Palo Alto Basics: Architecture & Single-Pass Engine
Palo Alto NGFW — PCNSE track EVE-NG — PAN-OS VM (GUI + CLI)
مقصدObjectiveObjective
پالو آلٹو کے ایس پی تھری سنگل پاس آرکیٹیکچر کو سمجھنا اور ایپ آئی ڈی، کنٹینٹ آئی ڈی، یوزر آئی ڈی کا کام سمجھنا۔Palo Alto ke SP3 single-pass architecture ko samajhna aur App-ID, Content-ID, User-ID ka kaam samajhna.Understand Palo Alto's SP3 single-pass architecture and what App-ID, Content-ID, and User-ID do.
آسان مثالSimple AnalogySimple Analogy
پرانا فائر وال صرف لفافے کا پتہ پڑھتا ہے۔ پالو آلٹو کا سنگل پاس انجن لفافہ پڑھتا ہے، خط کھولتا ہے، ہینڈ رائٹنگ چیک کرتا ہے اور پوچھتا ہے ’یہ کس نے بھیجا؟‘ — سب ایک ہی پاس میں۔Purana firewall sirf lifafay ka pata parhta hai. Palo Alto ka single-pass engine lifafa parhta hai, letter kholta hai, handwriting check karta hai, aur poochta hai 'ye kis ne bheja?' — sab ek hi pass mein.A traditional firewall is like a post office that reads only the address on the envelope. Palo Alto's single-pass engine reads the envelope, opens the letter, checks the handwriting, and asks 'who sent this?' — all in one pass.
سیٹ اپLab SetupLab Setup
تھیوری لیسن ہے۔ ڈیوائس کی ضرورت نہیں۔ پی اے این او ایس وی ایم چھونے سے پہلے اسے پڑھیں۔Theory lesson hai. Device ki zaroorat nahi. PAN-OS VM chhone se pehle ise parhain.Theory lesson. No device needed. Read this before touching the PAN-OS VM.
اقداماتStepsSteps
Step 1
پالو آلٹو ایس پی تھری سنگل پاس پیرلل پروسیسنگ آرکیٹیکچر استعمال کرتا ہے۔ ایک انجن ہر پیکٹ کو صرف ایک دفعہ انسپیکٹ کرتا ہے، الگ الگ فائر وال، آئی پی ایس اور اے وی انجنز سے گزارنے کے بجائے۔Palo Alto SP3 single-pass parallel processing architecture use karta hai. Ek engine har packet ko sirf ek dafa inspect karta hai, alag alag firewall, IPS aur AV engines se guzarne ke bajaye.Palo Alto uses the SP3 single-pass parallel processing architecture. One engine inspects each packet once instead of passing it through separate firewall, IPS, and AV engines.
🖱️ مانیٹر > لاگز — اصل ٹریفک چلنے کے بعد یہاں ایپ نیمز نظر آئیں گے جیسے ’ویب براؤزنگ‘، ’ایس ایس ایل‘، ’فیس بک بیس‘۔Monitor > Logs — asal traffic chalne ke baad yahan App names nazar aayenge jaise 'web-browsing', 'ssl', 'facebook-base'.Monitor > Logs — after real traffic flows you will see App names like 'web-browsing', 'ssl', 'facebook-base'.
Step 2
ایپ آئی ڈی خود ایپلی کیشن کو پہچانتا ہے — پورٹ کو نہیں۔ ٹی سی پی 443 پر اسکائپ پھر بھی ’اسکائپ‘ ہے، ’ایچ ٹی ٹی پی ایس‘ نہیں۔ یہ نیکسٹ جین فائر وال کا دل ہے۔App-ID khud application ko pehchanta hai — port ko nahi. TCP 443 par Skype phir bhi 'skype' hai, 'https' nahi. Ye next-gen firewall ka dil hai.App-ID identifies the application itself — not the port. Skype on TCP 443 is still 'skype', not 'https'. This is the heart of a next-gen firewall.
Step 3
کنٹینٹ آئی ڈی اندر کے ڈیٹا کو اسکین کرتا ہے: اینٹی وائرس سگنیچرز، اینٹی اسپائی ویئر، ولنریبیلیٹی ایکسپلائٹس، یو آر ایل فلٹرنگ اور ڈیٹا لاس پیٹرنز (کریڈٹ کارڈز، نیٹ ورک سے نکلتی فائلز)۔Content-ID andar ke data ko scan karta hai: antivirus signatures, anti-spyware, vulnerability exploits, URL filtering aur data-loss patterns (credit cards, network se nikalti files).Content-ID scans the data inside: antivirus signatures, anti-spyware, vulnerability exploits, URL filtering, and data-loss patterns (credit cards, files leaving the network).
