Security Profiles: IPS, AV, Web Filter & App Control
FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)
مقصدObjectiveObjective
اس لیب میں آپ انسپیکشن موڈ سیٹ کریں گے اور فائر وال پالیسی پر اینٹی وائرس، IPS، ویب فلٹر اور ایپلی کیشن کنٹرول پروفائلز لگائیں گے۔Is lab mein aap inspection mode set karenge aur firewall policy par antivirus, IPS, web filter aur application control profiles lagayenge.In this lab you will set the inspection mode and attach antivirus, IPS, web filter, and application control profiles to a firewall policy.
آسان مثالSimple AnalogySimple Analogy
سیکیورٹی پروفائلز ایسے ہیں جیسے ایئرپورٹ پر مختلف اسکینرز: ایک آپ کا بیگ چیک کرتا ہے (اینٹی وائرس)، ایک مشہور مجرموں پر نظر رکھتا ہے (IPS)، ایک آپ کا ٹکٹ چیک کرتا ہے (ویب فلٹر)، اور ایک نوٹ کرتا ہے کہ آپ کیا کر رہے ہیں (ایپلی کیشن کنٹرول)۔Security profiles aise hain jaise airport par mukhtalif scanners: aik aap ka bag check karta hai (antivirus), aik mashhoor mujrimon par nazar rakhta hai (IPS), aik aap ka ticket check karta hai (web filter), aur aik note karta hai ke aap kya kar rahe hain (application control).Security profiles are like different scanners at an airport: one checks your bag (antivirus), one watches for known criminals (IPS), one checks your ticket (web filter), and one notes what you are doing (application control).
سیٹ اپLab SetupLab Setup
fg-03 والی FortiGate استعمال کریں جس میں LAN-to-WAN پالیسی ہے۔ FortiGuard انیبل رکھیں تاکہ سگنیچرز اپ ڈیٹ رہیں۔fg-03 wali FortiGate istemal karen jis mein LAN-to-WAN policy hai. FortiGuard enable rakhen taake signatures update rahen.Use the fg-03 FortiGate with the LAN-to-WAN policy. Enable FortiGuard so signatures stay updated.
اقداماتStepsSteps
Step 1
انسپیکشن موڈ منتخب کریں۔ فلو بیسڈ ڈیفالٹ ہے — تیز اور کم لیٹنسی۔ پراکسی بیسڈ گہرے انسپیکشن کے لیے پورا کنٹینٹ بفر کرتا ہے۔ ہر پالیسی پر الگ موڈ بھی رکھ سکتے ہیں۔Inspection mode muntakhib karen. Flow-based default hai — tez aur kam latency. Proxy-based gehre inspection ke liye poora content buffer karta hai. Har policy par alag mode bhi rakh sakte hain.Choose the inspection mode. Flow-based is the default — fast with low latency. Proxy-based buffers full content for deeper inspection. You can also mix per policy.
config system settings
set inspection-mode flow-based
end🖱️ System > Settings میں Inspection Mode تبدیل کریں۔System > Settings mein Inspection Mode tabdeel karen.Change Inspection Mode under System > Settings.
Step 2
ڈیفالٹ اینٹی وائرس پروفائل دیکھیں۔ یہ FortiGuard سگنیچرز اور مشکوک فائلز کے لیے FortiGuard کلاؤڈ اور ML بیسڈ ڈیٹیکشن سے گزرتے ہوئے فائلز کو مال ویئر کے لیے اسکین کرتا ہے۔Default antivirus profile dekhen. Yeh FortiGuard signatures aur mashkook files ke liye FortiGuard cloud aur ML-based detection se guzarte hue files ko malware ke liye scan karta hai.Review the default antivirus profile. It scans files in transit for malware using FortiGuard signatures plus FortiGuard's cloud and ML-based detection for suspicious files.
config antivirus profile
edit default
set comment LAB-AV
next
end🖱️ Security Profiles > AntiVirus میں اینٹی وائرس دیکھیں۔Security Profiles > AntiVirus mein Antivirus dekhen.Review Antivirus under Security Profiles > AntiVirus.
