Check Point Architecture: Gateway, Management & SmartConsole
Check Point — CCSA track EVE-NG — Check Point VM (SmartConsole + CLI)
مقصدObjectiveObjective
Check Point کا 3 درجے والا آرکیٹیکچر، Software Blades، اور پالیسی کے مینجمنٹ سے گیٹ وے تک کے بہاؤ کو سمجھنا۔Check Point ka 3-tier architecture, Software Blades, aur policy management se gateway tak ka flow samajhna.Understand the 3-tier Check Point architecture, Software Blades, and how a policy flows from management to gateway.
آسان مثالSimple AnalogySimple Analogy
ایسی کمپنی کی طرح جس میں تین ٹیمیں ہوں: گیٹ پر گارڈز (Gateway)، کنٹرول روم جو گارڈز کو ہدایات دیتا ہے (Management)، اور ریڈیو ایپ جس سے آپ کنٹرول روم سے بات کرتے ہیں (SmartConsole)۔Ek company ki tarah jisme teen teams hon: gate par guards (Gateway), control room jo guards ko instructions deta hai (Management), aur radio app jisse aap control room se baat karte hain (SmartConsole).Like a company with three teams: guards at the door (Gateway), the control room that writes the guard instructions (Management), and the radio app you use to talk to the control room (SmartConsole).
سیٹ اپLab SetupLab Setup
نظریاتی سبق۔ حوالہ: ایک EVE-NG چیک پوائنٹ گیٹ وے VM اور ایک مینجمنٹ VM (اسٹینڈالون یا تقسیم شدہ)، SmartConsole آپ کے کمپیوٹر پر۔Theory lesson. Reference: ek EVE-NG Check Point gateway VM plus ek management VM (standalone ya distributed), SmartConsole aap ke PC par.Theory lesson. Reference: one EVE-NG Check Point gateway VM plus a management VM (standalone or distributed), SmartConsole on your PC.
اقداماتStepsSteps
Step 1
Security Gateway نفاذ کا مقام ہے۔ یہ نیٹ ورک کے کنارے یا زونز کے درمیان ہوتا ہے اور انسٹال شدہ پالیسی کے خلاف ٹریفک کی جانچ کرتا ہے۔ اسے گیٹ پر گارڈ سمجھیں۔Security Gateway enforcement point hai. Yeh network edge ya zones ke darmiyan betha hota hai aur installed policy ke khilaf traffic inspect karta hai. Ise gate par guard samjhein.The Security Gateway is the enforcement point. It sits at the network edge or between zones and inspects traffic against the installed policy. Think of it as the guard at the gate.
Step 2
Security Management Server سب کچھ رکھتا ہے: آبجیکٹس، ایکسس پالیسی، NAT رولز، لاگز اور لائسنس۔ گیٹ ویز compiled پالیسی اسی سے لیتے ہیں۔ ایک مینجمنٹ کئی گیٹ ویز کنٹرول کر سکتی ہے۔Security Management Server sab kuch rakhta hai: objects, access policy, NAT rules, logs aur licenses. Gateways compiled policy usi se lete hain. Ek management kai gateways control kar sakti hai.The Security Management Server holds everything: objects, access policy, NAT rules, logs, and licenses. Gateways pull the compiled policy from it. One management can control many gateways.
Step 3
SmartConsole ایڈمن ایپلیکیشن ہے جو مینجمنٹ سرور سے جڑتی ہے۔ آپ یہیں سے آبجیکٹس بناتے ہیں، رول بیس لکھتے ہیں، blades ترتیب دیتے ہیں اور لاگز کی نگرانی کرتے ہیں۔SmartConsole admin application hai jo management server se connect hoti hai. Aap yahan se objects banate hain, rulebase likhte hain, blades configure karte hain aur logs monitor karte hain.SmartConsole is the admin application that connects to the management server. You build objects, write the rulebase, configure blades, and monitor logs from here.
Step 4
Software Blades لائسنس یافتہ ماڈیولز ہیں جو آپ ہر گیٹ وے پر چالو کرتے ہیں: Firewall، IPS، Application Control، URL Filtering، Anti-Bot، Anti-Virus، Threat Emulation (SandBlast)، Identity Awareness، VPN، DLP، HTTPS Inspection۔Software Blades licensed modules hain jo aap har gateway par on karte hain: Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation (SandBlast), Identity Awareness, VPN, DLP, HTTPS Inspection.Software Blades are licensed modules you switch on per gateway: Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation (SandBlast), Identity Awareness, VPN, DLP, HTTPS Inspection.
Step 5
پالیسی کا بہاؤ: SmartConsole میں پالیسی لکھیں اور محفوظ کریں، پھر Install Policy پر کلک کرکے compiled پالیسی گیٹ ویز پر بھیجیں۔ گیٹ وے اسے فوراً نافذ کرتا ہے۔Policy flow: SmartConsole mein policy likhein aur save karein, phir Install Policy par click karke compiled policy gateways par push karein. Gateway ise foran enforce karta hai.Policy flow: write and save policy in SmartConsole, then click Install Policy to push the compiled policy to gateways. The gateway then enforces it immediately.
Step 6
تعیناتیاں: standalone (ایک باکس پر مینجمنٹ + گیٹ وے، لیبز کے لیے اچھا) یا distributed (الگ مینجمنٹ سرور، انٹرپرائز ماڈل)۔ EVE-NG لیبز عام طور پر standalone سے شروع ہوتے ہیں۔Deployments: standalone (ek box par management + gateway, labs ke liye acha) ya distributed (alag management server, enterprise model). EVE-NG labs aam tor par standalone se shuru hote hain.Deployments: standalone (management + gateway on one box, good for labs) or distributed (separate management server, the enterprise model). EVE-NG labs usually start standalone.
تصدیقVerifyVerify
خود کو سمجھائیں: پالیسی کون سا درجہ رکھتا ہے، کون سا نافذ کرتا ہے، اور Install Policy کیا کرتا ہے۔Khud ko samjhaein: policy kaun sa tier store karta hai, kaun sa enforce karta hai, aur Install Policy kya karta hai.Explain to yourself: which tier stores the policy, which tier enforces it, and what Install Policy does.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Check Point کا 3 درجے والا آرکیٹیکچر کیا ہے اور یہ کیوں ضروری ہے؟Check Point 3-tier architecture kya hai aur yeh kyun zaroori hai?What is the Check Point 3-tier architecture, and why does it matter?
تین درجے: Security Gateway (ٹریفک پر پالیسی نافذ کرتا ہے)، Security Management Server (پالیسی، لاگز اور آبجیکٹس رکھتا ہے)، اور SmartConsole (ایڈمن GUI)۔ مرکزی پالیسی: ایک پالیسی ایک بار لکھی جاتی ہے اور کئی گیٹ ویز پر انسٹال ہوتی ہے۔Teen tiers: Security Gateway (traffic par policy enforce karta hai), Security Management Server (policy, logs aur objects store karta hai), aur SmartConsole (admin GUI). Centralized policy: ek policy ek dafa likhi jati hai aur kai gateways par install hoti hai.Three tiers: Security Gateway (enforces policy on traffic), Security Management Server (stores policy, logs, and objects), and SmartConsole (the admin GUI). Centralized policy: one policy is written once and installed to many gateways.