Initial Setup: SIC, Interfaces & Topology

Check Point — CCSA track EVE-NG — Check Point VM (SmartConsole + CLI)

مقصدObjectiveObjective

ابتدائی سیٹ اپ مکمل کریں: SIC اعتماد قائم کریں، انٹرفیس ٹوپالوجی اور سیکیورٹی زونز بتائیں، anti-spoofing چالو کریں۔Initial setup mukammal karein: SIC trust establish karein, interface topology aur security zones define karein, anti-spoofing enable karein.Complete first-time setup: establish SIC trust, define interface topology and security zones, and enable anti-spoofing.

آسان مثالSimple AnalogySimple Analogy

مہر شدہ شناختی کارڈز کے تبادلے کی طرح: SIC وہ خفیہ اشارہ ہے جو مینجمنٹ سرور اور گیٹ وے کو اصل کام سے پہلے ایک دوسرے پر اعتماد کرنے دیتا ہے۔Sealed ID cards exchange karne ki tarah: SIC woh secret handshake hai jo management server aur gateway ko asal kaam se pehle ek doosre par trust karne deta hai.Like exchanging sealed ID cards: SIC is the secret handshake that lets the management server and gateway trust each other before any real work begins.

سیٹ اپLab SetupLab Setup

EVE-NG: ایک چیک پوائنٹ گیٹ وے VM کم از کم 2 انٹرفیسز کے ساتھ (WAN انٹرنیٹ کلاؤڈ کی طرف، LAN ایک ہوسٹ کی طرف)۔ SmartConsole مینجمنٹ سرور سے منسلک۔EVE-NG: ek Check Point gateway VM kam az kam 2 interfaces ke saath (WAN internet cloud ki taraf, LAN ek host ki taraf). SmartConsole management server se connected.EVE-NG: one Check Point gateway VM with at least 2 interfaces (WAN to internet cloud, LAN to a host). SmartConsole connected to the management server.

اقداماتStepsSteps

Step 1

Expert-mode CLI سے گیٹ وے بلڈ اور انٹرفیسز کی تصدیق کریں۔ کچھ بھی تبدیل کرنے سے پہلے یقینی بنائیں کہ کون سا انٹرفیس WAN اور کون سا LAN ہے۔Expert-mode CLI se gateway build aur interfaces verify karein. Kuch bhi change karne se pehle confirm karein ke kaun sa interface WAN aur kaun sa LAN hai.Verify the gateway build and interfaces from expert-mode CLI. Confirm which physical interface is WAN and which is LAN before touching anything.

show version
show interfaces all

Step 2

SIC قائم کریں: SmartConsole میں گیٹ وے آبجیکٹ پر one-time ایکٹیویشن کی سیٹ کریں، پھر گیٹ وے پر وہی کی دے کر SIC initialize کریں۔ دونوں طرف اعتماد قائم دکھنا چاہیے۔SIC establish karein: SmartConsole mein gateway object par one-time activation key set karein, phir gateway par wohi key dekar SIC initialize karein. Dono taraf trust established dikhna chahiye.Establish SIC: set the one-time activation key on the gateway object in SmartConsole, then run the SIC initialization on the gateway with the identical key. Both sides must show trust as established.

🖱️ Gateways & Servers > gateway object > General: SIC ایکٹیویشن کی ڈالیں؛ گیٹ وے CLI/FTW پر وہی کی دے کر SIC وِزارڈ چلائیں جب تک اعتماد Initialized نہ دکھائے۔Gateways & Servers > gateway object > General: SIC activation key dalein; gateway CLI/FTW par wohi key dekar SIC wizard chalayein jab tak trust Initialized na dikhaye.Gateways & Servers > gateway object > General: enter SIC activation key; on the gateway CLI/FTW run the SIC wizard with the same key until trust shows Initialized.

Step 3

ٹوپالوجی بتائیں: WAN کو External، LAN کو Internal درست نیٹ ورک کے ساتھ نشان زد کریں۔ Anti-spoofing چالو کریں تاکہ جعلی ذریعے والے پیکٹس گر جائیں۔Topology define karein: WAN ko External, LAN ko Internal sahi network ke saath mark karein. Anti-spoofing enable karein taake fake source wale packets drop hon.Define topology: mark WAN as External, LAN as Internal with the correct network behind it. Enable anti-spoofing so packets with fake sources are dropped.

cpstat fw

🖱️ Gateway object > Network Management > Topology: WAN انٹرفیس کو External، LAN کو Internal اس کے نیٹ ورک کے ساتھ سیٹ کریں؛ دونوں پر anti-spoofing چالو کریں۔Gateway object > Network Management > Topology: WAN interface ko External, LAN ko Internal us ke network ke saath set karein; dono par anti-spoofing enable karein.Gateway object > Network Management > Topology: set WAN interface to External, LAN to Internal with its network; enable anti-spoofing on both.

Step 4

زونز کو پالیسی سے جوڑیں: External زون کے انٹرفیسز کو Internal سے سخت رولز ملیں گے۔ دستاویز بنائیں کہ ہر انٹرفیس کس زون میں ہے — یہ اگلے سبق میں ایکسس رول بیس کو چلائے گا۔Zones ko policy se map karein: External zone ke interfaces ko Internal se sakht rules milenge. Document karein ke har interface kaun se zone mein hai — yeh agle lesson mein access rulebase drive karega.Map zones to policy: interfaces in the External zone get stricter rules than Internal. Document which zone each interface belongs to — this drives the access rulebase in the next lesson.

