Threat Prevention: IPS, Anti-Bot & SandBlast
Check Point — CCSA track EVE-NG — Check Point VM (SmartConsole + CLI)
مقصدObjectiveObjective
Threat Prevention blades چالو کریں (IPS، Anti-Bot، Anti-Virus، SandBlast)، Threat Prevention پالیسی میں profile لگائیں، اور لاگز میں بلاکس کی تصدیق کریں۔Threat Prevention blades enable karein (IPS, Anti-Bot, Anti-Virus, SandBlast), Threat Prevention policy mein profile apply karein, aur logs mein blocks verify karein.Enable Threat Prevention blades (IPS, Anti-Bot, Anti-Virus, SandBlast), apply a profile in the Threat Prevention policy, and verify blocks in logs.
آسان مثالSimple AnalogySimple Analogy
ایئرپورٹ سیکیورٹی کی تہوں کی طرح: IPS معروف ہتھیاروں کے لیے میٹل ڈیٹیکٹر ہے، Anti-Bot عجیب رویہ والے مسافروں کو دیکھتا ہے، اور SandBlast مشکوک سامان کو دھماکہ پروف کمرے میں کھولتا ہے۔Airport security ki layers ki tarah: IPS known weapons ke liye metal detector hai, Anti-Bot ajeeb behave karne wale passengers ko dekhta hai, aur SandBlast mashkook luggage ko blast-proof kamre mein kholta hai.Like airport security with layers: IPS is the metal detector for known weapons, Anti-Bot watches for passengers acting strangely, and SandBlast opens suspicious luggage in a blast-proof room.
سیٹ اپLab SetupLab Setup
EVE-NG گیٹ وے انٹرنیٹ رسائی کے ساتھ تاکہ blades اپ ڈیٹس لے سکیں؛ SmartConsole Threat Prevention view۔ ٹیسٹ ڈاؤن لوڈ (مثلاً EICAR ٹیسٹ فائل) آزمانا محفوظ ہے۔EVE-NG gateway internet access ke saath taake blades updates le sakein; SmartConsole Threat Prevention view. Test download (masalan EICAR test file) try karna safe hai.EVE-NG gateway with internet access so blades can fetch updates; SmartConsole Threat Prevention view. A test download (e.g. EICAR test file) is safe to try.
اقداماتStepsSteps
Step 1
گیٹ وے پر Threat Prevention blades چالو کریں اور انسٹال کریں۔ ہر blade ایک الگ inspection engine ہے جو ایک پالیسی شیئر کرتا ہے۔Gateway par Threat Prevention blades on karein aur install karein. Har blade ek alag inspection engine hai jo ek policy share karta hai.Turn on the Threat Prevention blades on the gateway and install. Each blade is a separate inspection engine sharing one policy.
🖱️ Gateway object > General > Network Security: IPS، Anti-Bot، Anti-Virus، Threat Emulation blades چالو کریں۔ Install Policy۔Gateway object > General > Network Security: IPS, Anti-Bot, Anti-Virus, Threat Emulation blades enable karein. Install Policy.Gateway object > General > Network Security: enable IPS, Anti-Bot, Anti-Virus, Threat Emulation blades. Install Policy.
Step 2
پالیسی پر Threat Prevention profile لگائیں۔ Profiles فی-blade actions (Prevent/Detect) یکجا کرتے ہیں تاکہ آپ ایک ترتیب سنبھالیں، سینکڑوں signatures نہیں۔Policy par Threat Prevention profile apply karein. Profiles per-blade actions (Prevent/Detect) bundle karte hain taake aap ek setting manage karein, sainkron signatures nahi.Apply a Threat Prevention profile to the policy. Profiles bundle per-blade actions (Prevent/Detect) so you manage one setting, not hundreds of signatures.
🖱️ Security Policies > Threat Prevention > Policy: اپنے گیٹ وے کے رولز پر Optimized (یا Strict) profile لگائیں۔Security Policies > Threat Prevention > Policy: apne gateway ke rules par Optimized (ya Strict) profile assign karein.Security Policies > Threat Prevention > Policy: assign the Optimized (or Strict) profile to your gateway's rules.
Step 3
ایک IPS protection ترتیب دے کر دیکھیں کہ overrides کیسے کام کرتے ہیں: profile defaults ہر جگہ لگتے ہیں، لیکن آپ ہر protection پر Prevent یا Detect نافذ کر سکتے ہیں۔Ek IPS protection tune karke dekhein ke overrides kaise kaam karte hain: profile defaults har jagah lagte hain, lekin aap har protection par Prevent ya Detect force kar sakte hain.Tune one IPS protection to see how overrides work: profile defaults apply everywhere, but you can force Prevent or Detect per protection.
🖱️ Threat Prevention > IPS Protections: ایک protection تلاش کریں، اس کا action Prevent سیٹ کریں، اور اس کی severity نوٹ کریں۔Threat Prevention > IPS Protections: ek protection search karein, us ka action Prevent set karein, aur us ki severity note karein.Threat Prevention > IPS Protections: search one protection, set its action to Prevent, and note its severity.
Step 4
SandBlast Threat Emulation چالو کریں: نامعلوم فائلیں ڈیلیوری سے پہلے کلاؤڈ sandbox میں detonate ہوتی ہیں — یہ آپ کا zero-day پکڑنے والا جال ہے۔SandBlast Threat Emulation enable karein: unknown files delivery se pehle cloud sandbox mein detonate hoti hain — yeh aap ka zero-day catch net hai.Enable SandBlast Threat Emulation: unknown files are detonated in the cloud sandbox before delivery — this is your zero-day catch net.
