Access Control Policy: Rulebase & Objects
Check Point — CCSA track EVE-NG — Check Point VM (SmartConsole + CLI)
مقصدObjectiveObjective
متحدہ ایکسس کنٹرول پالیسی بنائیں: نیٹ ورک آبجیکٹس، ترتیب شدہ رولز cleanup rule کے ساتھ، اور ایک inline layer۔Unified access control policy banayein: network objects, ordered rules cleanup rule ke saath, aur ek inline layer.Build a unified access control policy: network objects, ordered rules with a cleanup rule, and an inline layer.
آسان مثالSimple AnalogySimple Analogy
باؤنسر کی مہمانوں کی فہرست کی طرح جو اوپر سے نیچے پڑھی جاتی ہے: پہلا matching رول فیصلہ کرتا ہے، اور آخری رول فہرست میں نہ ہونے والوں کو باہر نکال دیتا ہے۔Bouncer ki guest list ki tarah jo upar se neeche parhi jati hai: pehla matching rule faisla karta hai, aur aakhri rule list mein na hone walon ko bahar nikal deta hai.Like a bouncer's guest list read top to bottom: the first matching rule decides, and the last rule throws out everyone not on the list.
سیٹ اپLab SetupLab Setup
وہی EVE-NG ٹوپالوجی: WAN (external)، LAN (internal) ایک ہوسٹ کے ساتھ اور DMZ ویب سرور اگر دستیاب ہو۔ SmartConsole انسٹال شدہ گیٹ وے کے ساتھ۔Wohi EVE-NG topology: WAN (external), LAN (internal) ek host ke saath aur DMZ web server agar available ho. SmartConsole installed gateway ke saath.Same EVE-NG topology: WAN (external), LAN (internal) with a host and a DMZ web server if available. SmartConsole with an installed gateway.
اقداماتStepsSteps
Step 1
پہلے reusable آبجیکٹس بنائیں: نیٹ ورکس، ہوسٹس اور سروسز۔ اچھے آبجیکٹس رول بیس کو پڑھنے کے قابل اور پالیسیوں میں دوبارہ قابلِ استعمال بناتے ہیں۔Pehle reusable objects banayein: networks, hosts aur services. Achhe objects rulebase ko readable aur policies mein reusable banate hain.Create reusable objects first: networks, hosts, and services. Good objects make the rulebase readable and reusable across policies.
🖱️ Objects > New > Network / Host: LAN_net (10.0.1.0/24)، web_srv host، اور ضروری service objects بنائیں۔Objects > New > Network / Host: LAN_net (10.0.1.0/24), web_srv host, aur zaroori service objects banayein.Objects > New > Network / Host: create LAN_net (10.0.1.0/24), web_srv host, and any service objects you need.
Step 2
رول 1 — stealth rule: گیٹ وے کی طرف آنے والا سب کچھ drop کریں۔ یہ فائر وال کو براہِ راست حملے سے چھپاتا ہے۔Rule 1 — stealth rule: gateway ki taraf aane wala sab kuch drop karein. Yeh firewall ko direct attack se chhupata hai.Rule 1 — stealth rule: drop everything destined to the gateway itself. This hides the firewall from direct attack.
🖱️ Security Policies > Access Control > Policy: stealth rule شامل کریں — گیٹ وے خود کی طرف آنے والا تمام ٹریفک drop کریں۔Security Policies > Access Control > Policy: stealth rule add karein — gateway KHUD ki taraf aane wala sab traffic drop karein.Security Policies > Access Control > Policy: add a stealth rule — drop all traffic TO the gateway itself.
Step 3
مخصوص allow rules شامل کریں: internal users انٹرنیٹ کی طرف (لاگ کریں)، اور انٹرنیٹ DMZ ویب سرور کی طرف صرف HTTPS پر۔ عام سے پہلے مخصوص۔Specific allow rules add karein: internal users internet ki taraf (log karein), aur internet DMZ web server ki taraf sirf HTTPS par. General se pehle specific.Add specific allow rules: internal users out to the internet (log it), and the internet in to the DMZ web server on HTTPS only. Specific before general.
🖱️ Allow rules شامل کریں: LAN_net سے Any http/https/dns پر (Log)، اور Any سے web_srv صرف https پر (Log)۔Allow rules add karein: LAN_net se Any http/https/dns par (Log), aur Any se web_srv sirf https par (Log).Add allow rules: LAN_net to Any on http/https/dns (Log), and Any to web_srv on https only (Log).
Step 4
ویب سرور رول میں inline layer شامل کریں باریک کنٹرول کے لیے — مثلاً منظور شدہ HTTPS رول کے اندر /admin paths بلاک کرنا۔ Layers مرکزی پالیسی کو مختصر رکھتے ہیں۔Web-server rule mein inline layer add karein fine-grained control ke liye — masalan allowed HTTPS rule ke andar /admin paths block karna. Layers main policy ko chhota rakhte hain.Add an inline layer to the web-server rule for fine-grained control — for example blocking /admin paths inside the allowed HTTPS rule. Layers keep the main policy short.
🖱️ ویب سرور رول کے Action میں Inline Layer منتخب کریں اور باریک رولز والی layer بنائیں (مثلاً admin URLs بلاک کریں)۔Web-server rule ke Action mein Inline Layer chunein aur finer rules wali layer banayein (masalan admin URLs block karein).In the web-server rule's Action, choose Inline Layer and create a layer with finer rules (e.g. block admin URLs).
