Capstone: Branch Firewall Build

Palo Alto NGFW — PCNSE track EVE-NG — PAN-OS VM (GUI + CLI)

مقصدObjectiveObjective

اسکریچ سے کمپلیٹ برانچ فائر وال ڈیپلائے کرنا: سیٹ اپ، زونز، پالیسیز، نیٹ، پروفائلز، وی پی این، لاگنگ — اینڈ ٹو اینڈ ویریفائیڈ۔Scratch se complete branch firewall deploy karna: setup, zones, policies, NAT, profiles, VPN, logging — end to end verified.Deploy a complete branch firewall from scratch: setup, zones, policies, NAT, profiles, VPN, logging — verified end to end.

آسان مثالSimple AnalogySimple Analogy

یہ کیپسٹون ڈرائیونگ لیسنز کے بعد فائنل ایگزام ڈرائیو ہے: زونز، پالیسیز، نیٹ، پروفائلز، لاگنگ — سب کچھ ایک ساتھ، ایک برانچ آفس، ٹریننگ وہیلز کے بغیر۔Ye capstone driving lessons ke baad final exam drive hai: zones, policies, NAT, profiles, logging — sab kuch ek saath, ek branch office, training wheels ke baghair.This capstone is the final exam drive after driving lessons: zones, policies, NAT, profiles, logging — everything together, one branch office, no training wheels.

سیٹ اپLab SetupLab Setup

ای وی ای این جی میں فریش پی اے این او ایس وی ایم۔ لین 192.168.10.0/24، وین 203.0.113.2/30، ڈی ایم زیڈ 10.10.20.0/24، ایچ کیو پیئر 203.0.113.6 پر۔ چیک لسٹ ٹاپ سے باٹم تک فالو کریں۔EVE-NG mein fresh PAN-OS VM. LAN 192.168.10.0/24, WAN 203.0.113.2/30, DMZ 10.10.20.0/24, HQ peer 203.0.113.6 par. Checklist top se bottom tak follow karein.Fresh PAN-OS VM in EVE-NG. LAN 192.168.10.0/24, WAN 203.0.113.2/30, DMZ 10.10.20.0/24, HQ peer at 203.0.113.6. Work the checklist top to bottom.

اقداماتStepsSteps

Step 1

چیک لسٹ 1 — بیس سیٹ اپ: ہوسٹ نیم، ڈی این ایس، این ٹی پی، ایڈمن ہارڈننگ۔ کمیٹ کریں۔Checklist 1 — base setup: hostname, DNS, NTP, admin hardening. Commit karein.Checklist 1 — base setup: hostname, DNS, NTP, admin hardening. Commit.

set deviceconfig system hostname PA-Branch-01
set deviceconfig system dns-setting servers primary 8.8.8.8
commit

🖱️ ڈیوائس > سیٹ اپ: ہوسٹ نیم، ڈی این ایس، این ٹی پی، اور مینیجمنٹ ایکسیس اپنے ایڈمن آئی پی تک ریسٹرکٹ کریں۔Device > Setup: hostname, DNS, NTP, aur management access apne admin IP tak restrict karein.Device > Setup: hostname, DNS, NTP, and restrict management access to your admin IP.

Step 2

چیک لسٹ 2 — انٹرفیسز اور زونز، پھر انہیں ڈیفالٹ ورچوئل روٹر میں ایڈ کریں۔Checklist 2 — interfaces aur zones, phir unhein default virtual router mein add karein.Checklist 2 — interfaces and zones, then add them to the default virtual router.

set network interface ethernet ethernet1/1 layer3 ip 192.168.10.1/24
set network interface ethernet ethernet1/2 layer3 ip 203.0.113.2/30
set zone zone Trust network layer3 ethernet1/1
set zone zone Untrust network layer3 ethernet1/2
commit

🖱️ نیٹ ورک > انٹرفیسز + نیٹ ورک > زونز: انٹرفیسز لیئر تھری، زونز ٹرسٹ/ان ٹرسٹ۔Network > Interfaces + Network > Zones: interfaces layer3, zones Trust/Untrust.Network > Interfaces + Network > Zones: interfaces as layer3, zones Trust/Untrust.

Step 3

چیک لسٹ 3 — لاگنگ کے ساتھ لیسٹ پریولیج سیکیورٹی رولز، پروفائل گروپ اٹیچڈ، باٹم پر ایکسپلی سٹ ڈینائی۔Checklist 3 — logging ke saath least-privilege security rules, profile group attached, bottom par explicit deny.Checklist 3 — security rules least-privilege with logging, profile group attached, explicit deny at the bottom.

set rulebase security rules Trust-to-Untrust from Trust to Untrust source any destination any application any service application-default action allow log-setting default profile-setting group Branch-Strict
set rulebase security rules Cleanup-Deny from any to any source any destination any application any service any action deny log-setting default
commit

🖱️ پالیسیز > سیکیورٹی: پروفائل گروپ کے ساتھ آؤٹ باؤنڈ الاؤ، باٹم پر ایکسپلی سٹ کلین اپ ڈینائی۔Policies > Security: profile group ke saath outbound allow, bottom par explicit cleanup deny.Policies > Security: outbound allow with profile group, explicit cleanup deny at the bottom.

