Initial Setup: Management, Interfaces & Zones

Palo Alto NGFW — PCNSE track EVE-NG — PAN-OS VM (GUI + CLI)

مقصدObjectiveObjective

مینیجمنٹ آئی پی سیٹ کرنا، لیئر تھری انٹرفیسز کنفیگر کرنا، اور ٹرسٹ/ان ٹرسٹ/ڈی ایم زیڈ سیکیورٹی زونز بنانا۔Management IP set karna, layer3 interfaces configure karna, aur Trust/Untrust/DMZ security zones banana.Set a management IP, configure layer3 interfaces, and create Trust/Untrust/DMZ security zones.

آسان مثالSimple AnalogySimple Analogy

مینیجمنٹ انٹرفیس فائر وال کا فرنٹ ڈور ہے (صرف آپ انٹر ہوتے ہیں)، ڈیٹا انٹرفیسز شہر کی سڑکیں ہیں (ٹریفک ان سے گزرتا ہے)، اور زونز محلے ہیں — رولز طے کرتے ہیں کون سا محلہ کہاں جا سکتا ہے۔Management interface firewall ka front door hai (sirf aap enter hote hain), data interfaces sheher ki streets hain (traffic un se guzarta hai), aur zones mohallay hain — rules tay karte hain kaun sa mohalla kahan ja sakta hai.The management interface is the firewall's front door (only you enter), the data interfaces are the city streets (traffic flows through them), and zones are the neighborhoods — rules decide which neighborhood can visit which.

سیٹ اپLab SetupLab Setup

ای وی ای این جی: ایک پی اے این او ایس وی ایم — ایتھرنیٹ1/1 لین کی طرف (192.168.10.0/24)، ایتھرنیٹ1/2 وین کی طرف (203.0.113.0/30)، ایتھرنیٹ1/3 ڈی ایم زیڈ کی طرف (10.10.20.0/24)۔EVE-NG: ek PAN-OS VM — ethernet1/1 LAN ki taraf (192.168.10.0/24), ethernet1/2 WAN ki taraf (203.0.113.0/30), ethernet1/3 DMZ ki taraf (10.10.20.0/24).EVE-NG: one PAN-OS VM with ethernet1/1 toward LAN (192.168.10.0/24), ethernet1/2 toward WAN (203.0.113.0/30), ethernet1/3 toward DMZ (10.10.20.0/24).

اقداماتStepsSteps

Step 1

پہلے ہوسٹ نیم اور ڈی این ایس سیٹ کریں۔ ہر کنفیگریشن بلاک کے بعد کمیٹ کریں تاکہ چینجز اپلائی ہوں۔Pehle hostname aur DNS set karein. Har configuration block ke baad commit karein taake changes apply hon.Set hostname and DNS first. Commit after every configuration block so changes take effect.

set deviceconfig system hostname PA-Branch-01
set deviceconfig system dns-setting servers primary 8.8.8.8
commit

🖱️ ڈیوائس > سیٹ اپ > مینیجمنٹ > جنرل سیٹنگز: ہوسٹ نیم اور ڈی این ایس سیٹ کریں۔Device > Setup > Management > General Settings: Hostname aur DNS set karein.Device > Setup > Management > General Settings: set Hostname, DNS.

Step 2

تینوں انٹرفیسز کو لیئر تھری کے طور پر آئی پیز کے ساتھ کنفیگر کریں۔ جب تک انٹرفیس پر زون نہیں، ٹریفک پاس نہیں ہوگا۔Teeno interfaces ko layer3 ke tor par IPs ke saath configure karein. Jab tak interface par zone nahi, traffic pass nahi hoga.Configure the three interfaces as layer3 with IPs. Until an interface has a zone, it will not pass traffic.

set network interface ethernet ethernet1/1 layer3 ip 192.168.10.1/24
set network interface ethernet ethernet1/2 layer3 ip 203.0.113.2/30
set network interface ethernet ethernet1/3 layer3 ip 10.10.20.1/24
commit

🖱️ نیٹ ورک > انٹرفیسز > ایتھرنیٹ: ہر انٹرفیس ایڈٹ کریں، انٹرفیس ٹائپ لیئر تھری سیٹ کریں، آئی پی ایڈ کریں۔Network > Interfaces > Ethernet: har interface edit karein, Interface Type Layer3 set karein, IP add karein.Network > Interfaces > Ethernet: edit each interface, set Interface Type to Layer3, add IP.

Step 3

سیکیورٹی زونز بنائیں اور ہر انٹرفیس بائنڈ کریں۔ آنے والی ہر پالیسی رول انہی زون نیمز کو ریفرنس کرے گی۔Security zones banayein aur har interface bind karein. Aane wali har policy rule inhi zone names ko reference karegi.Create security zones and bind each interface. Every later policy rule references these zone names.

set zone zone Trust network layer3 ethernet1/1
set zone zone Untrust network layer3 ethernet1/2
set zone zone DMZ network layer3 ethernet1/3
commit

🖱️ نیٹ ورک > زونز: ٹرسٹ، ان ٹرسٹ، ڈی ایم زیڈ ایڈ کریں؛ میچنگ لیئر تھری انٹرفیسز اٹیچ کریں۔Network > Zones: Trust, Untrust, DMZ add karein; matching layer3 interfaces attach karein.Network > Zones: Add Trust, Untrust, DMZ; attach the matching layer3 interfaces.