Step 5

گیٹ وے پر پالیسی انسٹال کریں۔ کامیاب انسٹال اس بات کی تصدیق کرتا ہے کہ SIC درست ہے، ٹوپالوجی معتبر ہے، اور گیٹ وے نافذ کر رہا ہے۔Gateway par policy install karein. Kamyab install confirm karta hai ke SIC theek hai, topology valid hai, aur gateway enforce kar raha hai.Install the policy to the gateway. A successful install confirms SIC is healthy, topology is valid, and the gateway is enforcing.

fw ctl pstat

🖱️ Install Policy: گیٹ وے منتخب کریں، Access Control + Threat Prevention انسٹال کریں، اور ٹاسک لاگ میں کامیاب انسٹال کی تصدیق کریں۔Install Policy: gateway select karein, Access Control + Threat Prevention install karein, aur task log mein kamyab install confirm karein.Install Policy: select the gateway, install Access Control + Threat Prevention, and confirm successful install in the task log.

تصدیقVerifyVerify

SIC initialized دکھائے، ٹوپالوجی میں WAN External اور LAN Internal anti-spoofing کے ساتھ، اور پالیسی صاف انسٹال ہو۔SIC initialized dikhaye, topology mein WAN External aur LAN Internal anti-spoofing ke saath, aur policy saaf install ho.SIC shows initialized, topology marks WAN External and LAN Internal with anti-spoofing on, and policy installs cleanly.

cpstat fw
fw stat

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ SIC/communication error کے ساتھ پالیسی انسٹال ناکام ہو جاتا ہے۔SIC/communication error ke saath policy install fail ho jata hai.Policy install fails with a SIC/communication error.

✅ SIC دوبارہ initialize کریں: دونوں طرف ایک جیسی نئی کی سے reset کریں، مینجمنٹ سے گیٹ وے connectivity چیک کریں (port 18191)، اور دوبارہ انسٹال کریں۔SIC dobara initialize karein: dono taraf identical nayi key se reset karein, management-to-gateway connectivity check karein (port 18191), aur reinstall karein.Re-run SIC initialization: reset the activation key on both sides with an identical new key, check management-to-gateway connectivity (port 18191), and reinstall.

⚠️ Anti-spoofing جائز ٹریفک گرا رہا ہے۔Anti-spoofing legitimate traffic drop kar raha hai.Legitimate traffic dropped by anti-spoofing.

✅ ٹوپالوجی غلط ہے: انٹرفیس کا defined نیٹ ورک حقیقت سے میل نہیں کھاتا۔ انٹرفیس کے پیچھے نیٹ ورک درست کریں یا ٹوپالوجی صحیح سیٹ کریں، پھر reinstall کریں۔Topology ghalat hai: interface ka defined network haqeeqat se match nahi karta. Interface ke peeche network theek karein ya topology sahi set karein, phir reinstall karein.Topology is wrong: the interface's defined network doesn't match reality. Fix the network behind the interface or set the interface topology correctly, then reinstall.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ SIC کیا ہے اور اسے کیسے قائم کرتے ہیں؟SIC kya hai aur ise kaise establish karte hain?What is SIC and how do you establish it?

SIC مینجمنٹ اور گیٹ وے کے درمیان سرٹیفکیٹ پر مبنی اعتماد ہے۔ گیٹ وے آبجیکٹ پر ایکٹیویشن کی سیٹ کریں اور گیٹ وے پر SIC وِزارڈ چلائیں؛ دونوں طرف میچ ہونا ضروری ہے۔ SIC ٹوٹا = پالیسی انسٹال نہیں ہوگی۔SIC management aur gateway ke darmiyan certificate-based trust hai. Gateway object par activation key set karein aur gateway par SIC wizard chalayein; dono taraf match hona chahiye. SIC toota = policy install nahi hogi.SIC is the certificate-based trust between management and gateway. You set an activation key on the gateway object and run the SIC wizard on the gateway; both sides must match. SIC broken = no policy install.

❓ انٹرفیس ٹوپالوجی اور anti-spoofing کیا ہیں؟Interface topology aur anti-spoofing kya hain?What is interface topology and anti-spoofing?

ٹوپالوجی ہر انٹرفیس کو External (انٹرنیٹ کی طرف)، Internal (گیٹ وے کے پیچھے)، یا DMZ بتاتی ہے، اس کے پیچھے نیٹ ورک کے ساتھ۔ Anti-spoofing ان پیکٹس کو گرا دیتا ہے جن کا ذریعہ ٹوپالوجی نیٹ ورک سے میل نہ کھائے — جعلی حملے روکیں۔Topology har interface ko External (internet ki taraf), Internal (gateway ke peeche), ya DMZ define karti hai, us ke peeche network ke saath. Anti-spoofing un packets ko drop karta hai jinka source topology network se match na kare — spoofed attacks rokein.Topology defines each interface as External (leads to internet), Internal (behind the gateway), or DMZ, with the network behind it. Anti-spoofing drops packets whose source doesn't match the topology-defined network — stopping spoofed attacks.