Site-to-Site VPN: Communities & Encryption Domains

Check Point — CCSA track EVE-NG — Check Point VM (SmartConsole + CLI)

مقصدObjectiveObjective

سائٹ ٹو سائٹ VPN بنائیں: star community ترتیب دیں، encryption domains بتائیں، اور ٹنل کی تصدیق کریں۔Site-to-site VPN banayein: star community configure karein, encryption domains define karein, aur tunnel verify karein.Build a site-to-site VPN: configure a star community, define encryption domains, and verify the tunnel.

آسان مثالSimple AnalogySimple Analogy

دو دفاتر کے درمیان نجی کوریئر روٹ کی طرح: VPN community وہ معاہدہ ہے کہ روٹ کون استعمال کر سکتا ہے، اور encryption domain ان عمارتوں کی فہرست ہے جن کی حفاظت ہر دفتر کرتا ہے۔Do offices ke darmiyan private courier route ki tarah: VPN community woh agreement hai ke route kaun use kar sakta hai, aur encryption domain un buildings ki list hai jin ki hifazat har office karta hai.Like a private courier route between two offices: a VPN community is the agreement on who can use the route, and the encryption domain is the list of buildings each office protects.

سیٹ اپLab SetupLab Setup

EVE-NG: دو چیک پوائنٹ گیٹ ویز (HQ اور Branch) WAN کلاؤڈ پر منسلک، ہر ایک کے پیچھے ایک LAN ہوسٹ۔ دونوں ایک ہی مینجمنٹ سرور سے منظم۔EVE-NG: do Check Point gateways (HQ aur Branch) WAN cloud par connected, har ek ke peeche ek LAN host. Dono ek hi management server se managed.EVE-NG: two Check Point gateways (HQ and Branch) connected over a WAN cloud, each with a LAN host behind it. Both managed by the same management server.

اقداماتStepsSteps

Step 1

دونوں گیٹ ویز پر IPsec VPN blade چالو کریں۔ Blade کے بغیر گیٹ وے کسی VPN community میں شامل نہیں ہو سکتا۔Dono gateways par IPsec VPN blade enable karein. Blade ke baghair gateway kisi VPN community mein shaamil nahi ho sakta.Enable the IPsec VPN blade on both gateways. Without the blade, a gateway can't join any VPN community.

🖱️ دونوں گیٹ وے آبجیکٹس > General > Network Security: VPN blade (IPsec VPN) چالو کریں۔Dono gateway objects > General > Network Security: VPN blade (IPsec VPN) enable karein.Both gateway objects > General > Network Security: enable the VPN blade (IPsec VPN).

Step 2

Star VPN community بنائیں: HQ مرکز ہے، Branch satellite۔ Branch ٹنلز HQ سے گزرتے ہیں — شاخوں کے لیے کلاسک hub-and-spoke۔Star VPN community banayein: HQ center hai, Branch satellite. Branch tunnels HQ se guzarte hain — branch offices ka classic hub-and-spoke.Create a star VPN community: HQ is the center, Branch is the satellite. Branch tunnels go through HQ — the classic hub-and-spoke for branch offices.

🖱️ Objects > VPN > Communities: ایک Star community بنائیں، HQ کو مرکز اور Branch کو satellite سیٹ کریں۔Objects > VPN > Communities: ek Star community banayein, HQ ko center aur Branch ko satellite set karein.Objects > VPN > Communities: create a Star community, set HQ as center and Branch as satellite.

Step 3

ہر گیٹ وے کا encryption domain (VPN domain) بتائیں: وہ LAN نیٹ ورکس جو ٹنل استعمال کر سکتے ہیں۔ صرف encryption domains کے درمیان ٹریفک encrypt ہوتا ہے۔Har gateway ka encryption domain (VPN domain) define karein: woh LAN networks jo tunnel use kar sakte hain. Sirf encryption domains ke darmiyan traffic encrypt hota hai.Define each gateway's encryption domain (VPN domain): the LAN networks that may use the tunnel. Only traffic between encryption domains gets encrypted.

🖱️ ہر گیٹ وے > Topology > VPN Domain: HQ کے پیچھے HQ_LAN اور Branch کے پیچھے Branch_LAN بتائیں (یا 'all IPs behind gateway based on topology' استعمال کریں)۔Har gateway > Topology > VPN Domain: HQ ke peeche HQ_LAN aur Branch ke peeche Branch_LAN define karein (ya 'all IPs behind gateway based on topology' use karein).Each gateway > Topology > VPN Domain: define HQ_LAN behind HQ and Branch_LAN behind Branch (or use 'all IPs behind gateway based on topology').

Step 4

Access rulebase میں VPN ٹریفک allow کریں، VPN کالم میں community کے ساتھ۔ Encryption access control کو نظرانداز نہیں کرتی — allow rule پھر بھی چاہیے۔Access rulebase mein VPN traffic allow karein, VPN column mein community ke saath. Encryption access control ko bypass nahi karti — allow rule phir bhi chahiye.Allow the VPN traffic in the access rulebase with the community in the VPN column. Encryption doesn't bypass access control — you still need the allow rule.

🖱️ Access Control: رول شامل کریں — Source HQ_LAN، Destination Branch_LAN، VPN = star community، Action Allow، Log۔Access Control: rule add karein — Source HQ_LAN, Destination Branch_LAN, VPN = star community, Action Allow, Log.Access Control: add a rule — Source HQ_LAN, Destination Branch_LAN, VPN = the star community, Action Allow, Log.

