Firewall Policies & Objects
FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)
مقصدObjectiveObjective
اس لیب میں آپ ایڈریس اور سروس آبجیکٹس بنائیں گے اور درست سورس، ڈیسٹینیشن، سروس، ایکشن اور لاگنگ کے ساتھ فائر وال پالیسی بنائیں گے۔Is lab mein aap address aur service objects banayenge aur durust source, destination, service, action aur logging ke saath firewall policy banayenge.In this lab you will create address and service objects and build a firewall policy with the correct source, destination, service, action, and logging.
آسان مثالSimple AnalogySimple Analogy
آبجیکٹس ایسے ہیں جیسے فون بک میں سیو کی ہوئی کونٹیکٹ — ہر بار نمبر (IP) ٹائپ کرنے کے بجائے نام سے کام ہوتا ہے۔ پالیسیز ایسی ہیں جیسے سوسائٹی کے اصول: پہلے نام چیک ہوتا ہے، پھر کون سے دروازے سے جانا الاؤڈ ہے۔Objects aise hain jaise phone book mein save ki hui contact — har baar number (IP) type karne ke bajaye naam se kaam hota hai. Policies aisi hain jaise society ke usool: pehle naam check hota hai, phir kaun se darwaze se jaana allowed hai.Objects are like saved contacts in a phone book — instead of typing the number (IP) each time, you call the name. Policies are like society rules: check name first, then which door you are allowed to enter.
سیٹ اپLab SetupLab Setup
fg-02 والی FortiGate استعمال کریں: port2 پر LAN 192.168.10.0/24، port1 پر WAN۔ مقصد: LAN ہوسٹس کو HTTP/HTTPS پر انٹرنیٹ براؤزنگ کی اجازت دینا اور لاگنگ آن کرنا۔fg-02 wali FortiGate istemal karen: port2 par LAN 192.168.10.0/24, port1 par WAN. Maqsad: LAN hosts ko HTTP/HTTPS par internet browsing ki ijazat dena aur logging on karna.Use the fg-02 FortiGate: LAN 192.168.10.0/24 on port2, WAN on port1. Goal: allow LAN hosts to browse the internet over HTTP/HTTPS with logging.
اقداماتStepsSteps
Step 1
LAN سب نیٹ کے لیے ایڈریس آبجیکٹ بنائیں۔ اسے نام (LAN_NET) دینے سے پالیسیز پڑھنا آسان ہوتا ہے۔LAN subnet ke liye address object banayen. Ise naam (LAN_NET) dene se policies parhna aasan hota hai.Create an address object for the LAN subnet. Giving it a name (LAN_NET) makes policies easy to read.
config firewall address
edit LAN_NET
set subnet 192.168.10.0 255.255.255.0
next
end🖱️ Policy & Objects > Addresses میں Create New > Address پر جائیں۔Policy & Objects > Addresses mein Create New > Address par jayen.Go to Policy & Objects > Addresses, Create New > Address.
Step 2
ایڈریس گروپ بنائیں۔ گروپ کئی ایڈریسز کو ایک ساتھ رکھتا ہے تاکہ ایک پالیسی لائن کئی سرورز کو کور کرے — DMZ سرور فارم کے لیے مفید۔Address group banayen. Group kai addresses ko aik saath rakhta hai taake aik policy line kai servers ko cover kare — DMZ server farm ke liye mufeed.Create an address group. Groups bundle several addresses so one policy line covers many servers — useful for DMZ server farms.
config firewall addrgrp
edit SERVERS
set member WEB_SRV
next
end🖱️ Policy & Objects > Addresses میں Create New > Address Group پر جائیں۔Policy & Objects > Addresses mein Create New > Address Group par jayen.Go to Policy & Objects > Addresses, Create New > Address Group.
Step 3
TCP پورٹ 8080 کے لیے کسٹم سروس آبجیکٹ بنائیں۔ HTTP اور HTTPS جیسے بلٹ اِن سروسز پہلے سے موجود ہوتے ہیں۔TCP port 8080 ke liye custom service object banayen. HTTP aur HTTPS jaise built-in services pehle se mojood hote hain.Create a custom service object for TCP port 8080. Built-in services like HTTP and HTTPS already exist.
config firewall service custom
edit TCP_8080
set tcp-portrange 8080
next
end🖱️ Policy & Objects > Services میں Create New > Service پر جائیں۔Policy & Objects > Services mein Create New > Service par jayen.Go to Policy & Objects > Services, Create New > Service.
Step 4
LAN-to-WAN پالیسی بنائیں۔ ہر فیلڈ ایک گیٹ ہے: صرف وہ ٹریفک گزرتا ہے جو سب فیلڈز (سورس، ڈیسٹینیشن، سروس) سے میچ کرے۔ logtraffic all ہر سیشن ریکارڈ کرتا ہے۔LAN-to-WAN policy banayen. Har field aik gate hai: sirf woh traffic guzarta hai jo SAB fields (source, destination, service) se match kare. logtraffic all har session record karta hai.Create the LAN-to-WAN policy. Each field is a gate: only traffic matching ALL fields (source, destination, service) passes. logtraffic all records every session.
config firewall policy
edit 1
set name LAN-to-WAN
set srcintf port2
set dstintf port1
set srcaddr LAN_NET
set dstaddr all
set service HTTP HTTPS
set schedule always
set action accept
set logtraffic all
set nat enable
next
end🖱️ Policy & Objects > Firewall Policy میں Create New — Incoming Interface، Outgoing Interface، Source، Destination، Service، Action ACCEPT بھریں اور Log Traffic آن کریں۔Policy & Objects > Firewall Policy mein Create New — Incoming Interface, Outgoing Interface, Source, Destination, Service, Action ACCEPT bharen aur Log Traffic on karen.Go to Policy & Objects > Firewall Policy, Create New — fill Incoming Interface, Outgoing Interface, Source, Destination, Service, Action ACCEPT, and enable Log Traffic.
