NAT: Automatic & Manual Rules

Check Point — CCSA track EVE-NG — Check Point VM (SmartConsole + CLI)

مقصدObjectiveObjective

باہر جانے والے صارفین کے لیے automatic Hide NAT اور سرور شائع کرنے کے لیے manual NAT رولز ترتیب دیں؛ NAT جانچ کی ترتیب سمجھیں۔Outbound users ke liye automatic Hide NAT aur server publish karne ke liye manual NAT rules configure karein; NAT evaluation order samjhein.Configure automatic Hide NAT for outbound users and manual NAT rules for publishing a server; understand NAT evaluation order.

آسان مثالSimple AnalogySimple Analogy

ڈاکخانے کی طرح: automatic NAT وہ معیاری forwarding لیبل ہے جو ہر پارسل پر لگتا ہے، جبکہ manual NAT حسبِ ضرورت ہاتھ سے لکھی ہدایت ہے جو پہلے چیک ہوتی ہے۔Post office ki tarah: automatic NAT woh standard forwarding label hai jo har package par lagta hai, jabke manual NAT custom handwritten hidayat hai jo pehle check hoti hai.Like a post office: automatic NAT is the standard forwarding label stamped on every package, while manual NAT is a custom handwritten instruction that gets checked first.

سیٹ اپLab SetupLab Setup

EVE-NG: گیٹ وے کے پیچھے LAN ہوسٹ کو انٹرنیٹ چاہیے؛ DMZ ویب سرور (10.0.2.10) WAN طرف سے public ایڈریس پر قابلِ رسائی ہونا چاہیے۔EVE-NG: gateway ke peeche LAN host ko internet chahiye; DMZ web server (10.0.2.10) WAN side se public address par reachable hona chahiye.EVE-NG: LAN host behind the gateway needs internet; DMZ web server (10.0.2.10) should be reachable from the WAN side on a public address.

اقداماتStepsSteps

Step 1

LAN نیٹ ورک آبجیکٹ پر automatic Hide NAT چالو کریں: اندرونی ایڈریسز باہر جانے والے ٹریفک کے لیے گیٹ وے کے external IP کے پیچھے چھپ جائیں۔ NAT rulebase entry کی ضرورت نہیں۔LAN network object par automatic Hide NAT enable karein: internal addresses outbound traffic ke liye gateway ke external IP ke peeche chhup jayein. NAT rulebase entry ki zaroorat nahi.Enable automatic Hide NAT on the LAN network object: internal addresses hide behind the gateway's external IP for outbound traffic. No NAT rulebase entry needed.

🖱️ LAN_net آبجیکٹ کھولیں > NAT: Add Automatic Address Translation چالو کریں، طریقہ Hide، گیٹ وے کے پیچھے چھپائیں۔LAN_net object kholein > NAT: Add Automatic Address Translation enable karein, method Hide, gateway ke peeche hide karein.Open the LAN_net object > NAT: enable Add Automatic Address Translation, method Hide, hide behind the gateway.

Step 2

NAT rulebase چیک کریں: automatic NAT رولز اپنے حصے میں سب سے اوپر نظر آتے ہیں۔ یہ ہمیشہ manual رولز سے پہلے جانچے جاتے ہیں۔NAT rulebase check karein: automatic NAT rules apne section mein sab se upar nazar aate hain. Yeh hamesha manual rules se pehle evaluate hote hain.Check the NAT rulebase: automatic NAT rules appear in their own section at the top. They are always evaluated before manual rules.

🖱️ Security Policies > NAT: تصدیق کریں کہ LAN_net کا auto-generated NAT رول اوپر والے حصے میں نظر آ رہا ہے۔Security Policies > NAT: verify karein ke LAN_net ka auto-generated NAT rule top section mein nazar aa raha hai.Security Policies > NAT: verify the auto-generated NAT rule for LAN_net appears at the top section.

Step 3

DMZ ویب سرور شائع کرنے کے لیے manual NAT رول شامل کریں: public IP پر آنے والا ٹریفک (static) 10.0.2.10 پر translate ہو۔ Manual رولز automatic NAT کے بعد اوپر سے نیچے چیک ہوتے ہیں۔DMZ web server publish karne ke liye manual NAT rule add karein: public IP par aane wala traffic (static) 10.0.2.10 par translate ho. Manual rules automatic NAT ke baad upar se neeche check hote hain.Add a manual NAT rule to publish the DMZ web server: traffic to its public IP translates (static) to 10.0.2.10. Manual rules are checked top-down after automatic NAT.

🖱️ NAT rulebase > Add rule above: Original Source Any، Original Destination = public IP object، Translated Destination = web_srv (static)، service https۔NAT rulebase > Add rule above: Original Source Any, Original Destination = public IP object, Translated Destination = web_srv (static), service https.NAT rulebase > Add rule above: Original Source Any, Original Destination = public IP object, Translated Destination = web_srv (static), service https.

Step 4

یاد رکھیں: NAT صرف ایڈریسز translate کرتا ہے — allow یا drop کا فیصلہ access rulebase کرتا ہے۔ ہمیشہ NAT رول کے ساتھ مطابقتی access rule رکھیں۔Yaad rakhein: NAT sirf addresses translate karta hai — allow ya drop ka faisla access rulebase karta hai. Hamesha NAT rule ke saath matching access rule rakhein.Remember: NAT only translates addresses — the access rulebase still decides allow or drop. Always pair a NAT rule with a matching access rule.

