📝 Section Review: Firewall Policies
اہم نکاتKey TakeawaysKey Takeaways
- پالیسی صرف تب میچ ہوتی ہے جب سب فیلڈز میچ کریں: سورس/ڈیسٹینیشن انٹرفیسز، ایڈریسز، سروس، شیڈول۔Policy sirf tab match hoti hai jab SAB fields match karen: source/destination interfaces, addresses, service, schedule.A policy matches only when ALL fields match: source/destination interfaces, addresses, service, schedule.
- جو ٹریفک میچ نہیں ہوتا وہ implicit deny سے ٹکراتا ہے — ٹریفک بلاک ہو تو پالیسی آرڈر اور انٹرفیس پیئرز چیک کریں۔Jo traffic match nahi hota woh implicit deny se takrata hai — traffic block ho to policy order aur interface pairs check karen.Unmatched traffic hits the implicit deny — check policy order and interface pairs when traffic is blocked.
- آبجیکٹس (ایڈریسز، گروپس، سروسز) پالیسیز کو پڑھنے اور سنبھالنے میں آسان رکھتے ہیں۔Objects (addresses, groups, services) policies ko parhne aur sambhalne mein aasan rakhte hain.Objects (addresses, groups, services) keep policies readable and maintainable.
- پالیسیز پر logtraffic all آپ کو ٹربل شوٹنگ اور آڈٹس کے لیے ضروری وزبیلیٹی دیتا ہے۔Policies par logtraffic all aap ko troubleshooting aur audits ke liye zaroori visibility deta hai.logtraffic all on policies gives you the visibility needed for troubleshooting and audits.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ FortiGate سیشن سے کون سی پالیسی میچ ہوگی، یہ کیسے چنتا ہے؟FortiGate session se kaun si policy match hogi, yeh kaise chunta hai?How does FortiGate pick which policy matches a session?
اوپر سے نیچے، پہلا میچ جیتتا ہے — اسی لیے خاص رولز عام رولز سے اوپر ہوتے ہیں۔Oopar se neeche, pehla match jeetta hai — isi liye khaas rules aam rules se oopar hote hain.Top to bottom, first match wins — that is why specific rules go above general rules.
❓ ایڈریس اور سروس آبجیکٹس کا سب سے بڑا فائدہ کیا ہے؟Address aur service objects ka sab se bara faida kya hai?What is the main benefit of address and service objects?
یہ نام کے ساتھ دوبارہ استعمال ہونے والی ویلیوز رکھتے ہیں؛ ایک تبدیلی ہر اس پالیسی کو اپ ڈیٹ کر دیتی ہے جو آبجیکٹ استعمال کرتی ہے۔Yeh naam ke saath dobara istemal hone wali values rakhte hain; aik tabdeeli har us policy ko update kar deti hai jo object istemal karti hai.They store reusable values with names; one change updates every policy that uses the object.
❓ CLI میں فائر وال پالیسیز کا آرڈر کیسے تبدیل کرتے ہیں؟CLI mein firewall policies ka order kaise tabdeel karte hain?How do you reorder firewall policies in the CLI?
config firewall policy کے اندر move کمانڈ استعمال کریں، مثال move 2 before 1۔config firewall policy ke andar move command istemal karen, misal move 2 before 1.Use the move command inside config firewall policy, e.g. move 2 before 1.