Security Policies: Rulebase Best Practices
Palo Alto NGFW — PCNSE track EVE-NG — PAN-OS VM (GUI + CLI)
مقصدObjectiveObjective
کلین سیکیورٹی رول بیس بنانا: انٹر زون اور انٹرا زون رولز، صحیح آرڈر، اور لاگ ایٹ سیشن اینڈ۔Clean security rulebase banana: interzone aur intrazone rules, sahi order, aur log-at-session-end.Build a clean security rulebase: interzone and intrazone rules, correct order, and log-at-session-end.
آسان مثالSimple AnalogySimple Analogy
سیکیورٹی رولز کلب کے باؤنسر کی چیک لسٹ کی طرح ہیں: وہ لسٹ ٹاپ سے باٹم تک پڑھتا ہے، اور پہلی میچنگ لائن فیصلہ کرتی ہے — اس کے بعد وہ پڑھنا بند کر دیتا ہے۔Security rules club ke bouncer ki checklist ki tarah hain: woh list top se bottom tak parhta hai, aur pehli matching line faisla karti hai — uske baad woh parhna band kar deta hai.Security rules are like a bouncer's checklist at a club: he reads the list top to bottom, and the first matching line decides — after that he stops reading.
سیٹ اپLab SetupLab Setup
پالو-02 کا بلڈ استعمال کریں: زونز ٹرسٹ (ایتھرنیٹ1/1)، ان ٹرسٹ (ایتھرنیٹ1/2)، ڈی ایم زیڈ (ایتھرنیٹ1/3)۔ ایک لین ہوسٹ انٹرنیٹ اور ڈی ایم زیڈ ویب سرور تک براؤز کرے گا۔palo-02 ka build use karein: zones Trust (ethernet1/1), Untrust (ethernet1/2), DMZ (ethernet1/3). Ek LAN host internet aur DMZ web server tak browse karega.Use the palo-02 build: zones Trust (ethernet1/1), Untrust (ethernet1/2), DMZ (ethernet1/3). One LAN host will browse to the internet and to a DMZ web server.
اقداماتStepsSteps
Step 1
بیسک آؤٹ باؤنڈ رول بنائیں: ٹرسٹ سے ان ٹرسٹ، الاؤ۔ ہمیشہ لاگ ایٹ سیشن اینڈ آن رکھیں تاکہ مانیٹر > لاگز > ٹریفک میں ایپلی کیشن نظر آئے۔Basic outbound rule banayein: Trust se Untrust, allow. Hamesha log-at-session-end on rakhein taake Monitor > Logs > Traffic mein application nazar aaye.Create the basic outbound rule: Trust to Untrust, allow. Always enable log-at-session-end so you can see the application in Monitor > Logs > Traffic.
set rulebase security rules Trust-to-Untrust from Trust to Untrust source any destination any application any service application-default action allow log-setting default commit
🖱️ پالیسیز > سیکیورٹی: رول ’ٹرسٹ ٹو ان ٹرسٹ‘ ایڈ کریں، فرام ٹرسٹ ٹو ان ٹرسٹ، ایکشن الاؤ، آپشنز: لاگ ایٹ سیشن اینڈ۔Policies > Security: rule 'Trust-to-Untrust' add karein, From Trust To Untrust, action Allow, Options: Log at Session End.Policies > Security: Add rule 'Trust-to-Untrust', From Trust To Untrust, action Allow, Options: Log at Session End.
