Interfaces, Zones & Routing Basics
FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)
مقصدObjectiveObjective
اس لیب میں آپ انٹرفیس رولز سیٹ کریں گے، زونز بنائیں گے اور اسٹیٹک روٹس کنفیگر کر کے FortiGate کو نیٹ ورک میں روٹنگ کے قابل بنائیں گے۔Is lab mein aap interface roles set karenge, zones banayenge aur static routes configure kar ke FortiGate ko network mein routing ke qabil banayenge.In this lab you will set interface roles, create zones, and configure static routes to make the FortiGate routable in the network.
آسان مثالSimple AnalogySimple Analogy
زونز ایسے ہیں جیسے عمارت کے حصے — لابی (WAN)، دفاتر (LAN)، سرور روم (DMZ)۔ ہر حصے کے اپنے دروازے (انٹرفیس) اور اپنے اصول (پالیسیز) ہوتے ہیں۔Zones aise hain jaise imarat ke hisse — lobby (WAN), dafatir (LAN), server room (DMZ). Har hisse ke apne darwaze (interfaces) aur apne usool (policies) hote hain.Zones are like sections of a building — lobby (WAN), offices (LAN), server room (DMZ). Each section has its own doors (interfaces) and its own rules (policies).
سیٹ اپLab SetupLab Setup
fg-01 والی FortiGate استعمال کریں۔ ٹوپولوجی: port1 = WAN (203.0.113.2/24، گیٹ وے 203.0.113.1)، port2 = LAN (192.168.10.1/24)، port3 = DMZ (10.10.10.1/24)۔fg-01 wali FortiGate istemal karen. Topology: port1 = WAN (203.0.113.2/24, gateway 203.0.113.1), port2 = LAN (192.168.10.1/24), port3 = DMZ (10.10.10.1/24).Use the fg-01 FortiGate. Topology: port1 = WAN (203.0.113.2/24, gateway 203.0.113.1), port2 = LAN (192.168.10.1/24), port3 = DMZ (10.10.10.1/24).
اقداماتStepsSteps
Step 1
ہر انٹرفیس کو اس کا رول دیں — WAN باہر کی طرف، LAN اندر کی طرف، DMZ سرورز کے لیے۔ رول سے GUI میں انٹرفیس کی پہچان آسان ہوتی ہے۔Har interface ko us ka role den — WAN bahar ki taraf, LAN andar ki taraf, DMZ servers ke liye. Role se GUI mein interface ki pehchan aasan hoti hai.Give each interface its role — WAN facing outside, LAN facing inside, DMZ for servers. Roles make interfaces easy to identify in the GUI.
config system interface
edit port1
set role wan
next
edit port2
set role lan
next
edit port3
set role dmz
next
end🖱️ Network > Interfaces میں ہر انٹرفیس ایڈٹ کر کے Role سیٹ کریں۔Network > Interfaces mein har interface edit kar ke Role set karen.Set the Role for each interface by editing it under Network > Interfaces.
Step 2
LAN اور DMZ انٹرفیسز پر IP ایڈریس لگائیں۔ یہ ان کے نیٹ ورکس کے ڈیفالٹ گیٹ وے بنیں گے۔LAN aur DMZ interfaces par IP address lagayen. Yeh un ke networks ke default gateway banenge.Assign IP addresses to the LAN and DMZ interfaces. These become the default gateways for their networks.
config system interface
edit port1
set ip 203.0.113.2/24
set allowaccess ping
next
edit port2
set ip 192.168.10.1/24
set allowaccess ping
next
edit port3
set ip 10.10.10.1/24
set allowaccess ping
next
end🖱️ Network > Interfaces میں IP/Netmask فیلڈز بھریں۔Network > Interfaces mein IP/Netmask fields bharen.Fill in the IP/Netmask fields under Network > Interfaces.
Step 3
زون بنائیں — زون ایک سے زیادہ انٹرفیسز کا گروپ ہے۔ مثال کے طور پر LAN_Zone میں port2 اور port3 رکھیں تاکہ ایک پالیسی دونوں پر لاگو ہو۔Zone banayen — zone aik se zyada interfaces ka group hai. Misal ke taur par LAN_Zone mein port2 aur port3 rakhen taake aik policy dono par lago ho.Create a zone — a zone is a group of multiple interfaces. For example, put port2 and port3 in LAN_Zone so one policy applies to both.
config system zone
edit LAN_Zone
set interface port2 port3
next
end🖱️ Network > Zones میں Create New > Zone — نام دیں اور انٹرفیس منتخب کریں۔Network > Zones mein Create New > Zone — naam den aur interfaces muntakhib karen.Go to Network > Zones, Create New > Zone — give a name and select interfaces.
Step 4
ڈیفالٹ اسٹیٹک روٹ بنائیں تاکہ انٹرنیٹ کی طرف جانے والا ٹریفک WAN گیٹ وے سے نکلے۔ dst 0.0.0.0/0 کا مطلب ہے 'ہر منزل'۔Default static route banayen taake internet ki taraf jaane wala traffic WAN gateway se nikle. dst 0.0.0.0/0 ka matlab hai 'har manzil'.Create a default static route so traffic toward the internet exits via the WAN gateway. dst 0.0.0.0/0 means 'every destination'.
config router static
edit 1
set dst 0.0.0.0/24
set gateway 203.0.113.1
set device port1
next
end🖱️ Network > Static Routes میں Create New — Destination 0.0.0.0/0، Gateway 203.0.113.1، Interface port1۔Network > Static Routes mein Create New — Destination 0.0.0.0/0, Gateway 203.0.113.1, Interface port1.Under Network > Static Routes, Create New — Destination 0.0.0.0/0, Gateway 203.0.113.1, Interface port1.