Step 4
یوزر آئی ڈی ٹریفک کو یوزر نیمز سے جوڑتا ہے (اے ڈی، سس لاگ یا کیپٹو پورٹل سے) تاکہ آپ ’الاؤ مینیجرز ٹو یوز فیس بک‘ جیسی رولز لکھ سکیں، آئی پی بیسڈ رولز کے بجائے۔User-ID traffic ko usernames se jorta hai (AD, syslog ya captive portal se) taake aap 'allow Managers to use facebook' jaisi rules likh saken, IP-based rules ke bajaye.User-ID ties traffic to usernames (from AD, syslog, or captive portal) so you can write rules like 'allow Managers to use facebook' instead of IP-based rules.
Step 5
پلان: آنے والے ہر لیب میں پہلے ٹریفک لاگ کا ایپلی کیشن کالم دیکھیں۔ اگر ایپ آئی ڈی ’ان نون ٹی سی پی‘ دکھائے تو آپ کی پالیسی یا ڈیکرپشن میں کام باقی ہے۔Plan: aane walay har lab mein pehle traffic log ka Application column dekhein. Agar App-ID 'unknown-tcp' dikhaye to aapki policy ya decryption mein kaam baki hai.Plan: in every later lab, check the traffic log's Application column first. If App-ID shows 'unknown-tcp', your policy or decryption needs work.
تصدیقVerifyVerify
آپ سنگل پاس، ایپ آئی ڈی، کنٹینٹ آئی ڈی اور یوزر آئی ڈی اپنے الفاظ میں سمجھا سکتے ہیں اور ٹریفک لاگ میں ایپلی کیشن کالم ڈھونڈ سکتے ہیں۔Aap single-pass, App-ID, Content-ID aur User-ID apne alfaaz mein samjha sakte hain aur traffic log mein Application column dhoondh sakte hain.You can explain single-pass, App-ID, Content-ID, and User-ID in your own words and find the Application column in the traffic log.
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ لاگز میں ’ایپلی کیشن ڈیفالٹ‘ سروس ایک چیٹ ایپ کو بلاک کر رہی ہے۔Logs mein 'application-default' service ek chat app ko block kar rahi hai.Logs show 'application-default' service blocking a chat app.
✅ ہو سکتا ہے ایپ آئی ڈی نے ٹریفک کلاسیفائی نہ کیا ہو۔ پیکٹ کیپچر سے ویریفائی کریں اور پالیسی میں ایپلی کیشن ٹھیک کریں یا ڈیٹیکٹڈ ایپ آئی ڈی کو واضح طور پر الاؤ کریں۔Ho sakta hai App-ID ne traffic classify na kiya ho. Packet capture se verify karein aur policy mein application theek karein ya detected App-ID ko clearly allow karein.App-ID may not have classified the traffic. Verify with packet capture and adjust the application in the policy or allow the detected App-ID explicitly.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ پالو آلٹو میں ’سنگل پاس‘ کا کیا مطلب ہے؟Palo Alto mein 'single-pass' ka kya matlab hai?What does 'single-pass' mean in Palo Alto?
سنگل پاس — فائر وال نیٹ ورکنگ، پالیسی لک اپ، ایپ آئی ڈی شناخت اور کنٹینٹ اسکیننگ ایک ہی پاس میں کرتا ہے، اس لیے تیز اور مستقل ہے۔Single pass — firewall networking, policy lookup, App-ID pehchan aur content scanning ek hi pass mein karta hai, is liye fast aur consistent hai.One pass — the firewall does networking, policy lookup, App-ID identification, and content scanning in a single processing pass, so it is fast and consistent.
❓ ایپ آئی ڈی، کنٹینٹ آئی ڈی اور یوزر آئی ڈی کیا ہیں؟App-ID, Content-ID aur User-ID kya hain?What are App-ID, Content-ID, and User-ID?
یہ تین شناختی انجن ہیں: ایپ آئی ڈی ایپلی کیشن پہچانتا ہے، کنٹینٹ آئی ڈی فائلز/ڈیٹا کو تھریٹس کے لیے اسکین کرتا ہے، یوزر آئی ڈی آئی پیز کو یوزر نیمز سے میپ کرتا ہے تاکہ پالیسیز میں یوزرز استعمال ہو سکیں۔Ye teen pehchan-engine hain: App-ID application pehchanta hai, Content-ID files/data ko threats ke liye scan karta hai, User-ID IPs ko usernames se map karta hai taake policies mein users use ho saken.They are the three identification engines: App-ID identifies the application, Content-ID scans files/data for threats, User-ID maps IPs to usernames so policies can use users.