Step 5

دونوں گیٹ ویز پر پالیسی انسٹال کریں۔ دونوں طرف community اور مطابقتی domains ہونے پر ٹنل خود negotiate ہو جاتا ہے (IKE)۔Dono gateways par policy install karein. Dono taraf community aur matching domains hone par tunnel khud negotiate ho jata hai (IKE).Install policy on both gateways. The tunnel negotiates automatically (IKE) once both sides have the community and matching domains.

🖱️ دونوں گیٹ ویز پر Install Policy۔ ٹاسک لاگ میں کامیاب VPN configuration push دیکھیں۔Dono gateways par Install Policy. Task log mein kamyab VPN configuration push dekhein.Install Policy on both gateways. Watch the task log for successful VPN configuration push.

Step 6

Expert CLI سے تصدیق کریں: ٹنل کی حیثیت اور IKE تفصیلات چیک کریں، پھر HQ_LAN ہوسٹ سے Branch_LAN ہوسٹ کو ping کریں اور لاگز میں encrypted ٹریفک کی تصدیق کریں۔Expert CLI se verify karein: tunnel status aur IKE details check karein, phir HQ_LAN host se Branch_LAN host ko ping karein aur logs mein encrypted traffic confirm karein.Verify from expert CLI: check tunnel status and IKE details, then ping Branch_LAN host from HQ_LAN host and confirm encrypted traffic in the logs.

vpn tu
vpn ver -k

تصدیقVerifyVerify

vpn tu میں ٹنل up دکھے، LAN ہوسٹس کے درمیان ping کامیاب ہو، اور لاگز ٹریفک کو star community کے تحت encrypted دکھائیں۔vpn tu mein tunnel up dikhe, LAN hosts ke darmiyan ping kamyab ho, aur logs traffic ko star community ke tehet encrypted dikhayein.Tunnel shows up in vpn tu, pings between LAN hosts succeed, and logs show the traffic as encrypted under the star community.

vpn tu
vpn ver -k

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ ٹنل کبھی up نہیں ہوتا۔Tunnel kabhi up nahi hota.Tunnel never comes up.

✅ چیک کریں کہ دونوں گیٹ ویز community میں ہیں، VPN domains overlap نہیں کرتے، external IPs کے درمیان IKE گزر سکتا ہے (UDP 500/4500)، اور دونوں پالیسیاں کامیاب انسٹال ہوئی ہیں۔Check karein ke dono gateways community mein hain, VPN domains overlap nahi karte, external IPs ke darmiyan IKE guzar sakta hai (UDP 500/4500), aur dono policies kamyab install hui hain.Check both gateways are in the community, VPN domains don't overlap, IKE can pass between external IPs (UDP 500/4500), and both policies installed successfully.

⚠️ ٹنل up ہے لیکن ٹریفک نہیں گزرتا۔Tunnel up hai lekin traffic nahi guzarta.Tunnel is up but no traffic passes.

✅ Access rulebase میں allow غائب ہے: دونوں LANs کے لیے VPN کالم میں community والا رول شامل کریں، اور چیک کریں کہ NAT VPN ٹریفک translate نہ کر رہا ہو (VPN domains کو NAT سے خارج کریں)۔Access rulebase mein allow missing hai: dono LANs ke liye VPN column mein community wala rule add karein, aur check karein ke NAT VPN traffic translate na kar raha ho (VPN domains ko NAT se exclude karein).The access rulebase is missing the allow: add a rule with the community in the VPN column for the two LANs, and check NAT isn't translating VPN traffic (exclude VPN domains from NAT).

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ Meshed بمقابلہ star VPN community — فرق کیا ہے؟Meshed vs star VPN community — farq kya hai?Meshed vs star VPN community — what's the difference?

Meshed community ہر گیٹ وے کو ہر دوسرے گیٹ وے سے براہِ راست جوڑتی ہے۔ Star community میں ایک مرکزی گیٹ وے ہوتا ہے اور satellites صرف مرکز سے بات کرتے ہیں — HQ اور کئی شاخوں کے لیے عام۔Meshed community har gateway ko har doosre gateway se direct jorta hai. Star community mein ek center gateway hota hai aur satellites sirf center se baat karte hain — HQ aur kai branches ke liye typical.A meshed community connects every gateway to every other gateway directly. A star community has one center gateway and satellites that only talk to the center — typical for HQ with many branches.

❓ Encryption domain کیا ہے؟Encryption domain kya hai?What is an encryption domain?

Encryption domain گیٹ وے کے پیچھے ان نیٹ ورکس کا مجموعہ ہے جنہیں VPN استعمال کی اجازت ہے۔ دو گیٹ ویز کے encryption domains کے درمیان ٹریفک encrypt ہوتا ہے؛ باقی سب کھلے میں جاتا ہے (یا drop ہوتا ہے)۔Encryption domain gateway ke peeche un networks ka set hai jinhein VPN use karne ki ijazat hai. Do gateways ke encryption domains ke darmiyan traffic encrypt hota hai; baqi sab clear mein jata hai (ya drop hota hai).The encryption domain is the set of networks behind a gateway that are allowed to use the VPN. Traffic between two gateways' encryption domains gets encrypted; traffic to anything else goes out in clear (or is dropped).