Capstone: Check Point Build

Check Point — CCSA track EVE-NG — Check Point VM (SmartConsole + CLI)

مقصدObjectiveObjective

مکمل Check Point deployment کریں: آرکیٹیکچر، ایکسس پالیسی، NAT، شناخت، VPN، threat prevention، لاگنگ اور API — شروع سے آخر تک تصدیق شدہ۔Mukammal Check Point deployment karein: architecture, access policy, NAT, identity, VPN, threat prevention, logging aur API — end to end verified.Complete a full Check Point deployment: architecture, access policy, NAT, identity, VPN, threat prevention, logging, and API — verified end to end.

آسان مثالSimple AnalogySimple Analogy

آخری عمارت کے معائنے کی طرح: ہر نظام — ڈھانچہ، وائرنگ، الارمز — بلیو پرنٹ کے خلاف چیک ہوتا ہے اس سے پہلے کہ کوئی اندر آئے۔Final building inspection ki tarah: har system — structure, wiring, alarms — blueprint ke khilaf check hota hai is se pehle ke koi andar aaye.Like a final building inspection: every system — structure, wiring, alarms — gets checked against the blueprint before anyone moves in.

سیٹ اپLab SetupLab Setup

EVE-NG: دو چیک پوائنٹ گیٹ ویز (HQ + Branch) WAN لنک کے ساتھ، LAN ہوسٹس، ایک DMZ سرور، اور ایک مینجمنٹ سرور۔ پچھلے تمام اسباق کی configs آپ کا نقطہ آغاز ہیں۔EVE-NG: do Check Point gateways (HQ + Branch) WAN link ke saath, LAN hosts, ek DMZ server, aur ek management server. Pichle tamam lessons ki configs aap ka starting point hain.EVE-NG: two Check Point gateways (HQ + Branch) with WAN link, LAN hosts, a DMZ server, and one management server. All previous lessons' configs are your starting point.

اقداماتStepsSteps

Step 1

چیک پوائنٹ 1 — اعتماد: تصدیق کریں کہ دونوں گیٹ ویز پر SIC initialized ہے۔ اعتماد کے بغیر کچھ کام نہیں کرے گا۔Checkpoint 1 — trust: confirm karein ke dono gateways par SIC initialized hai. Trust ke baghair kuch kaam nahi karega.Checkpoint 1 — trust: confirm SIC is initialized on both gateways. Nothing else works without trust.

cpstat fw
fw stat

🖱️ تصدیق کریں کہ دونوں گیٹ ویز اور مینجمنٹ پر SIC اعتماد Initialized ہے؛ سب سے پہلے کوئی SIC مسئلہ حل کریں۔Verify karein ke dono gateways aur management par SIC trust Initialized hai; sab se pehle koi SIC issue fix karein.Verify SIC trust is Initialized on both gateways and management; fix any SIC issue before anything else.

Step 2

چیک پوائنٹ 2 — ٹوپالوجی: WAN External، LAN Internal، anti-spoofing چالو، دونوں گیٹ ویز پر زونز دستاویزی۔Checkpoint 2 — topology: WAN External, LAN Internal, anti-spoofing enabled, dono gateways par zones documented.Checkpoint 2 — topology: WAN External, LAN Internal, anti-spoofing enabled, zones documented on both gateways.

🖱️ دونوں گیٹ ویز پر ٹوپالوجی کا جائزہ لیں: WAN=External، LAN=Internal، anti-spoofing on؛ سیکیورٹی زونز دستاویزی تصدیق کریں۔Dono gateways par topology review karein: WAN=External, LAN=Internal, anti-spoofing on; security zones documented confirm karein.Review topology on both gateways: WAN=External, LAN=Internal, anti-spoofing on; confirm security zones documented.

Step 3

چیک پوائنٹ 3 — ایکسس پالیسی: ترتیب شدہ rulebase stealth rule کے ساتھ پہلے، مخصوص allows، inline layer، اور cleanup rule آخر میں۔ دونوں گیٹ ویز پر انسٹال کریں۔Checkpoint 3 — access policy: ordered rulebase stealth rule ke saath pehle, specific allows, inline layer, aur cleanup rule aakhir mein. Dono gateways par install karein.Checkpoint 3 — access policy: ordered rulebase with stealth rule first, specific allows, inline layer, and cleanup rule last. Install on both gateways.

🖱️ Access rulebase کا جائزہ لیں: stealth rule، ترتیب شدہ allows، سرور رول پر inline layer، آخر میں cleanup drop+log۔Access rulebase review karein: stealth rule, ordered allows, server rule par inline layer, aakhir mein cleanup drop+log.Review the access rulebase: stealth rule, ordered allows, inline layer on the server rule, cleanup drop+log at the end.

Step 4

چیک پوائنٹ 4 — NAT: outbound Hide NAT کام کرے، inbound static NAT DMZ سرور تک پہنچے، لاگز دونوں translations دکھائیں۔Checkpoint 4 — NAT: outbound Hide NAT kaam kare, inbound static NAT DMZ server tak pahunche, logs dono translations dikhayein.Checkpoint 4 — NAT: outbound Hide NAT works, inbound static NAT reaches the DMZ server, logs show both translations.

fw tab -t nat_table -s

🖱️ LANs کے لیے Hide NAT اور DMZ سرور کے لیے manual static NAT کی تصدیق کریں؛ براؤزنگ اور inbound سرور رسائی ٹیسٹ کریں۔LANs ke liye Hide NAT aur DMZ server ke liye manual static NAT verify karein; browsing aur inbound server access test karein.Verify Hide NAT for LANs and the manual static NAT for the DMZ server; test browsing and inbound server access.