Step 3
ڈیفالٹ IPS سینسر دیکھیں۔ IPS ٹریفک کو ہزاروں حملہ سگنیچرز سے میچ کرتا ہے اور ایکسپلائٹس، بوٹ نیٹ ٹریفک اور مشہور تھریٹس بلاک کر سکتا ہے۔Default IPS sensor dekhen. IPS traffic ko hazaron hamla signatures se match karta hai aur exploits, botnet traffic aur mashhoor threats block kar sakta hai.Review the default IPS sensor. IPS matches traffic against thousands of attack signatures and can block exploits, botnet traffic, and known threats.
config ips sensor
edit default
set comment LAB-IPS
next
end🖱️ Security Profiles > Intrusion Prevention میں سینسرز دیکھیں۔Security Profiles > Intrusion Prevention mein sensors dekhen.Review the sensors under Security Profiles > Intrusion Prevention.
Step 4
ڈیفالٹ ویب فلٹر پروفائل دیکھیں۔ یہ ویب سائٹس کو کیٹیگری میں تقسیم کرتا ہے (سوشل میڈیا، جوا، مال ویئر سائٹس) اور کمپنی پالیسی کے مطابق کیٹیگریز یا URLs بلاک کرتا ہے۔Default web filter profile dekhen. Yeh websites ko category mein taqseem karta hai (social media, gambling, malware sites) aur company policy ke mutabiq categories ya URLs block karta hai.Review the default web filter profile. It categorizes websites (social media, gambling, malware sites) and blocks categories or URLs per company policy.
config webfilter profile
edit default
set comment LAB-WF
next
end🖱️ Security Profiles > Web Filter میں پروفائل دیکھیں۔Security Profiles > Web Filter mein profile dekhen.Review the profile under Security Profiles > Web Filter.
Step 5
ڈیفالٹ ایپلی کیشن کنٹرول لسٹ دیکھیں۔ یہ ایپلی کیشنز (فیس بک، یوٹیوب، بٹ ٹورنٹ) کی پہچان کرتا ہے اور آپ کو یوزر یا گروپ کے حساب سے الاؤ، بلاک یا لِمٹ کرنے دیتا ہے۔Default application control list dekhen. Yeh applications (Facebook, YouTube, BitTorrent) ki pehchan karta hai aur aap ko user ya group ke hisab se allow, block ya limit karne deta hai.Review the default application control list. It identifies applications (Facebook, YouTube, BitTorrent) and lets you allow, block, or limit them by user or group.
config application list
edit default
set comment LAB-APP
next
end🖱️ Security Profiles > Application Control میں لسٹ دیکھیں۔Security Profiles > Application Control mein list dekhen.Review the list under Security Profiles > Application Control.
Step 6
چاروں پروفائلز LAN-to-WAN پالیسی پر لگائیں۔ اب ایک پالیسی ہر سیشن پر اینٹی وائرس، IPS، ویب فلٹرنگ اور ایپلی کیشن کنٹرول کرتی ہے۔Charon profiles LAN-to-WAN policy par lagayen. Ab aik policy har session par antivirus, IPS, web filtering aur application control karti hai.Attach all four profiles to the LAN-to-WAN policy. One policy now does antivirus, IPS, web filtering, and application control on every session.
config firewall policy
edit 1
set utm-status enable
set inspection-mode flow
set av-profile default
set ips-sensor default
set webfilter-profile default
set application-list default
set ssl-ssh-profile certificate-inspection
next
end🖱️ Policy & Objects > Firewall Policy میں پالیسی ایڈٹ کریں اور Security Profiles آن کریں۔Policy & Objects > Firewall Policy mein policy edit karen aur Security Profiles on karen.Edit the policy under Policy & Objects > Firewall Policy and enable Security Profiles.
تصدیقVerifyVerify
عام براؤزنگ کریں، پھر کوئی بلاکڈ کیٹیگری ٹرائی کریں۔ Log & Report > Security Events میں سیکیورٹی ایونٹس نظر آنے چاہئیں، اس پروفائل کے نام کے ساتھ جس نے بلاک کیا۔Aam browsing karen, phir koi blocked category try karen. Log & Report > Security Events mein security events nazar aane chahiye, us profile ke naam ke saath jis ne block kiya.Browse normally, then try a blocked category. Security events should appear in Log & Report > Security Events with the profile name that blocked them.
show firewall policy 1
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ انسپیکشن آن کرنے کے بعد HTTPS سائٹس پر سرٹیفکیٹ وارننگ آتا ہے۔Inspection on karne ke baad HTTPS sites par certificate warning aata hai.HTTPS sites show certificate warnings after enabling inspection.
