📝 Section Review: Network Security
اہم نکاتKey TakeawaysKey Takeaways
- NSG میں IPs، ports اور protocols پر Layer 3–4 پر allow/deny rules ہوتی ہیں — simple، fast، cheap۔NSG mein IPs, ports aur protocols par Layer 3–4 par allow/deny rules hoti hain — simple, fast, cheap.An NSG holds allow/deny rules on IPs, ports, and protocols at Layer 3–4 — simple, fast, cheap.
- Rule priority سب کچھ decide کرتی ہے: سب سے کم نمبر پہلے evaluate ہوتا ہے، پہلی match جیتتی ہے، defaults آخر میں deny کرتی ہیں۔Rule priority sab kuch decide karti hai: sab se kam number pehle evaluate hota hai, pehli match jeet-ti hai, defaults aakhir mein deny karti hain.Rule priority decides everything: lowest number is evaluated first, first match wins, defaults deny last.
- NSG subnet یا VM network interface سے attach ہوتی ہے — boundary جہاں چاہیے وہاں attach کریں۔NSG subnet ya VM network interface se attach hoti hai — boundary jahan chahiye wahan attach karein.An NSG attaches to a subnet or a VM network interface — attach it where you want the boundary.
- Azure Firewall Layer 7 controls شامل کرتا ہے: FQDN filtering، threat intelligence، TLS inspection (Premium)۔Azure Firewall Layer 7 controls add karta hai: FQDN filtering, threat intelligence, TLS inspection (Premium).Azure Firewall adds Layer 7 controls: FQDN filtering, threat intelligence, TLS inspection (Premium).
- Firewall subnet کا نام بالکل AzureFirewallSubnet ہونا چاہیے — ایک classic interview trap۔Firewall subnet ka naam bilkul AzureFirewallSubnet hona chahiye — ek classic interview trap.The firewall subnet must be named exactly AzureFirewallSubnet — a classic interview trap.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ NSG rules کیسے evaluate ہوتی ہیں؟NSG rules kaise evaluate hoti hain?How are NSG rules evaluated?
سب سے کم priority number جیتتا ہے؛ پہلی matching rule لاگو ہوتی ہے۔ Rules stateful ہوتی ہیں — return traffic خودکار طور پر allow ہوتا ہے۔Sab se kam priority number jeet-ta hai; pehli matching rule lagoo hoti hai. Rules stateful hoti hain — return traffic automatically allow hota hai.Lowest priority number wins; the first matching rule is applied. Rules are stateful — return traffic is allowed automatically.
❓ NSG بمقابلہ Azure Firewall — بنیادی فرق کیا ہے؟NSG vs Azure Firewall — bunyadi farq kya hai?NSG vs Azure Firewall — what is the key difference?
NSG Layer 3–4 پر allow/deny rules سے فلٹر کرتا ہے؛ Azure Firewall stateful managed firewall ہے جس میں FQDN filtering اور threat intelligence جیسے Layer 7 features ہیں۔NSG Layer 3–4 par allow/deny rules se filter karta hai; Azure Firewall stateful managed firewall hai jismein FQDN filtering aur threat intelligence jaise Layer 7 features hain.NSG filters at Layer 3–4 with allow/deny rules; Azure Firewall is a stateful managed firewall with Layer 7 features like FQDN filtering and threat intelligence.
❓ Azure Firewall subnet کے لیے exact نام کیا چاہیے؟Azure Firewall subnet ke liye exact naam kya chahiye?What is the exact name required for the Azure Firewall subnet?
اس کا نام بالکل AzureFirewallSubnet ہونا چاہیے؛ firewall deployment کے لیے dedicated subnet ضروری ہے۔Us ka naam bilkul AzureFirewallSubnet hona chahiye; firewall deployment ke liye dedicated subnet zaroori hai.It must be named exactly AzureFirewallSubnet; a dedicated subnet is required for the firewall deployment.