Step 5

چیک پوائنٹ 5 — VPN: star community ٹنل up، LAN-to-LAN pings encrypted، encryption domains درست۔Checkpoint 5 — VPN: star community tunnel up, LAN-to-LAN pings encrypted, encryption domains sahi.Checkpoint 5 — VPN: star community tunnel up, LAN-to-LAN pings encrypted, encryption domains correct.

vpn tu

🖱️ تصدیق کریں کہ HQ اور Branch کے درمیان star community ٹنل up ہے؛ VPN allow rule اور encryption domains کی تصدیق کریں۔Confirm karein ke HQ aur Branch ke darmiyan star community tunnel up hai; VPN allow rule aur encryption domains verify karein.Confirm the star community tunnel is up between HQ and Branch; verify the VPN allow rule and encryption domains.

Step 6

چیک پوائنٹ 6 — threat prevention: blades profile کے ساتھ چالو، SandBlast emulation on، EICAR بلاک اور لاگ شدہ۔Checkpoint 6 — threat prevention: blades profile ke saath enabled, SandBlast emulation on, EICAR blocked aur logged.Checkpoint 6 — threat prevention: blades enabled with a profile, SandBlast emulation on, EICAR blocked and logged.

🖱️ تصدیق کریں کہ Threat Prevention blades on ہیں، profile لگا ہے، SandBlast emulation چالو ہے؛ EICAR ٹیسٹ چلائیں اور بلاک لاگ چیک کریں۔Confirm karein ke Threat Prevention blades on hain, profile applied hai, SandBlast emulation enabled hai; EICAR test chalayein aur block log check karein.Confirm Threat Prevention blades on, profile applied, SandBlast emulation enabled; run the EICAR test and check the block log.

Step 7

چیک پوائنٹ 7 — نگرانی و automation: لاگز SmartEvent میں جاری، mgmt_cli smoke ٹیسٹ کامیاب، اور build دستاویزی۔Checkpoint 7 — visibility & automation: logs SmartEvent mein flowing, mgmt_cli smoke test kamyab, aur build documented.Checkpoint 7 — visibility & automation: logs flowing to SmartEvent, an mgmt_cli smoke test succeeds, and the build is documented.

mgmt_cli -r true login > id.txt
mgmt_cli -s id.txt show access-rulebase limit 3
mgmt_cli -s id.txt logout

🖱️ SmartLog/SmartEvent میں حتمی جائزہ: لاگز جاری، شناختیں نظر آ رہی ہیں، کوئی غیر متوقع drops نہیں۔ پوری build دستاویز کریں۔SmartLog/SmartEvent mein final review: logs flowing, identities visible, koi ghair matuqa drops nahi. Poori build document karein.Final review in SmartLog/SmartEvent: logs flowing, identities visible, no unexpected drops. Document the whole build.

تصدیقVerifyVerify

سات چیک پوائنٹس پاس: اعتماد، ٹوپالوجی، پالیسی، NAT، VPN، threat prevention، اور لاگنگ/automation — ہر ایک کے لیے لاگز میں ثبوت۔Saat checkpoints pass: trust, topology, policy, NAT, VPN, threat prevention, aur logging/automation — har ek ke liye logs mein evidence.All seven checkpoints pass: trust, topology, policy, NAT, VPN, threat prevention, and logging/automation — with evidence in logs for each.

fw stat
vpn tu
cpstat fw -f policy

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ پالیسی HQ پر انسٹال ہوتی ہے لیکن Branch پر ناکام۔Policy HQ par install hoti hai lekin Branch par fail.Policy installs on HQ but fails on Branch.

✅ الگ کریں: Branch SIC، Branch ٹوپالوجی کی معتبریت، اور Branch مخصوص آبجیکٹس چیک کریں۔ Access Control اور Threat Prevention الگ الگ انسٹال کرکے دیکھیں کہ کون ناکام ہوتا ہے۔Isolate karein: Branch SIC, Branch topology validity, aur Branch-specific objects check karein. Access Control aur Threat Prevention alag alag install karke dekhein ke kaun fail hota hai.Isolate it: check Branch SIC, Branch topology validity, and Branch-specific objects. Install Access Control and Threat Prevention separately to see which one fails.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ اپنا Check Point deployment چیک لسٹ سمجھائیں۔Apna Check Point deployment checklist samjhaein.Walk me through your Check Point deployment checklist.

مضبوط جواب چیک لسٹ پر چلتا ہے: SIC صحت مند، ٹوپالوجی + anti-spoofing، ترتیب شدہ rulebase cleanup rule کے ساتھ، NAT دونوں طرف تصدیق شدہ، VPN ٹنلز up، blades profiles کے ساتھ on، logging جاری، پالیسی ہر جگہ انسٹال، اور ایک API smoke ٹیسٹ۔Mazboot jawab checklist par chalta hai: SIC healthy, topology + anti-spoofing, ordered rulebase cleanup rule ke saath, NAT dono taraf verified, VPN tunnels up, blades profiles ke saath on, logging flowing, policy har jagah installed, aur ek API smoke test.A solid answer walks the checklist: SIC healthy, topology + anti-spoofing, ordered rulebase with cleanup rule, NAT verified both ways, VPN tunnels up, blades on with profiles, logging flowing, policy installed everywhere, and one API smoke test.