Step 4

انٹرفیسز کو ڈیفالٹ ورچوئل روٹر میں ایڈ کریں تاکہ زونز کے درمیان لیئر تھری روٹنگ کام کرے۔Interfaces ko default virtual router mein add karein taake zones ke darmiyan layer3 routing kaam kare.Add the interfaces to the default virtual router so layer3 routing works between zones.

set network virtual-router default interface ethernet1/1
set network virtual-router default interface ethernet1/2
set network virtual-router default interface ethernet1/3
commit

🖱️ نیٹ ورک > ورچوئل روٹرز > ڈیفالٹ > انٹرفیسز: تینوں انٹرفیسز ایڈ کریں۔Network > Virtual Routers > default > Interfaces: teeno interfaces add karein.Network > Virtual Routers > default > Interfaces: add all three interfaces.

Step 5

سی ایل آئی سے ویریفائی کریں: لین انٹرفیس آئی پی کو پنگ کریں اور کنفرم کریں انٹرفیس اپ/اپ شو ہو رہا ہے۔CLI se verify karein: LAN interface IP ko ping karein aur confirm karein interface up/up show ho raha hai.Verify from CLI: ping the LAN interface IP and confirm the interface shows up/up.

ping host 192.168.10.1
show interface ethernet1/1

تصدیقVerifyVerify

تینوں انٹرفیسز اپنے زونز میں اپ/اپ ہیں، اور ہوسٹ نیم جی یو آئی ڈیش بورڈ میں شو ہو رہا ہے۔Teeno interfaces apne zones mein up/up hain, aur hostname GUI dashboard mein show ho raha hai.All three interfaces are up/up in their zones, and the hostname resolves in the GUI dashboard.

show interface all
show system info

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ انٹرفیس اپ ہے لیکن لاگز میں ’ڈینائی‘ ایکشن کے ساتھ ٹریفک ڈینائی ہو رہا ہے۔Interface up hai lekin logs mein 'deny' action ke saath traffic deny ho raha hai.Interface shows up but traffic is denied with 'deny' action in logs.

✅ ہو سکتا ہے انٹرفیس کسی زون میں نہ ہو۔ ہر انٹرفیس کو زون اسائنمنٹ چاہیے، اور ایک پالیسی رول کو اس زون پیئر کو الاؤ کرنا چاہیے۔Ho sakta hai interface kisi zone mein na ho. Har interface ko zone assignment chahiye, aur ek policy rule ko us zone pair ko allow karna chahiye.The interface is probably not in a zone. Every interface needs a zone assignment, and a policy rule must allow that zone pair.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ پی اے این او ایس کے انٹرفیس ٹائپس کے نام بتائیں۔PAN-OS ke interface types ke naam batayein.Name the PAN-OS interface types.

ٹیپ کا مطلب انٹرفیس ٹریفک کی کاپی دیکھتا ہے، چینج نہیں کرتا؛ ورچوئل وائر دو انٹرفیسز کو ٹرانسپیرنٹلی برج کرتا ہے؛ لیئر ٹو سوئچ کرتا ہے؛ لیئر تھری آئی پیز کے ساتھ روٹ کرتا ہے؛ ٹنل انٹرفیسز وی پی این ٹریفک اٹھاتے ہیں۔Tap ka matlab interface traffic ki copy dekhta hai, change nahi karta; virtual wire do interfaces ko transparently bridge karta hai; layer2 switch karta hai; layer3 IPs ke saath route karta hai; tunnel interfaces VPN traffic uthate hain.Tap means the interface sees a copy of traffic but doesn't change it; virtual wire transparently bridges two interfaces; layer2 switches; layer3 routes with IPs; tunnel interfaces carry VPN traffic.

❓ Palo Alto firewall پر security zone کیا ہوتا ہے؟Palo Alto firewall par security zone kya hota hai?What is a security zone on a Palo Alto firewall?

سیکیورٹی زون انٹرفیسز کا لاجیکل گروپ ہے (جیسے ٹرسٹ، ان ٹرسٹ، ڈی ایم زیڈ)۔ پالیسیز زون ٹو زون لکھی جاتی ہیں؛ زون کے بغیر انٹرفیس کوئی ٹریفک نہیں اٹھاتا۔Security zone interfaces ka logical group hai (jaise Trust, Untrust, DMZ). Policies zone-to-zone likhi jati hain; zone ke baghair interface koi traffic nahi uthata.A security zone is a logical grouping of interfaces (e.g. Trust, Untrust, DMZ). Policies are written zone-to-zone; an interface without a zone carries no traffic.