Step 5
نوٹ: اوپر والے قدم میں جان بوجھ کر ایک عام غلطی رکھی گئی ہے — درست کرنے کے لیے اگلا قدم دیکھیں۔ پہلے روٹنگ ٹیبل چیک کریں۔Note: oopar wale qadam mein jaan boojh kar aik aam ghalti rakhi gayi hai — durust karne ke liye agla qadam dekhen. Pehle routing table check karen.Note: the previous step deliberately contains a common mistake — see the next step to fix it. First check the routing table.
get router info routing-table all
Step 6
غلطی درست کریں: ڈیفالٹ روٹ کا dst 0.0.0.0/24 نہیں بلکہ 0.0.0.0/0 ہونا چاہیے۔ غلط ماسک سے ڈیفالٹ روٹ کام نہیں کرے گا۔Ghalti durust karen: default route ka dst 0.0.0.0/24 nahi balke 0.0.0.0/0 hona chahiye. Ghalat mask se default route kaam nahi karega.Fix the mistake: a default route's dst must be 0.0.0.0/0, not 0.0.0.0/24. A wrong mask breaks the default route.
config router static
edit 1
set dst 0.0.0.0/0
next
end
get router info routing-table allتصدیقVerifyVerify
روٹنگ ٹیبل میں تینوں کنیکٹڈ نیٹ ورکس (S اور C روٹس) اور ڈیفالٹ روٹ (0.0.0.0/0 via 203.0.113.1) نظر آنا چاہیے۔ LAN ہوسٹ سے 8.8.8.8 پنگ بھی ٹیسٹ کریں۔Routing table mein teenon connected networks (S aur C routes) aur default route (0.0.0.0/0 via 203.0.113.1) nazar aana chahiye. LAN host se 8.8.8.8 ping bhi test karen.The routing table should show all three connected networks (S and C routes) plus the default route (0.0.0.0/0 via 203.0.113.1). Also test ping to 8.8.8.8 from a LAN host.
get router info routing-table all execute ping 8.8.8.8
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ ڈیفالٹ روٹ بنانے کے باوجود انٹرنیٹ نہیں چل رہا۔Default route banane ke bawajood internet nahi chal raha.Internet still not working despite a default route.
✅ روٹ کا dst ماسک چیک کریں (0.0.0.0/0 ہونا چاہیے)، device درست انٹرفیس ہو، اور گیٹ وے اسی سب نیٹ میں reachable ہو۔ get router info routing-table all سے تصدیق کریں۔Route ka dst mask check karen (0.0.0.0/0 hona chahiye), device durust interface ho, aur gateway usi subnet mein reachable ho. get router info routing-table all se tasdeeq karen.Check the route's dst mask (must be 0.0.0.0/0), that device is the correct interface, and that the gateway is reachable in the same subnet. Confirm with get router info routing-table all.
⚠️ زون بنانے کے بعد پالیسی میں انٹرفیس نظر نہیں آ رہا۔Zone banane ke baad policy mein interface nazar nahi aa raha.Interface not visible in the policy after creating a zone.
✅ جب انٹرفیس زون کا ممبر بن جائے تو پالیسی میں انفرادی انٹرفیس کے بجائے زون کا نام استعمال کریں۔ دونوں ایک ساتھ استعمال نہیں ہو سکتے۔Jab interface zone ka member ban jaye to policy mein infiradi interface ke bajaye zone ka naam istemal karen. Dono aik saath istemal nahi ho sakte.Once an interface joins a zone, use the zone name in policies instead of the individual interface. Both cannot be used together.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ FortiGate میں زون کیوں استعمال کرتے ہیں؟FortiGate mein zone kyun istemal karte hain?Why use zones in FortiGate?
زون ایک سے زیادہ انٹرفیسز کو ایک نام دے دیتا ہے، تو ایک فائر وال پالیسی کئی انٹرفیسز پر لاگو ہو جاتی ہے۔ اس سے پالیسیز کم اور مینجمنٹ آسان ہوتی ہے۔Zone aik se zyada interfaces ko aik naam de deta hai, to aik firewall policy kai interfaces par lago ho jati hai. Is se policies kam aur management aasan hoti hai.A zone gives multiple interfaces one name, so a single firewall policy applies to several interfaces. This means fewer policies and easier management.
❓ انٹرفیس رول (lan/wan/dmz) کا کیا فائدہ ہے؟Interface role (lan/wan/dmz) ka kya faida hai?What is the benefit of interface roles (lan/wan/dmz)?
رول صرف ایک لیبل ہے جو GUI میں انٹرفیس کی پہچان آسان بناتا ہے اور کچھ فیچرز (جیسے DHCP سرور وزرڈ) کو متعلقہ انٹرفیسز دکھاتا ہے۔ یہ خود ٹریفک بلاک یا الاؤ نہیں کرتا۔Role sirf aik label hai jo GUI mein interface ki pehchan aasan banata hai aur kuch features (jaise DHCP server wizard) ko mutalliqa interfaces dikhata hai. Yeh khud traffic block ya allow nahi karta.A role is just a label that makes interfaces easy to identify in the GUI and shows relevant interfaces to some features (like the DHCP server wizard). It does not block or allow traffic by itself.