📝 Section Review: Authentication
اہم نکاتKey TakeawaysKey Takeaways
- پالیسیز صرف IPs نہیں، یوزر گروپس پر بھی میچ کر سکتی ہیں — مگر یوزر کو پہلے آتھینٹی کیٹ ہونا چاہیے۔Policies sirf IPs nahi, user groups par bhi match kar sakti hain — magar user ko pehle authenticate hona chahiye.Policies can match user groups, not just IPs — but the user must authenticate first.
- LDAP کو درست سرور، بائنڈ کریڈینشلز، dn سرچ بیس اور cnid چاہیے — diagnose test authserver سے ٹیسٹ کریں۔LDAP ko durust server, bind credentials, dn search base aur cnid chahiye — diagnose test authserver se test karen.LDAP needs the right server, bind credentials, dn search base, and cnid — test with diagnose test authserver.
- RADIUS VPN اور admin آتھینٹیکیشن کے لیے عام ہے؛ شیئرڈ سیکرٹ دونوں طرف ملنا چاہیے۔RADIUS VPN aur admin authentication ke liye aam hai; shared secret dono taraf milna chahiye.RADIUS is common for VPN and admin authentication; the shared secret must match on both sides.
- FSSO/SSO یوزرز کو IPs سے خود میپ کرتا ہے — یوزر بیسڈ رسائی کا زیرو ٹرسٹ فرینڈلی طریقہ۔FSSO/SSO users ko IPs se khud map karta hai — user-based rasai ka Zero Trust friendly tareeqa.FSSO/SSO maps users to IPs automatically — the Zero Trust friendly way to do user-based access.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ لوکل یوزرز کے ساتھ یوزر بیسڈ فائر وال پالیسی کیسے بناتے ہیں؟Local users ke saath user-based firewall policy kaise banate hain?How do you build a user-based firewall policy with local users?
یوزر کے لیے config user local، گروپ کے لیے config user group، پھر set groups سے گروپ کو پالیسی میں شامل کریں۔User ke liye config user local, group ke liye config user group, phir set groups se group ko policy mein shamil karen.config user local for the user, config user group for the group, then add the group to the policy with set groups.
❓ LDAP/RADIUS کے بجائے لوکل یوزرز کب منتخب کرتے ہیں؟LDAP/RADIUS ke bajaye local users kab muntakhib karte hain?When do you choose local users over LDAP/RADIUS?
لوکل یوزرز FortiGate پر رہتے ہیں؛ LDAP/RADIUS کمپنی کی ڈائریکٹری استعمال کرتے ہیں تاکہ کریڈینشلز ایک جگہ مینیج ہوں۔Local users FortiGate par rehte hain; LDAP/RADIUS company ki directory istemal karte hain taake credentials aik jagah manage hon.Local users live on the FortiGate; LDAP/RADIUS use the company's directory so credentials are managed in one place.
❓ FSSO کون سا مسئلہ حل کرتا ہے؟FSSO kaun sa masla hal karta hai?What problem does FSSO solve?
FSSO ونڈوز لاگ آنز سے user-to-IP میپنگز سیکھتا ہے تاکہ یوزرز دوسری لاگ اِن کے بغیر پالیسیز سے گزریں۔FSSO Windows logons se user-to-IP mappings seekhta hai taake users doosri login ke baghair policies se guzren.FSSO learns user-to-IP mappings from Windows logons so users pass policies without a second login.