Identity Awareness & User Authentication

Check Point — CCSA track EVE-NG — Check Point VM (SmartConsole + CLI)

مقصدObjectiveObjective

Identity Awareness کے تصورات سمجھیں: AD integration، identity sources، captive portal، اور user-based access rules۔Identity Awareness concepts samjhein: AD integration, identity sources, captive portal, aur user-based access rules.Understand Identity Awareness concepts: AD integration, identity sources, captive portal, and user-based access rules.

آسان مثالSimple AnalogySimple Analogy

اس دفتر کی طرح جو ملازمین کو چہرے سے پہچانتا ہے: Identity Awareness فائر وال کو صرف IP ایڈریسز کے بجائے لوگوں ('finance team') کے لیے رولز لکھنے دیتا ہے۔Us office ki tarah jo employees ko chehre se pehchanta hai: Identity Awareness firewall ko sirf IP addresses ke bajaye logon ('finance team') ke liye rules likhne deta hai.Like an office that recognizes employees by face: Identity Awareness lets the firewall write rules for people ('the finance team') instead of just IP addresses.

سیٹ اپLab SetupLab Setup

تصوری + ہلکی عملی مشق: گیٹ وے پر Identity Awareness blade چالو کریں؛ لیب میں AD/LDAP سرور آبجیکٹ اختیاری ہے — تصورات وہی رہتے ہیں۔Conceptual + halki hands-on: gateway par Identity Awareness blade enable karein; lab mein AD/LDAP server object optional hai — concepts wohi rehte hain.Conceptual + light hands-on: enable the Identity Awareness blade on the gateway; an AD/LDAP server object is optional in the lab — the concepts apply the same.

اقداماتStepsSteps

Step 1

گیٹ وے پر Identity Awareness blade چالو کریں۔ گیٹ وے صارف کی شناخت جمع یا نافذ کرنے سے پہلے اسے پالیسی سے انسٹال کرنا ضروری ہے۔Gateway par Identity Awareness blade enable karein. Gateway user identities collect ya enforce karne se pehle ise policy se install karna zaroori hai.Enable the Identity Awareness blade on the gateway. It must be installed via policy before the gateway can collect or enforce user identities.

🖱️ Gateway object > General > Network Security > Identity Awareness blade چالو کریں، پھر Install Policy۔Gateway object > General > Network Security > Identity Awareness blade enable karein, phir Install Policy.Gateway object > General > Network Security > enable Identity Awareness blade, then Install Policy.

Step 2

شناخت کے ذرائع سیکھیں: AD Query ڈومین لاگ اِن events پڑھتا ہے (agent کی ضرورت نہیں)، Identity Agent کمپیوٹر پر چلتا ہے، browser-based auth لاگ اِن صفحہ استعمال کرتا ہے، اور captive portal باقی سب کو پکڑتا ہے۔Identity sources seekhein: AD Query domain logon events parhta hai (agent ki zaroorat nahi), Identity Agent PC par chalta hai, browser-based auth login page use karta hai, aur captive portal baqi sab ko pakarta hai.Learn the identity sources: AD Query reads domain logon events (no agent needed), Identity Agent runs on the PC, browser-based auth uses a login page, and captive portal catches everyone else.

🖱️ Gateway object > Identity Awareness > Identity Sources: AD Query، Identity Agent، Browser-Based Authentication، Captive Portal کا جائزہ لیں۔Gateway object > Identity Awareness > Identity Sources: AD Query, Identity Agent, Browser-Based Authentication, Captive Portal ka jaiza lein.Gateway object > Identity Awareness > Identity Sources: review AD Query, Identity Agent, Browser-Based Authentication, Captive Portal.

Step 3

AD گروپ سے منسلک Access Role بنائیں۔ Access Roles وہ آبجیکٹس ہیں جو آپ اصل میں رولز میں ڈالتے ہیں — نفاذ کے وقت یہ صارفین میں حل ہوتے ہیں۔AD group se linked Access Role banayein. Access Roles woh objects hain jo aap asal mein rules mein dalte hain — enforcement ke waqt yeh users mein resolve hote hain.Create an Access Role tied to an AD group. Access Roles are the objects you actually put in rules — they resolve to users at enforcement time.

🖱️ Objects > Users: ایک Access Role بنائیں، مثلاً 'Finance_Team'، جو AD گروپ سے منسلک ہو۔Objects > Users: ek Access Role banayein, masalan 'Finance_Team', jo AD group se map ho.Objects > Users: create an Access Role, e.g. 'Finance_Team', mapped to an AD group.

Step 4

صارف پر مبنی رول لکھیں: صرف Finance ٹیم finance ایپ تک پہنچے، چاہے ان کے لیپ ٹاپ کا آج IP کچھ بھی ہو۔ یہ Zero Trust سوچ ہے — صرف پتہ نہیں، شناخت۔User-based rule likhein: sirf Finance team finance app tak pahunche, chahe un ke laptop ka aaj IP kuch bhi ho. Yeh Zero Trust soch hai — sirf address nahi, pehchan.Write a user-based rule: only the Finance team reaches the finance app, regardless of which IP their laptop has today. This is Zero Trust thinking — identity, not just address.