🖱️ Threat Prevention > Threat Emulation: ڈاؤن لوڈ/اپ لوڈ پر emulation چالو کریں، action Prevent۔Threat Prevention > Threat Emulation: download/upload par emulation enable karein, action Prevent.Threat Prevention > Threat Emulation: enable emulation on download/upload, action Prevent.
Step 5
EICAR ٹیسٹ فائل سے محفوظ ٹیسٹ کریں — بے ضرر ہے لیکن میلویئر کے طور پر flagged۔ تصدیق کریں کہ لاگ دکھاتا ہے کہ کس blade نے بلاک کیا اور کون سا profile لگا تھا۔EICAR test file se safe test karein — be-zarar hai lekin malware ke tor par flagged. Confirm karein ke log dikhata hai ke kis blade ne block kiya aur kaun sa profile laga tha.Test safely with the EICAR test file — harmless but flagged as malware. Confirm the log shows which blade blocked it and which profile was applied.
cpstat fw -f policy
🖱️ پالیسی انسٹال کریں، پھر LAN ہوسٹ سے EICAR ٹیسٹ فائل ڈاؤن لوڈ کریں؛ Logs & Monitor > Logs میں Anti-Virus/Emulation بلاک دیکھیں۔Policy install karein, phir LAN host se EICAR test file download karein; Logs & Monitor > Logs mein Anti-Virus/Emulation block dekhein.Install Policy, then from a LAN host download the EICAR test file; watch Logs & Monitor > Logs for the Anti-Virus/Emulation block.
تصدیقVerifyVerify
EICAR بلاک اور لاگ ہو blade name اور profile کے ساتھ؛ ترتیب شدہ IPS protection پالیسی میں آپ کا override دکھائے۔EICAR block aur log ho blade name aur profile ke saath; tuned IPS protection policy mein aap ka override dikhaye.EICAR is blocked and logged with blade name and profile; a tuned IPS protection shows your override in the policy.
cpstat fw -f policy fw stat
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ EICAR ٹیسٹ فائل بلاک ہوئے بغیر ڈاؤن لوڈ ہو جاتی ہے۔EICAR test file block hue baghair download ho jati hai.EICAR test file downloads without being blocked.
✅ چیک کریں کہ blades چالو ہیں اور Threat Prevention پالیسی (صرف Access Control نہیں) گیٹ وے پر انسٹال ہے؛ تصدیق کریں کہ profile action Prevent ہے، Detect نہیں۔Check karein ke blades enabled hain aur Threat Prevention policy (sirf Access Control nahi) gateway par installed hai; confirm karein ke profile action Prevent hai, Detect nahi.Check blades are enabled and the Threat Prevention policy (not just Access Control) is installed on the gateway; confirm the profile action is Prevent, not Detect.
⚠️ IPS چالو کرنے کے بعد جائز ایپلیکیشن ٹوٹ گئی۔IPS enable karne ke baad legitimate application toot gayi.Legitimate application broken after enabling IPS.
✅ لاگز میں بلاک کرنے والی protection تلاش کریں اور پوری blade بند کرنے کے بجائے اس ایک protection کو Detect پر سیٹ کریں (یا exception شامل کریں)۔Logs mein blocking protection dhoondein aur poori blade disable karne ke bajaye us ek protection ko Detect par set karein (ya exception add karein).Find the blocking protection in the logs and set that one protection to Detect (or add an exception) instead of disabling the whole blade.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ IPS بمقابلہ Anti-Bot بمقابلہ Anti-Virus — ہر ایک کیا کرتا ہے؟IPS vs Anti-Bot vs Anti-Virus — har ek kya karta hai?IPS vs Anti-Bot vs Anti-Virus — what does each do?
IPS signatures اور protocol inspection سے معروف حملے پکڑتا اور روکتا ہے۔ Anti-Bot متاثرہ مشینوں کو ان کے command-and-control رویے (DNS، غیر معمولی connections) سے پہچانتا ہے۔ Anti-Virus فائلوں میں معروف میلویئر اسکین کرتا ہے۔IPS signatures aur protocol inspection se known attacks detect aur block karta hai. Anti-Bot infected machines ko un ke command-and-control behavior (DNS, ghair mamooli connections) se pehchanta hai. Anti-Virus files mein known malware scan karta hai.IPS detects and blocks known attacks using signatures and protocol inspection. Anti-Bot detects infected machines by their command-and-control behavior (DNS, unusual connections). Anti-Virus scans files for known malware.
❓ SandBlast کیا ہے، اور Threat Prevention profiles کیا ہیں؟SandBlast kya hai, aur Threat Prevention profiles kya hain?What is SandBlast, and what are Threat Prevention profiles?
SandBlast Threat Emulation مشکوک فائلوں کو کلاؤڈ sandbox میں detonate کرتا ہے تاکہ zero-days پکڑے؛ Threat Extraction خطرناک مواد نکال کر محفوظ کاپی جلدی پہنچاتا ہے۔ Profiles blade ترتیبات کو یکجا کرتے ہیں تاکہ ایک پالیسی مستقل حفاظت کرے۔SandBlast Threat Emulation mashkook files ko cloud sandbox mein detonate karta hai taake zero-days pakre; Threat Extraction khatarnak content nikaal kar safe copy jaldi deliver karta hai. Profiles blade settings ko bundle karte hain taake ek policy mustaqil hifazat kare.SandBlast Threat Emulation detonates suspicious files in a cloud sandbox to catch zero-days; Threat Extraction strips risky content and delivers a safe copy fast. Profiles bundle blade settings so one policy protects consistently.