📝 Section Review: VPN
اہم نکاتKey TakeawaysKey Takeaways
- فیز 1 = گیٹ وے آتھینٹیکیشن اور مینجمنٹ چینل؛ فیز 2 = مِررڈ سیلیکٹرز کے ساتھ ڈیٹا ٹنل۔Phase 1 = gateway authentication aur management channel; Phase 2 = mirrored selectors ke saath data tunnel.Phase 1 = gateway authentication and management channel; Phase 2 = data tunnel with mirrored selectors.
- IKEv2 کے ساتھ مضبوط پروپوزلز (AES-256، SHA-256، DH گروپ 14) جدید بنیاد ہیں۔IKEv2 ke saath mazboot proposals (AES-256, SHA-256, DH group 14) jadeed bunyad hain.Strong proposals (AES-256, SHA-256, DH group 14) with IKEv2 are the modern baseline.
- دونوں ڈائریکشنز میں الاؤ پالیسیز کے بغیر ٹنل ہر ٹریفک ڈراپ کرتا ہے — پالیسیز ٹنل انٹرفیس کا حوالہ دیتی ہیں۔Dono directions mein allow policies ke baghair tunnel har traffic drop karta hai — policies tunnel interface ka hawala deti hain.A tunnel without allow policies in both directions drops all traffic — policies reference the tunnel interface.
- diagnose vpn ike gateway list اور diagnose vpn tunnel list سے ویریفائی کریں، یا Monitor > IPsec Monitor سے۔diagnose vpn ike gateway list aur diagnose vpn tunnel list se verify karen, ya Monitor > IPsec Monitor se.Verify with diagnose vpn ike gateway list and diagnose vpn tunnel list, or Monitor > IPsec Monitor.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ ہر IPsec فیز کیا کرتا ہے؟Har IPsec phase kya karta hai?What does each IPsec phase do?
فیز 1 گیٹ ویز کی آتھینٹیکیشن کرتا ہے اور IKE SA بناتا ہے؛ فیز 2 IPsec SA نیگوشی ایٹ کرتا ہے جو یوزر ٹریفک اٹھاتا ہے۔Phase 1 gateways ki authentication karta hai aur IKE SA banata hai; Phase 2 IPsec SA negotiate karta hai jo user traffic uthata hai.Phase 1 authenticates the gateways and builds the IKE SA; Phase 2 negotiates the IPsec SA that carries user traffic.
❓ فیز 1 اپ نہیں ہو رہا — کیا چیک کریں گے؟Phase 1 up nahi ho raha — kya check karenge?Phase 1 will not come up — what do you check?
پری شیئرڈ کی، ریموٹ گیٹ وے IP، IKE ورژن اور پروپوزلز دونوں طرف ملنے چاہئیں۔Pre-shared key, remote gateway IP, IKE version aur proposals dono taraf milne chahiye.Pre-shared key, remote gateway IP, IKE version, and proposals must match on both sides.
❓ فیز 1 اپ ہے مگر ٹریفک نہیں گزر رہا — کیا چیک کریں گے؟Phase 1 up hai magar traffic nahi guzar raha — kya check karenge?Phase 1 is up but no traffic flows — what do you check?
سیلیکٹرز (src-subnet/dst-subnet) دونوں طرف ایک دوسرے کے آئینہ ہونے چاہئیں، اور ٹنل کی دونوں ڈائریکشنز میں فائر وال پالیسیز ہونی چاہئیں۔Selectors (src-subnet/dst-subnet) dono taraf aik doosre ke aaina hone chahiye, aur tunnel ki dono directions mein firewall policies honi chahiye.The selectors (src-subnet/dst-subnet) must mirror on both sides, and firewall policies must exist in both tunnel directions.
❓ IPsec ٹیمپلیٹ کب اور مینوئل سیٹ اپ کب استعمال کرتے ہیں؟IPsec template kab aur manual setup kab istemal karte hain?When do you use the IPsec template versus manual setup?
جب دونوں طرف FortiGate ہوں تو ٹیمپلیٹ استعمال کریں؛ دوسرے وینڈرز یا خاص ریکوائرمنٹس کے لیے مینوئل کنفیگر کریں۔Jab dono taraf FortiGate hon to template istemal karen; doosre vendors ya khaas requirements ke liye manual configure karen.Use the template when both sides are FortiGates; configure manually for other vendors or custom requirements.