🖱️ Access Control rule: Source = Finance_Team Access Role، Destination = finance_app، Action = Allow، Log۔Access Control rule: Source = Finance_Team Access Role, Destination = finance_app, Action = Allow, Log.Access Control rule: Source = Finance_Team Access Role, Destination = finance_app, Action = Allow, Log.

Step 5

مہمانوں کے لیے LAN انٹرفیس پر captive portal چالو کریں: نامعلوم صارفین کو شناخت والی allow rule لگنے سے پہلے لاگ اِن صفحہ ملے گا۔Guests ke liye LAN interface par captive portal enable karein: unknown users ko identity wali allow rule lagne se pehle login page milega.Enable captive portal on the LAN interface for guests: unknown users get a login page before any allow rule with identity applies to them.

🖱️ Identity Awareness > Captive Portal: LAN انٹرفیس پر اسے سادہ لاگ اِن صفحے کے ساتھ چالو کریں لیب ٹیسٹنگ کے لیے۔Identity Awareness > Captive Portal: LAN interface par ise simple login page ke saath enable karein lab testing ke liye.Identity Awareness > Captive Portal: enable it on the LAN interface with a simple login page for lab testing.

تصدیقVerifyVerify

لاگز matched rules پر صارف نام (صرف IPs نہیں) دکھائیں، اور غیر تصدیق شدہ ٹیسٹ کلائنٹ کے لیے captive portal صفحہ نظر آئے۔Logs matched rules par usernames (sirf IPs nahi) dikhayein, aur unauthenticated test client ke liye captive portal page nazar aaye.Logs show usernames (not just IPs) on matched rules, and the captive portal page appears for an unauthenticated test client.

fw tab -t userc_users -s

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ صارف پر مبنی رول کبھی میچ نہیں کرتا؛ ٹریفک cleanup rule پر گرتا ہے۔User-based rule kabhi match nahi karta; traffic cleanup rule par girta hai.User-based rule never matches; traffic falls to the cleanup rule.

✅ گیٹ وے صارف کی شناخت نہیں جانتا۔ شناخت کا ذریعہ چیک کریں (AD Query connectivity، agent انسٹال، یا captive portal متحرک) اور Logs & Monitor میں شناخت دیکھیں۔Gateway user ki identity nahi janta. Identity source check karein (AD Query connectivity, agent installed, ya captive portal triggered) aur Logs & Monitor mein identity dekhein.The gateway doesn't know the user's identity. Check the identity source (AD Query connectivity, agent installed, or captive portal triggered) and look for identity in Logs & Monitor.

⚠️ مہمانوں کے لیے captive portal صفحہ نظر نہیں آتا۔Guests ke liye captive portal page nazar nahi aata.Captive portal page doesn't appear for guests.

✅ تصدیق کریں کہ captive portal درست انٹرفیس پر چالو ہے اور شناخت والی allow rule cleanup rule سے اوپر ہے؛ چیک کریں کہ گیٹ وے portal صفحہ دے سکتا ہے (HTTPS)۔Verify karein ke captive portal sahi interface par enabled hai aur identity wali allow rule cleanup rule se upar hai; check karein ke gateway portal page serve kar sakta hai (HTTPS).Verify captive portal is enabled on the correct interface and that an allow rule with identity exists above the cleanup rule; check the gateway can serve the portal page (HTTPS).

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ Identity Awareness کو صارف کی پہچان کیسے ہوتی ہے؟Identity Awareness ko user ki pehchan kaise hoti hai?How does Identity Awareness learn who a user is?

Identity Awareness صارفین کو IPs سے جوڑتا ہے AD logon events، Identity Agent، captive portal، یا browser-based authentication جیسے ذرائع سے۔ پھر access rules میں source کے طور پر user/group آبجیکٹس استعمال ہو سکتے ہیں۔Identity Awareness users ko IPs se map karta hai AD logon events, Identity Agent, captive portal, ya browser-based authentication jaise sources se. Phir access rules mein source ke tor par user/group objects use ho sakte hain.Identity Awareness maps users to IPs using sources like AD logon events, the Identity Agent, captive portal, or browser-based authentication. Then access rules can use user/group objects as source.

❓ Captive portal کس لیے استعمال ہوتا ہے؟Captive portal kis liye use hota hai?What is the captive portal used for?

Captive portal نامعلوم صارف کو ٹریفک allow کرنے سے پہلے گیٹ وے کے لاگ اِن صفحے پر بھیجتا ہے — مہمانوں اور BYOD کے لیے مفید جہاں agent یا AD لاگ اِن موجود نہ ہو۔Captive portal unknown user ko traffic allow karne se pehle gateway ke login page par redirect karta hai — guests aur BYOD ke liye mufeed jahan agent ya AD logon maujood na ho.Captive portal redirects an unknown user to a login page on the gateway before allowing traffic — useful for guests and BYOD where no agent or AD logon exists.