Step 5
cleanup rule پر ختم کریں: جو واضح طور پر allow نہیں، سب drop اور log کریں۔ اس کے بغیر unmatched ٹریفک کا رویہ غیر یقینی ہوتا ہے۔Cleanup rule par khatam karein: jo explicitly allow nahi, sab drop aur log karein. Is ke baghair unmatched traffic ka behavior ghair yaqeeni hota hai.Finish with the cleanup rule: drop and log everything not explicitly allowed. Without it, unmatched traffic behavior is unpredictable.
🖱️ آخری رول: Any سے Any، Drop، Log کے ساتھ۔ یہ cleanup rule ہے۔Aakhri rule: Any se Any, Drop, Log ke saath. Yeh cleanup rule hai.Last rule: Any to Any, Drop, with Log. This is the cleanup rule.
Step 6
پالیسی انسٹال کریں اور لاگز میں تصدیق کریں کہ ٹریفک آپ کے مطلوبہ رولز پر hit ہو رہا ہے — cleanup rule باقی سب پکڑ رہا ہو۔Policy install karein aur logs mein verify karein ke traffic aap ke intended rules par hit ho raha hai — cleanup rule baqi sab pakar raha ho.Install the policy and verify in the logs that traffic hits your intended rules — including the cleanup rule catching the rest.
🖱️ Install Policy > گیٹ وے منتخب کریں > Install۔ Logs & Monitor > Logs میں اپنے نئے رولز پر hits چیک کریں۔Install Policy > gateway select karein > Install. Logs & Monitor > Logs mein apne naye rules par hits check karein.Install Policy > select gateway > Install. Check Logs & Monitor > Logs for hits on your new rules.
تصدیقVerifyVerify
لاگز دکھاتے ہیں کہ منظور شدہ ٹریفک آپ کے allow rules پر hit ہو رہا ہے اور باقی سب cleanup drop rule پر۔Logs dikhate hain ke allowed traffic aap ke allow rules par hit ho raha hai aur baqi sab cleanup drop rule par.Logs show allowed traffic hitting your allow rules and everything else hitting the cleanup drop rule.
fw tab -t connections -s
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ ٹریفک allow ہو رہا ہے جو بلاک ہونا چاہیے تھا۔Traffic allow ho raha hai jo block hona chahiye tha.Traffic allowed that should be blocked.
✅ اوپر والا کوئی رول پہلے میچ کر رہا ہے۔ رول کی ترتیب اور لاگ کا matched-rule کالم چیک کریں، پھر deny کو وسیع allow سے اوپر لے جائیں۔Upar wala koi rule pehle match kar raha hai. Rule order aur log ke matched-rule column check karein, phir deny ko broad allow se upar le jayein.A rule above is matching first. Check rule order and the log's matched-rule column, then move the deny above the broad allow.
⚠️ cleanup rule جائز ٹریفک گرا رہا ہے۔Cleanup rule legitimate traffic drop kar raha hai.Legitimate traffic dropped by the cleanup rule.
✅ آپ نے allow rule چھوٹ دی ہے۔ Logs & Monitor میں drop تلاش کریں، source/destination/service نوٹ کریں، اور cleanup rule سے اوپر مخصوص allow شامل کریں۔Aap ne allow rule miss ki hai. Logs & Monitor mein drop dhoondein, source/destination/service note karein, aur cleanup rule se upar specific allow add karein.You missed an allow rule. Find the drop in Logs & Monitor, note source/destination/service, and add the specific allow above the cleanup rule.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ رول میچنگ کیسے کام کرتی ہے، اور cleanup rule کہاں لگتا ہے؟Rule matching kaise kaam karti hai, aur cleanup rule kahan lagta hai?How does rule matching work, and where does the cleanup rule go?
رولز اوپر سے نیچے جانچے جاتے ہیں؛ پہلا میچ جیتتا ہے، اس لیے ترتیب اہم ہے۔ مخصوص allows پہلے رکھیں، وسیع denies بعد میں، اور آخر میں cleanup rule جو باقی سب کو drop/log کرے۔Rules upar se neeche evaluate hote hain; pehla match jeetta hai, is liye order ahem hai. Specific allows pehle rakhein, broad denies baad mein, aur aakhir mein cleanup rule jo baqi sab drop/log kare.Rules are evaluated top-down; the first match wins, so order matters. Put specific allows first, broad denies after, and always end with a cleanup rule that drops/logs everything else.
❓ Unified پالیسی میں inline layer کیا ہے؟Unified policy mein inline layer kya hai?What is an inline layer in the unified policy?
Inline layer ایک sub-rulebase ہے جو parent rule کے action سے طلب کی جاتی ہے — مثلاً مرکزی پالیسی کے اندر 'web servers' layer۔ یہ بڑی پالیسیوں کو منظم رکھتا ہے اور مختلف ٹیمیں مختلف layers کی مالک ہو سکتی ہیں۔Inline layer ek sub-rulebase hai jo parent rule ke action se call hoti hai — masalan main policy ke andar 'web servers' layer. Yeh bari policies ko organized rakhta hai aur alag teams alag layers own kar sakti hain.An inline layer is a sub-rulebase called from a parent rule's action — e.g. a 'web servers' layer inside the main policy. It keeps big policies organized and lets different teams own different layers.