🖱️ تصدیق کریں کہ مطابقتی access rule موجود ہے: Any سے web_srv https پر، Allow۔ صرف NAT ٹریفک allow نہیں کرتا۔Confirm karein ke matching access rule maujood hai: Any se web_srv https par, Allow. Sirf NAT traffic allow nahi karta.Confirm the matching access rule exists: Any to web_srv on https, Allow. NAT alone never permits traffic.

Step 5

دونوں سمتوں میں انسٹال اور ٹیسٹ کریں۔ لاگز سے تصدیق کریں کہ outbound کے لیے hide translation اور inbound سرور ٹریفک کے لیے static translation ہو رہی ہے۔Dono directions install aur test karein. Logs se confirm karein ke outbound ke liye hide translation aur inbound server traffic ke liye static translation ho rahi hai.Install and test both directions. Use the logs to confirm the hide translation for outbound and the static translation for inbound server traffic.

fw tab -t nat_table -s

🖱️ پالیسی انسٹال کریں، پھر ٹیسٹ کریں: LAN سے انٹرنیٹ براؤز کریں، اور WAN سے ویب سرور کے public IP پر۔ لاگز میں NAT translations چیک کریں۔Policy install karein, phir test karein: LAN se internet browse karein, aur WAN se web server ke public IP par. Logs mein NAT translations check karein.Install Policy, then test: browse from LAN to the internet, and from WAN to the web server's public IP. Check Logs for NAT translations.

تصدیقVerifyVerify

Hide NAT سے LAN براؤزنگ کام کرے، ویب سرور static NAT سے اپنے public IP پر جواب دے، اور لاگز دونوں translations دکھائیں۔Hide NAT se LAN browsing kaam kare, web server static NAT se apne public IP par jawab de, aur logs dono translations dikhayein.LAN browsing works through Hide NAT, the web server answers on its public IP via static NAT, and logs show both translations.

fw tab -t nat_table -s
cpstat fw -f policy

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ LAN صارفین انٹرنیٹ تک نہیں پہنچ پا رہے۔LAN users internet tak nahi pahunch pa rahe.LAN users can't reach the internet.

✅ چیک کریں کہ LAN_net پر Hide NAT چالو ہے، access rule outbound allow کرتا ہے، اور گیٹ وے کے پاس WAN کا default route ہے۔ LAN ہوسٹ کے لیے لاگ تلاش سے تصدیق کریں۔Check karein ke LAN_net par Hide NAT enabled hai, access rule outbound allow karta hai, aur gateway ke paas WAN ka default route hai. LAN host ke liye log search se verify karein.Check Hide NAT is enabled on LAN_net, the access rule allows outbound, and the gateway has a default route to WAN. Verify with a log search for the LAN host.

⚠️ ویب سرور اپنے public IP پر قابلِ رسائی نہیں۔Web server apne public IP par reachable nahi.Web server not reachable on its public IP.

✅ Manual NAT رول کی ترتیب چیک کریں (automatic ٹھیک ہے، conflict نہیں کرتا)، مطابقتی access allow rule کی تصدیق کریں، اور یقینی بنائیں کہ public IP گیٹ وے کی طرف routed ہے۔Manual NAT rule ka order check karein (automatic theek hai, conflict nahi karta), matching access allow rule confirm karein, aur verify karein ke public IP gateway ki taraf routed hai.Check manual NAT rule order (automatic is fine, it doesn't conflict), confirm the matching access allow rule exists, and verify the public IP is routed to the gateway.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ Automatic بمقابلہ manual NAT — فرق کیا ہے اور جانچ کی ترتیب کیا ہے؟Automatic vs manual NAT — farq kya hai aur evaluation order kya hai?Automatic vs manual NAT — what's the difference and the evaluation order?

Automatic NAT آبجیکٹ پر ہی ترتیب دیا جاتا ہے (مثلاً گیٹ وے کے پیچھے hide NAT) اور پہلے جانچا جاتا ہے۔ Manual NAT رولز NAT rulebase میں لکھے جاتے ہیں، automatic کے بعد اوپر سے نیچے جانچے جاتے ہیں۔ Manual رولز میچ پر automatic کو override کرتے ہیں۔Automatic NAT object par hi configure hota hai (masalan gateway ke peeche hide NAT) aur pehle evaluate hota hai. Manual NAT rules NAT rulebase mein likhe jate hain, automatic ke baad upar se neeche evaluate hote hain. Manual rules match par automatic ko override karte hain.Automatic NAT is configured on the object itself (e.g. hide NAT behind the gateway) and is evaluated first. Manual NAT rules are written in the NAT rulebase, evaluated top-down after automatic. Manual rules override automatic when they match.

❓ Hide NAT کب اور Static NAT کب استعمال کرتے ہیں؟Hide NAT kab aur Static NAT kab use karte hain?When do you use Hide NAT vs Static NAT?

اندرونی صارفین کے باہر جانے کے لیے Hide NAT (many-to-one, PAT)؛ DMZ ویب سرور جیسے اندرونی سرورز شائع کرنے کے لیے static NAT (one-to-one) تاکہ private ایڈریس ایک public ایڈریس سے map ہو۔Internal users ke bahar jaane ke liye Hide NAT (many-to-one, PAT); DMZ web server jaise internal servers publish karne ke liye static NAT (one-to-one) taake private address ek public address se map ho.Hide NAT (many-to-one, PAT) for internal users going out; static NAT (one-to-one) for publishing internal servers like the DMZ web server so its private address maps to one public address.