🎤 Check Point Firewall — Interview Q&A
❓ Check Point کا 3 درجے والا آرکیٹیکچر سمجھائیں۔Check Point 3-tier architecture samjhaein.Explain the Check Point 3-tier architecture.
Security Gateway (ٹریفک پر پالیسی نافذ کرتا ہے)، Security Management Server (پالیسی، آبجیکٹس، لاگز رکھتا ہے)، SmartConsole (ایڈمن GUI)۔ فائدہ: پالیسی ایک بار لکھیں، کئی گیٹ ویز پر انسٹال کریں۔Security Gateway (traffic par policy enforce karta hai), Security Management Server (policy, objects, logs rakhta hai), SmartConsole (admin GUI)۔ Faida: policy ek dafa likhein, kai gateways par install karein۔Security Gateway (enforces policy on traffic), Security Management Server (stores policy, objects, logs), SmartConsole (admin GUI). Benefit: write policy once, install to many gateways.
❓ SIC کیا ہے اور یہ کیوں اہم ہے؟SIC kya hai aur yeh kyun ahem hai?What is SIC and why does it matter?
مینجمنٹ اور گیٹ وے کے درمیان سرٹیفکیٹ پر مبنی اعتماد، ایک جیسی one-time ایکٹیویشن کی سے قائم ہوتا ہے۔ اس کے بغیر پالیسی انسٹالز اور لاگ کا بہاؤ ناکام ہوتے ہیں۔Management aur gateway ke darmiyan certificate-based trust, matching one-time activation key se establish hota hai. Is ke baghair policy installs aur log flow fail hote hain.Certificate-based trust between management and gateway, established with a matching one-time activation key. Without it, policy installs and log flow fail.
❓ Software Blades کیا ہیں؟ چند کے نام بتائیں۔Software Blades kya hain? Chand ke naam batayein.What are Software Blades? Name a few.
ہر گیٹ وے پر چالو لائسنس یافتہ ماڈیولز: Firewall، IPS، Anti-Bot، Anti-Virus، Application Control، URL Filtering، Threat Emulation (SandBlast)، Identity Awareness، VPN، DLP، HTTPS Inspection۔Har gateway par enabled licensed modules: Firewall, IPS, Anti-Bot, Anti-Virus, Application Control, URL Filtering, Threat Emulation (SandBlast), Identity Awareness, VPN, DLP, HTTPS Inspection۔Licensed modules enabled per gateway: Firewall, IPS, Anti-Bot, Anti-Virus, Application Control, URL Filtering, Threat Emulation (SandBlast), Identity Awareness, VPN, DLP, HTTPS Inspection.
❓ Check Point میں NAT جانچ کی ترتیب سمجھائیں۔Check Point mein NAT evaluation order samjhaein.Explain NAT evaluation order in Check Point.
Automatic NAT (آبجیکٹ پر سیٹ، مثلاً Hide) پہلے جانچا جاتا ہے؛ پھر manual NAT رولز اوپر سے نیچے۔ باہر جانے والے صارفین کے لیے Hide، سرورز شائع کرنے کے لیے Static one-to-one۔Automatic NAT (object par set, masalan Hide) pehle evaluate hota hai; phir manual NAT rules upar se neeche۔ Outbound users ke liye Hide, servers publish karne ke liye Static one-to-one۔Automatic NAT (set on the object, e.g. Hide) is evaluated first; then manual NAT rules top-down. Use Hide for outbound users, Static one-to-one to publish servers.
❓ Identity Awareness کیا ہے؟Identity Awareness kya hai?What is Identity Awareness?
یہ AD Query، Identity Agent، browser auth یا captive portal سے صارفین کو IPs سے جوڑتا ہے، تاکہ access rules صارف/گروپ Access Roles استعمال کر سکیں — شناخت پر مبنی کنٹرول، Zero Trust کا اصول۔Yeh AD Query, Identity Agent, browser auth ya captive portal se users ko IPs se map karta hai, taake access rules user/group Access Roles use kar sakein — identity-based control, Zero Trust ka usool۔It maps users to IPs via AD Query, Identity Agent, browser auth, or captive portal, so access rules can use user/group Access Roles — identity-based control, a Zero Trust principle.
❓ VPN community کیا ہے؟ Meshed بمقابلہ star؟VPN community kya hai? Meshed vs star?What is a VPN community? Meshed vs star?
VPN community بتاتی ہے کہ کون سے گیٹ ویز آپس میں ٹنل بنائیں گے — meshed (ہر ایک ہر ایک سے) یا star (مرکز + satellites، مثلاً HQ with branches)۔ ہر گیٹ وے کا encryption domain ان نیٹ ورکس کی فہرست ہے جنہیں VPN پر اجازت ہے۔VPN community define karti hai ke kaun se gateways aapas mein tunnel banayein ge — meshed (har ek har ek se) ya star (center + satellites, masalan HQ with branches)۔ Har gateway ka encryption domain un networks ki list hai jinhein VPN par ijazat hai۔A VPN community defines which gateways tunnel to each other — meshed (every-to-every) or star (center + satellites, e.g. HQ with branches). Each gateway's encryption domain lists the networks allowed on the VPN.
❓ SandBlast zero-day حملے کیسے روکتا ہے؟SandBlast zero-day attacks kaise rokta hai?How does SandBlast stop zero-day attacks?
SandBlast Threat Emulation نامعلوم فائلوں کو کلاؤڈ sandbox میں ML رویے کے تجزیے کے ساتھ detonate کرتا ہے تاکہ zero-days پکڑے؛ Threat Extraction فوراً محفوظ reconstructed کاپی پہنچاتا ہے۔ Zero-day = ایسا حملہ جس کا کوئی معروف signature نہ ہو۔SandBlast Threat Emulation unknown files ko cloud sandbox mein ML behavior analysis ke saath detonate karta hai taake zero-days pakre; Threat Extraction foran safe reconstructed copy deliver karta hai۔ Zero-day = aisa attack jis ka koi known signature na ho۔SandBlast Threat Emulation detonates unknown files in a cloud sandbox with ML behavior analysis to catch zero-days; Threat Extraction delivers a safe reconstructed copy immediately. Zero-day = attack with no known signature.
❓ Management API سے کیا automate کر سکتے ہیں؟Management API se kya automate kar sakte hain?What can you automate with the Management API?
mgmt_cli (یا REST API): لاگ اِن، آبجیکٹس اور رولز بنانا/بدلنا، تبدیلیاں شائع کرنا، پالیسی انسٹال، لاگ آؤٹ۔ یہ scripted، جائزہ شدہ، دہرائی جانے والی فائر وال تبدیلیاں اور Zero Trust orchestration ممکن بناتا ہے۔mgmt_cli (ya REST API): login, objects aur rules create/modify, changes publish, policy install, logout۔ Yeh scripted, reviewed, repeatable firewall changes aur Zero Trust orchestration enable karta hai۔mgmt_cli (or REST API): login, create/modify objects and rules, publish changes, install policy, logout. It enables scripted, reviewed, repeatable firewall changes and Zero Trust orchestration.