✅ ڈیپ انسپیکشن HTTPS ٹریفک کو FortiGate CA سے دوبارہ سائن کرتا ہے۔ FortiGate CA سرٹیفکیٹ کلائنٹ ڈیوائسز پر انسٹال کریں، یا ڈیپ انسپیکشن کے بجائے certificate-inspection (صرف SNI) استعمال کریں۔Deep inspection HTTPS traffic ko FortiGate CA se dobara sign karta hai. FortiGate CA certificate client devices par install karen, ya deep inspection ke bajaye certificate-inspection (sirf SNI) istemal karen.Deep inspection re-signs HTTPS traffic with the FortiGate CA. Install the FortiGate CA certificate on client devices, or use certificate-inspection (SNI only) instead of deep inspection.
⚠️ کچھ فیچر کو پراکسی موڈ چاہیے مگر پالیسی فلو موڈ میں ہے۔Kuch feature ko proxy mode chahiye magar policy flow mode mein hai.Some feature needs proxy mode but the policy is in flow mode.
✅ کچھ فیچرز (جیسے ویب فلٹر اور DLP کے کچھ آپشنز) صرف پراکسی موڈ میں کام کرتے ہیں۔ اس پالیسی کو inspection-mode proxy پر کر دیں — ہر پالیسی پر موڈ الگ رکھ سکتے ہیں۔Kuch features (jaise web filter aur DLP ke kuch options) sirf proxy mode mein kaam karte hain. Us policy ko inspection-mode proxy par kar den — har policy par mode alag rakh sakte hain.Certain features (like some web filter and DLP options) only work in proxy mode. Switch that policy to inspection-mode proxy — you can mix modes per policy.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ فلو بیسڈ اور پراکسی بیسڈ انسپیکشن میں کیا فرق ہے؟Flow-based aur proxy-based inspection mein kya farq hai?What is the difference between flow-based and proxy-based inspection?
فلو موڈ میں FortiGate پیکٹس کو گزرتے ہوئے اسکین کرتا ہے، پوری فائل بفر نہیں کرتا — تیز، کم لیٹنسی۔ پراکسی موڈ میں کنٹینٹ بفر کر کے پوری طرح ری کنسٹرکٹ کرتا ہے — گہرا انسپیکشن مگر سست اور زیادہ CPU۔ کچھ فیچرز کو پراکسی موڈ چاہیے ہوتا ہے۔Flow mode mein FortiGate packets ko guzarte hue scan karta hai, poori file buffer nahi karta — tez, kam latency. Proxy mode mein content buffer kar ke poori tarah reconstruct karta hai — gehra inspection magar sust aur zyada CPU. Kuch features ko proxy mode chahiye hota hai.In flow mode FortiGate scans packets as they pass without buffering the whole file — fast, low latency. In proxy mode it buffers and fully reconstructs content — deeper inspection but slower and with more CPU use. Some features need proxy mode.
❓ IPS اور ایپلی کیشن کنٹرول میں کیا فرق ہے؟IPS aur application control mein kya farq hai?What is the difference between IPS and application control?
IPS مشہور حملہ پیٹرنز (سگنیچرز) بلاک کرتا ہے، جبکہ ایپلی کیشن کنٹرول ایپلی کیشنز (جیسے فیس بک یا بٹ ٹورنٹ) کی پہچان کر کے انہیں کنٹرول کرتا ہے — ایک حملے روکتا ہے، دوسرا استعمال کی پالیسی نافذ کرتا ہے۔IPS mashhoor hamla patterns (signatures) block karta hai, jabke application control applications (jaise Facebook ya BitTorrent) ki pehchan kar ke unhen control karta hai — aik hamle rokta hai, doosra istemal ki policy nafiz karta hai.IPS blocks known attack patterns (signatures), while application control identifies and controls applications (like Facebook or BitTorrent) — one stops attacks, the other enforces usage policy.