Step 2
ڈی ایم زیڈ ویب سرور کے لیے پریسائز ان باؤنڈ رول ایڈ کریں — صرف ایک ایڈریس آبجیکٹ پر ویب براؤزنگ، ’اینی‘ نہیں۔ لیسٹ پریولیج ہی زیرو ٹرسٹ ہے۔DMZ web server ke liye precise inbound rule add karein — sirf ek address object par web-browsing, 'any' nahi. Least privilege hi Zero Trust hai.Add a precise inbound rule for the DMZ web server — only web-browsing to one address object, not 'any'. Least privilege is Zero Trust in action.
set rulebase security rules Untrust-to-DMZ-Web from Untrust to DMZ source any destination DMZ-Web-Server application web-browsing service application-default action allow log-setting default commit
🖱️ پہلے آبجیکٹس > ایڈریسز: ’ڈی ایم زیڈ ویب سرور‘ (10.10.20.10) بنائیں۔ پھر پالیسیز > سیکیورٹی: ’ان ٹرسٹ ٹو ڈی ایم زیڈ ویب‘ ایڈ کریں، فرام ان ٹرسٹ ٹو ڈی ایم زیڈ، ایپلی کیشن ویب براؤزنگ۔Pehle Objects > Addresses: 'DMZ-Web-Server' (10.10.20.10) banayein. Phir Policies > Security: 'Untrust-to-DMZ-Web' add karein, From Untrust To DMZ, Application web-browsing.Objects > Addresses first: create 'DMZ-Web-Server' (10.10.20.10). Then Policies > Security: Add 'Untrust-to-DMZ-Web', From Untrust To DMZ, Application web-browsing.
Step 3
انٹرا زون رول ایڈ کریں تاکہ لین یوزرز لین ریسورسز تک پہنچ سکیں۔ اس کے بغیر سیم زون ٹریفک امپلی سٹ ڈینائی پر لگے گا۔Intrazone rule add karein taake LAN users LAN resources tak pohonch saken. Iske baghair same-zone traffic implicit deny par lagega.Add an intrazone rule so LAN users can reach LAN resources. Without it, same-zone traffic hits the implicit deny.
set rulebase security rules Trust-intrazone from Trust to Trust source any destination any application any service any action allow log-setting default commit
🖱️ پالیسیز > سیکیورٹی: ’ٹرسٹ انٹرا زون‘ ایڈ کریں، فرام ٹرسٹ ٹو ٹرسٹ (دونوں طرف سیم زون)۔Policies > Security: 'Trust-intrazone' add karein, From Trust To Trust (dono taraf same zone).Policies > Security: Add 'Trust-intrazone', From Trust To Trust (same zone both sides).
Step 4
اصل ٹریفک سے پہلے پالیسی میچ ٹیسٹ کمانڈ سے چیک کریں کہ سیمپل فلو کون سی رول میچ کرتا ہے۔Asal traffic se pehle policy-match test command se check karein ke sample flow kaun si rule match karta hai.Test which rule matches a sample flow with the policy-match test command — before you commit to real traffic.
test security-policy-match source 192.168.10.50 destination 8.8.8.8 protocol 6 destination-port 443 from Trust to Untrust commit
Step 5
ٹریفک چلنے کے بعد ہٹ کاؤنٹس ریویو کریں۔ ان یوزڈ رولز ڈس ایبل کر کے ہٹا دیں — کلین رول بیس ہی آڈیٹیبل رول بیس ہے۔Traffic chalne ke baad hit counts review karein. Unused rules disable karke hata dein — clean rulebase hi auditable rulebase hai.Review hit counts after traffic flows. Unused rules should be disabled and removed — a clean rulebase is an auditable rulebase.
show rule-hit-count security
🖱️ پالیسیز > سیکیورٹی: ’ہٹ کاؤنٹ‘ کالم دکھاتا ہے کون سی رولز اصل میں ٹریفک میچ کرتی ہیں — ڈیڈ رولز پر 0 ہوتا ہے۔Policies > Security: 'Hit Count' column dikhata hai kaun si rules asal mein traffic match karti hain — dead rules par 0 hota hai.Policies > Security: the 'Hit Count' column shows which rules actually match traffic — dead rules have 0.
