🎤 FortiGate — Interview Q&A

❓ پراکسی بیسڈ بمقابلہ فلو بیسڈ انسپیکشن سمجھائیں۔Proxy-based vs flow-based inspection samjhayen.Explain proxy-based vs flow-based inspection.

فلو موڈ پیکٹس کو بفر کیے بغیر اِن لائن اسکین کرتا ہے — تیز، کم لیٹنسی۔ پراکسی موڈ پورا کنٹینٹ بفر کر کے ری کنسٹرکٹ کرتا ہے — گہرا انسپیکشن مگر سست اور CPU پر بھاری۔ کچھ فیچرز صرف پراکسی موڈ میں کام کرتے ہیں۔Flow mode packets ko buffer kiye baghair inline scan karta hai — tez, kam latency. Proxy mode poora content buffer kar ke reconstruct karta hai — gehra inspection magar sust aur CPU par bhari. Kuch features sirf proxy mode mein kaam karte hain.Flow mode scans packets inline without buffering — fast with low latency. Proxy mode buffers and reconstructs full content — deeper inspection but slower and heavier on CPU. Some features only work in proxy mode.

❓ FortiGate کون سے NAT ٹائپس سپورٹ کرتا ہے؟FortiGate kaun se NAT types support karta hai?What NAT types does FortiGate support?

پالیسی NAT ہر فائر وال پالیسی پر NAT لگاتا ہے؛ سینٹرل NAT NAT کو الگ مرکزی SNAT/DNAT ٹیبلز میں رکھتا ہے تاکہ پالیسیز صرف allow/deny فیصلہ کریں۔ DNAT ورچوئل IPs سے ہوتا ہے، جو پبلک IP/پورٹ کو اندرونی سرور سے میپ کرتے ہیں — اور ساتھ میچنگ الاؤ پالیسی چاہیے۔Policy NAT har firewall policy par NAT lagata hai; central NAT NAT ko alag markazi SNAT/DNAT tables mein rakhta hai taake policies sirf allow/deny faisla karen. DNAT Virtual IPs se hota hai, jo public IP/port ko androoni server se map karte hain — aur saath matching allow policy chahiye.Policy NAT puts NAT on each firewall policy; central NAT moves NAT into separate central SNAT/DNAT tables so policies only decide allow/deny. DNAT is done with Virtual IPs, which map a public IP/port to an internal server — plus a matching allow policy.

❓ یوزر ID بیسڈ پالیسیز کا FortiGate میں متبادل کیا ہے؟User-ID based policies ka FortiGate mein mutabadil kya hai?What is FortiGate's equivalent of user-ID based policies?

FortiGate کا متبادل FSSO ہے — یہ ونڈوز لاگ آنز سے user-to-IP میپنگز سیکھتا ہے (کلیکٹر ایجنٹ یا پولنگ سے)، تاکہ فائر وال پالیسیز صرف IPs کے بجائے یوزر گروپس پر میچ کر سکیں۔FortiGate ka mutabadil FSSO hai — yeh Windows logons se user-to-IP mappings seekhta hai (collector agent ya polling se), taake firewall policies sirf IPs ke bajaye user groups par match kar saken.FortiGate's equivalent is FSSO — it learns user-to-IP mappings from Windows logons (collector agent or polling), so firewall policies can match user groups instead of just IPs.

❓ FortiSandbox زیرو ڈے تھریٹس کے خلاف کیسے کام کرتا ہے؟FortiSandbox zero-day threats ke khilaf kaise kaam karta hai?How does FortiSandbox work against zero-day threats?

FortiSandbox مشکوک فائلز کو الگ ورچوئل ماحول میں چلا کر ان کا رویہ دیکھتا ہے تاکہ بغیر سگنیچر والا زیرو ڈے مال ویئر پکڑا جا سکے۔ ورڈکٹس IOCs بن کر پوری سیکیورٹی فیبرک میں شیئر ہوتے ہیں۔FortiSandbox mashkook files ko alag virtual mahol mein chala kar un ka rawaiya dekhta hai taake bina signature wala zero-day malware pakra ja sake. Verdicts IOCs ban kar poori Security Fabric mein share hote hain.FortiSandbox runs suspicious files in an isolated virtual environment and observes their behavior to catch zero-day malware with no known signature. Verdicts become IOCs shared across the whole Security Fabric.

❓ FortiManager بمقابلہ FortiAnalyzer — فرق کیا ہے؟FortiManager vs FortiAnalyzer — farq kya hai?FortiManager vs FortiAnalyzer — what is the difference?

