For admin access, Azure Bastion gives private RDP/SSH through the portal — but it is billed per hour. On the free tier, your NSG rule from the previous step (SSH from only your IP) is the free and safe way in. Learn the Bastion path conceptually for now.
🖱️ پورٹل میں دیکھیں، ڈپلائے نہ کریںPortal mein dekhen, deploy na kareinHome > Bastion > Create (conceptual — skip on free tier)
Step 6
Network Watcher سے تصدیق کریں: spoke1 سے spoke2 تک پورٹ 22 پر کنیکٹیویٹی ٹیسٹ کریں۔ ٹیسٹ کو hub کے راستے سے گزرنا چاہیے۔ روٹ کا کام کرنا Azure کے اپنے طریقے سے ثابت ہوتا ہے۔Network Watcher se tasdeeq karein: spoke1 se spoke2 tak port 22 par connectivity test karein. Test ko hub ke raste se guzarna chahiye. Route ka kaam karna Azure ke apne tareeqe se sabit hota hai.Verify with Network Watcher: test connectivity from spoke1 to spoke2 over port 22. The test should pass through the hub path. This is Azure's own way of proving the route works.
az network watcher configure -g NetworkWatcherRG -l eastus --enabled true az network watcher test-connectivity -g rg-netsec-lab --source-resource spoke1-vnet --dest-resource spoke2-vnet --dest-port 22
🖱️ پورٹل میں جائیںPortal mein jayenHome > Network Watcher > Connection troubleshoot
Step 7
صفائی: فائروال ڈیلیٹ کریں اور پھر پورا ریسورس گروپ ڈیلیٹ کر دیں۔ یہ سب کچھ ایک ساتھ مٹا دیتا ہے اور ہر گھنٹے کی فیس روک دیتا ہے۔ یہ عادت آپ کو غیرمتوقع بلوں سے بچاتی ہے۔Safai: firewall delete karein aur phir poora resource group delete kar dein. Yeh sab kuch ek saath mita deta hai aur har ghante ki fees rok deta hai. Yeh aadat aap ko na-umeed bills se bachati hai.Clean up: delete the firewall and then the whole resource group. This deletes everything in one go and stops all hourly charges. This habit protects you from surprise bills.
az network firewall delete -g rg-netsec-lab -n hub-fw --yes az group delete -n rg-netsec-lab --yes --no-wait
🖱️ پورٹل میں جائیںPortal mein jayenResource groups > rg-netsec-lab > Delete resource group
تصدیقVerifyVerify
دونوں طرف پیئرنگ Connected دکھاتی ہے، spoke1 سے spoke2 تک Network Watcher کنیکٹیویٹی ٹیسٹ کامیاب ہوتا ہے، اور effective NSG رولز میں SSH صرف آپ کے IP سے allowed نظر آتا ہے۔Dono taraf peering Connected dikhati hai, spoke1 se spoke2 tak Network Watcher connectivity test kamyab hota hai, aur effective NSG rules mein SSH sirf aap ke IP se allowed nazar aata hai.Peering state shows Connected on both sides, the Network Watcher connectivity test from spoke1 to spoke2 succeeds, and the effective NSG rules show SSH allowed only from your IP.
az network vnet peering list -g rg-netsec-lab --vnet-name hub-vnet -o table az network watcher test-connectivity -g rg-netsec-lab --source-resource spoke1-vnet --dest-resource spoke2-vnet --dest-port 22
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ VNet peering Disconnected دکھا رہی ہے۔VNet peering Disconnected dikha rahi hai.VNet peering shows Disconnected.
✅ پیئرنگ دونوں طرف سے بنائیں: hub-to-spoke اور spoke-to-hub۔ صرف ایک طرف سے بنانا کبھی کافی نہیں ہوتا۔Peering dono taraf se banayen: hub-to-spoke AUR spoke-to-hub. Sirf ek taraf se banana kabhi kaafi nahi hota.Create the peering from both sides: hub-to-spoke AND spoke-to-hub. One side alone is never enough.
⚠️ پیئرنگ connected ہونے کے باوجود VM پر SSH timeout ہو رہا ہے۔Peering connected hone ke bawajood VM par SSH timeout ho raha hai.SSH to a VM times out even though peering is connected.
✅ NSG چیک کریں: default deny رول ہر اس چیز کو روک دیتی ہے جس کی allow رول نے اجازت نہ دی ہو۔ اپنے پبلک IP کے لیے ایک allow رول بنائیں جس کی priority deny سے کم (چھوٹی تعداد) ہو۔NSG check karein: default deny rule har us cheez ko rok deti hai jis ki allow rule ne ijazat na di ho. Apne public IP ke liye ek allow rule banayen jis ki priority deny se kam (chhoti taadad) ho.Check the NSG: the default deny rule blocks everything your allow rules do not permit. Add an allow rule for your public IP with a priority lower (smaller number) than the deny.
⚠️ Azure اکاؤنٹ پر غیرمتوقع فیس نظر آ رہی ہے۔Azure account par ghair-mutawaqa fees nazar aa rahi hain.You see unexpected charges on your Azure account.
✅ فوراً ریسورس گروپ ڈیلیٹ کر دیں (مرحلہ 7)۔ Azure Firewall اور Bastion ہر گھنٹے کی قیمت لیتے ہیں — فری ٹیئر پر ٹیسٹ کے فوراً بعد billed ریسورسز ہمیشہ ڈیلیٹ کریں۔Foran resource group delete kar dein (marhala 7). Azure Firewall aur Bastion har ghante ki qeemat lete hain — free tier par test ke foran baad billed resources hamesha delete karein.Delete the resource group immediately (step 7). Azure Firewall and Bastion bill per hour — always delete billed resources right after testing on the free tier.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ اسپوک سے اسپوک تک ٹریفک حب سے کیوں گزرنا چاہیے؟ (پریکٹس)Spoke se spoke tak traffic hub se kyun guzarna chahiye? (practice)Why must spoke-to-spoke traffic go through the hub? (practice)
سارا ٹریفک حب سے گزرتا ہے — Azure Firewall اس کی مرکزی طور پر جانچ کرتا ہے۔ حب راستے میں نہ ہو تو فائروال کے پاس جانچنے کے لیے کچھ نہیں ہوتا۔Sara traffic hub se guzarta hai — Azure Firewall us ki markazi tor par janch karta hai. Hub raaste mein na ho to firewall ke paas janchne ke liye kuch nahi hota.All traffic passes through the hub — the Azure Firewall inspects it centrally. Without the hub in the path, the firewall has nothing to inspect.
❓ NSG اور Azure Firewall میں کیا فرق ہے؟ (پریکٹس)NSG aur Azure Firewall mein kya farq hai? (practice)NSG vs Azure Firewall — what is the difference? (practice)
NSG ایک چھوٹا فائروال ہے جو سب نیٹ یا NIC پر لگتا ہے — یہ VM سے پہلے کا آخری دروازہ ہے۔ حب کا فائروال پورے کیمپس کی حفاظت کرتا ہے، NSG ایک دروازے کی۔NSG ek chhota firewall hai jo subnet ya NIC par lagta hai — yeh VM se pehle ka aakhri darwaza hai. Hub ka firewall pure campus ki hifazat karta hai, NSG ek darwaze ki.An NSG is a small firewall that sits at the subnet or NIC level — it is the last gate before a VM. The hub firewall guards the whole campus, the NSG guards one door.