تصدیقVerifyVerify
ایک لین ہوسٹ انٹرنیٹ اور ڈی ایم زیڈ ویب سرور براؤز کرتا ہے؛ دونوں فلوز مانیٹر > لاگز > ٹریفک میں صحیح رول نیمز اور ایپلی کیشنز کے ساتھ نظر آتے ہیں۔Ek LAN host internet aur DMZ web server browse karta hai; dono flows Monitor > Logs > Traffic mein sahi rule names aur applications ke saath nazar aate hain.A LAN host browses the internet and the DMZ web server; both flows appear in Monitor > Logs > Traffic with the correct rule names and applications.
test security-policy-match source 192.168.10.50 destination 203.0.113.5 protocol 6 destination-port 443 from Untrust to DMZ show rule-hit-count security
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ ٹریفک غلط رول میچ کر رہا ہے — ایک اسپیسفک الاؤ کبھی فائر نہیں ہوتی۔Traffic galat rule match kar raha hai — ek specific allow kabhi fire nahi hoti.Traffic matches the wrong rule — a specific allow never fires.
✅ اس سے اوپر ایک براڈ رول ٹریفک کو پہلے پکڑ رہی ہے۔ اسپیسفک رولز کو جنرل رولز کے اوپر موو کریں؛ میچ آرڈر دیکھنے کے لیے ’ٹیسٹ سیکیورٹی پالیسی میچ‘ استعمال کریں۔Us se upar ek broad rule traffic ko pehle pakar rahi hai. Specific rules ko general rules ke upar move karein; match order dekhne ke liye 'test security-policy-match' use karein.A broader rule above it is catching the traffic first. Move specific rules above general ones; use 'test security-policy-match' to see the match order.
⚠️ لاگز میں ’ڈینائی‘ شو ہو رہا ہے لیکن کوئی ایسی رول کا نام نہیں جو آپ نے لکھی ہو۔Logs mein 'deny' show ho raha hai lekin koi aisi rule ka naam nahi jo aap ne likhi ho.Logs show 'deny' but no rule name you wrote.
✅ یہ باٹم پر امپلی سٹ انٹر زون ڈینائی ہے (یا انٹرا زون ڈینائی)۔ اس سے اوپر ایکسپلی سٹ الاؤ ایڈ کریں، یا ٹریفک کا ڈینائی ہونا ہی صحیح ہے۔Ye bottom par implicit interzone deny hai (ya intrazone deny). Us se upar explicit allow add karein, ya traffic ka deny hona hi sahi hai.That's the implicit interzone deny at the bottom (or intrazone deny). Add an explicit allow above it, or the traffic is supposed to be denied.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ رول آرڈر کیوں اہم ہے؟Rule order kyun important hai?Why does rule order matter?
رولز ٹاپ سے باٹم ایویلوایٹ ہوتی ہیں؛ پہلی میچ جیتتی ہے۔ اس لیے براڈ رولز آخر میں (کلین اپ ڈینائی)، اور اسپیسفک الاؤز پہلے۔Rules top se bottom evaluate hoti hain; pehli match jeet ti hai. Is liye broad rules aakhir mein (cleanup deny), aur specific allows pehle.Rules are evaluated top to bottom; the first match wins. So broad rules go last (the cleanup deny), and specific allows go first.
❓ Intrazone اور interzone security rules میں کیا فرق ہے؟Intrazone aur interzone security rules mein kya farq hai?What is the difference between intrazone and interzone security rules?
انٹرا زون رولز تب لگتی ہیں جب سورس اور ڈیسٹینیشن سیم زون میں ہوں؛ انٹر زون رولز ڈفرنٹ زونز کے درمیان۔ زیرو ٹرسٹ پوسچر کے لیے دونوں واضح طور پر ڈیفائن کریں۔Intrazone rules tab lagti hain jab source aur destination same zone mein hon; interzone rules different zones ke darmiyan. Zero Trust posture ke liye dono clearly define karein.Intrazone rules apply when source and destination are in the same zone; interzone rules apply across different zones. Define both explicitly for a Zero Trust posture.