FortiManager کئی FortiGates کو مرکزی طور پر مینیج کرتا ہے — پالیسیز، کنفگز اور فرم ویئر پش کرتا ہے۔ FortiAnalyzer ان کے لاگز مرکزی طور پر جمع کر کے اینالائز کرتا ہے — رپورٹس، فارنزکس، کمپلائنس۔ ایک کنفیگر کرتا ہے، دوسرا نظر رکھتا ہے۔FortiManager kai FortiGates ko markazi taur par manage karta hai — policies, configs aur firmware push karta hai. FortiAnalyzer un ke logs markazi taur par jama kar ke analyze karta hai — reports, forensics, compliance. Aik configure karta hai, doosra nazar rakhta hai.FortiManager centrally manages many FortiGates — pushing policies, configs, and firmware. FortiAnalyzer centrally collects and analyzes their logs — reports, forensics, compliance. One configures, the other watches.

❓ IPsec فیز 1 اور فیز 2 سمجھائیں۔IPsec Phase 1 aur Phase 2 samjhayen.Explain IPsec Phase 1 and Phase 2.

فیز 1 دونوں گیٹ ویز کی آتھینٹیکیشن کرتا ہے اور سیکیور IKE مینجمنٹ چینل بناتا ہے۔ فیز 2 IPsec ٹنل نیگوشی ایٹ کرتا ہے جو یوزر ٹریفک اٹھاتا ہے، src/dst سب نیٹ سیلیکٹرز کے ساتھ جو دونوں طرف ایک دوسرے کے آئینہ ہونے چاہئیں۔Phase 1 dono gateways ki authentication karta hai aur secure IKE management channel banata hai. Phase 2 IPsec tunnel negotiate karta hai jo user traffic uthata hai, src/dst subnet selectors ke saath jo dono taraf aik doosre ke aaina hone chahiye.Phase 1 authenticates the two gateways and builds the secure IKE management channel. Phase 2 negotiates the IPsec tunnel that carries user traffic, with src/dst subnet selectors that must mirror on both sides.

❓ ZTNA کیا ہے اور VPN سے کس طرح مختلف ہے؟ZTNA kya hai aur VPN se kis tarah mukhtalif hai?What is ZTNA and how does it differ from VPN?

ZTNA ہر یوزر کو آئیڈینٹیٹی اور ڈیوائس ہیلتھ چیک کرنے کے بعد صرف مخصوص ایپلی کیشنز تک رسائی دیتا ہے — VPN جیسی وسیع نیٹ ورک رسائی نہیں۔ یہ زیرو ٹرسٹ پر چلتا ہے: کبھی بھروسا نہیں، ہمیشہ ویریفائی، ہر ایپلی کیشن کے لیے۔ZTNA har user ko identity aur device health check karne ke baad sirf makhsoos applications tak rasai deta hai — VPN jaisi wasee network rasai nahi. Yeh Zero Trust par chalta hai: kabhi bharosa nahi, hamesha verify, har application ke liye.ZTNA gives each user access only to specific applications after checking identity and device health — no broad network access like VPN. It follows Zero Trust: never trust, always verify, per application.

❓ ٹریفک غیر متوقع طور پر بلاک ہو رہا ہے — FortiGate پر آپ کا ٹربل شوٹنگ طریقہ کیا ہے؟Traffic ghair mutawaqqa tor par block ho raha hai — FortiGate par aap ka troubleshooting tareeqa kya hai?Traffic is blocked unexpectedly — what is your troubleshooting approach on FortiGate?

میں پالیسی آرڈر اور implicit deny چیک کرتا ہوں، NAT/VIP سیٹنگز کنفرم کرتا ہوں، روٹس ویریفائی کرتا ہوں، پھر فیل ہونے والے IP پر Forward Traffic لاگز فلٹر کر کے دیکھتا ہوں کہ کون سی پالیسی لگی۔ FortiGuard کنکٹیویٹی اور FortiAnalyzer تک لاگز کا پہنچنا بھی کنفرم کرتا ہوں۔Main policy order aur implicit deny check karta hoon, NAT/VIP settings confirm karta hoon, routes verify karta hoon, phir fail hone wale IP par Forward Traffic logs filter kar ke dekhta hoon ke kaun si policy lagi. FortiGuard connectivity aur FortiAnalyzer tak logs ka pohanchna bhi confirm karta hoon.I check policy order and the implicit deny, confirm NAT/VIP settings, verify routes, then filter Forward Traffic logs by the failing IP to see which policy matched. I also confirm FortiGuard connectivity and that logs reach FortiAnalyzer.