Step 5
move کمانڈ سے پالیسیز کا آرڈر تبدیل کریں۔ مثال: move 2 before 1 پالیسی 2 کو پالیسی 1 کے اوپر لے آتا ہے۔ خاص رولز ہمیشہ عام رولز سے اوپر ہوتے ہیں۔move command se policies ka order tabdeel karen. Misal: move 2 before 1 policy 2 ko policy 1 ke oopar le aata hai. Khaas rules hamesha aam rules se oopar hote hain.Reorder policies with the move command. Example: move 2 before 1 puts policy 2 above policy 1. Specific rules always go above general rules.
config firewall policy
move 2 before 1
end🖱️ Policy & Objects > Firewall Policy لسٹ میں پالیسیز کو ڈریگ کر کے آرڈر تبدیل کریں۔Policy & Objects > Firewall Policy list mein policies ko drag kar ke order tabdeel karen.Drag policies in the Policy & Objects > Firewall Policy list to change their order.
Step 6
پالیسی کے کنٹینٹس ویریفائی کریں اور چیک کریں کہ یہ سیشن ٹیبل میں ایکٹیو ہے۔Policy ke contents verify karen aur check karen ke yeh session table mein active hai.Verify the policy contents and check that it is active in the session table.
show firewall policy 1 diagnose firewall iprope list 100004
تصدیقVerifyVerify
LAN ہوسٹ سے کوئی ویب سائٹ کھولیں۔ Log & Report > Forward Traffic میں پالیسی ID 1 کے ساتھ سیشنز لاگ ہوتے نظر آنے چاہئیں۔LAN host se koi website kholen. Log & Report > Forward Traffic mein policy ID 1 ke saath sessions log hote nazar aane chahiye.Browse a website from a LAN host. In Log & Report > Forward Traffic you should see sessions logged with policy ID 1.
show firewall policy 1
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ پالیسی موجود ہونے کے باوجود LAN ہوسٹس براؤز نہیں کر سکتے۔Policy mojood hone ke bawajood LAN hosts browse nahi kar sakte.LAN hosts cannot browse even though a policy exists.
✅ implicit deny چیک کریں: جو ٹریفک میچ نہیں ہوتا وہ ڈیفالٹ بلاک ہوتا ہے۔ srcintf/dstintf پیئر، آبجیکٹس، سروس ویریفائی کریں اور دیکھیں کہ پالیسی کسی deny رول سے اوپر ہے۔Implicit deny check karen: jo traffic match nahi hota woh default block hota hai. srcintf/dstintf pair, objects, service verify karen aur dekhain ke policy kisi deny rule se oopar hai.Check the implicit deny: unmatched traffic is blocked by default. Verify srcintf/dstintf pair, objects, service, and that the policy is above any deny rule.
⚠️ پالیسی آرڈر کی وجہ سے غلط پالیسی میچ ہو رہی ہے۔Policy order ki wajah se ghalat policy match ho rahi hai.Wrong policy is matching because of policy order.
✅ یاد رکھیں: اوپر سے نیچے پہلا میچ۔ زیادہ خاص پالیسی کو move کمانڈ سے عام پالیسی کے اوپر لے جائیں۔Yaad rakhen: oopar se neeche pehla match. Zyada khaas policy ko move command se aam policy ke oopar le jayen.Remember top-down first-match. Move the more specific policy above the general one with the move command.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ FortiGate کون سی فائر وال پالیسی سیشن پر لاگو ہوگی، یہ کیسے فیصلہ کرتا ہے؟FortiGate kaun si firewall policy session par lago hogi, yeh kaise faisla karta hai?How does FortiGate decide which firewall policy matches a session?
FortiGate پالیسیز کو اوپر سے نیچے چیک کرتا ہے اور وہ پہلی پالیسی لاگو کرتا ہے جو سب فیلڈز سے میچ کرے۔ اسی لیے خاص رولز عام رولز سے اوپر رکھے جاتے ہیں — غلط آرڈر ٹریفک بلاک یا اوور الاؤ کر سکتا ہے۔FortiGate policies ko oopar se neeche check karta hai aur woh pehli policy lago karta hai jo sab fields se match kare. Isi liye khaas rules aam rules se oopar rakhe jate hain — ghalat order traffic block ya over-allow kar sakta hai.FortiGate checks policies top to bottom and applies the first policy that matches all fields. That is why specific rules go above general rules — a wrong order can block or over-allow traffic.
❓ پالیسیز میں سیدھا IP لکھنے کے بجائے ایڈریس اور سروس آبجیکٹس کیوں استعمال کریں؟Policies mein seedha IP likhne ke bajaye address aur service objects kyun istemal karen?Why use address and service objects instead of typing IPs directly in policies?
آبجیکٹس IP، پورٹ نمبر اور یوزرز جیسی ویلیوز کو نام دے کر ایک جگہ رکھتے ہیں۔ جب کوئی ویلیو تبدیل ہو تو آبجیکٹ اپ ڈیٹ کرنے سے وہ ہر پالیسی میں اپ ڈیٹ ہو جاتی ہے جو اسے استعمال کرتی ہے۔Objects IP, port number aur users jaisi values ko naam de kar aik jagah rakhte hain. Jab koi value tabdeel ho to object update karne se woh har policy mein update ho jati hai jo isay istemal karti hai.Objects store values like IPs, port numbers, and users in one place with a name. When a value changes, updating the object updates every policy that uses it — no per-policy editing.