Step 4

چیک لسٹ 4 — نیٹ: آؤٹ باؤنڈ ڈائنامک سورس نیٹ، سب سے اسپیسفک رولز ٹاپ پر۔Checklist 4 — NAT: outbound dynamic source NAT, sab se specific rules top par.Checklist 4 — NAT: outbound dynamic source NAT, most-specific rules on top.

set rulebase nat rules Outbound-DNAT from Trust to Untrust source any destination any service any source-translation dynamic-ip-and-port interface-address interface ethernet1/2
commit

🖱️ پالیسیز > نیٹ: آؤٹ باؤنڈ کے لیے ڈائنامک سورس نیٹ؛ ’شو رننگ نیٹ پالیسی‘ سے آرڈر ویریفائی کریں۔Policies > NAT: outbound ke liye dynamic source NAT; 'show running nat-policy' se order verify karein.Policies > NAT: dynamic source NAT for outbound; verify order with 'show running nat-policy'.

Step 5

چیک لسٹ 5 — اینڈ ٹو اینڈ ویریفائی: ایس ایز اپ، پالیسی میچ صحیح، لاگز کلین، پھر کنفگ بیک اپ ایکسپورٹ کریں (ڈیوائس > سیٹ اپ > آپریشنز)۔Checklist 5 — end to end verify: SAs up, policy-match sahi, logs clean, phir config backup export karein (Device > Setup > Operations).Checklist 5 — verify end to end: SAs up, policy-match correct, logs clean, then export a config backup (Device > Setup > Operations).

show vpn ike-sa
show vpn ipsec-sa
test security-policy-match source 192.168.10.50 destination 8.8.8.8 protocol 6 destination-port 443 from Trust to Untrust
commit

🖱️ مانیٹر > لاگز > ٹریفک + مانیٹر > لاگز > تھریٹ: کلین الاؤز اور کوئی ان ایکسپیکٹڈ بلاکس نہیں — کنفرم کریں۔Monitor > Logs > Traffic + Monitor > Logs > Threat: clean allows aur koi unexpected blocks nahi — confirm karein.Monitor > Logs > Traffic + Monitor > Logs > Threat: confirm clean allows and no unexpected blocks.

تصدیقVerifyVerify

ایک لین ہوسٹ نیٹ کے ذریعے انٹرنیٹ براؤز کرتا ہے، لاگز میں صحیح رول/ایپ نظر آتا ہے، تھریٹ پروفائلز اٹیچڈ ہیں، وی پی این ایس ایز اپ ہیں، اور کنفگ بیک اپ سیو ہے۔Ek LAN host NAT ke zariye internet browse karta hai, logs mein sahi rule/app nazar aata hai, threat profiles attached hain, VPN SAs up hain, aur config backup save hai.A LAN host browses the internet through NAT, logs show the right rule/app, threat profiles are attached, VPN SAs are up, and a config backup is saved.

show vpn ike-sa
show vpn ipsec-sa
show rule-hit-count security
show running nat-policy

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ چیک لسٹ میں کچھ فیل ہو رہا ہے اور سمجھ نہیں آ رہا کہاں۔Checklist mein kuch fail ho raha hai aur samajh nahi aa raha kahan.Something in the checklist fails and you don't know where.

✅ اسٹیک پر باٹم اپ چلیں: انٹرفیس اپ؟ زون اسائنڈ؟ نیٹ رول میچڈ؟ سیکیورٹی رول میچڈ؟ پروفائل بلاکنگ؟ ٹریفک لاگ ہر لیئر کا جواب دیتا ہے۔Stack par bottom-up chalein: interface up? zone assigned? NAT rule matched? security rule matched? profile blocking? Traffic log har layer ka jawab deta hai.Work the stack bottom-up: interface up? zone assigned? NAT rule matched? security rule matched? profile blocking? The traffic log answers each layer.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ برانچ فائر وال کے لیے آپ کی گو لائیو چیک لسٹ کیا ہے؟Branch firewall ke liye aapki go-live checklist kya hai?What is your go-live checklist for a branch firewall?

چیک لسٹ پر چلیں: مینیجمنٹ ایکسیس سیکیورڈ، انٹرفیسز/زونڈ، روٹنگ، نیٹ، لاگنگ کے ساتھ لیسٹ پریولیج سیکیورٹی رولز، پروفائلز اٹیچڈ، وی پی این ٹیسٹڈ، بیک اپس لیے گئے۔Checklist par chalein: mgmt access secured, interfaces/zoned, routing, NAT, logging ke saath least-privilege security rules, profiles attached, VPN tested, backups liye gaye.Walk the checklist: mgmt access secured, interfaces/zoned, routing, NAT, security rules least-privilege with logging, profiles attached, VPN tested, backups taken.

❓ Branch firewall build کو end to end کیسے validate کرو گے؟Branch firewall build ko end to end kaise validate karoge?How would you validate a branch firewall build end to end?

ٹاپ ڈاؤن ٹیسٹ کریں: گیٹ وے کو پنگ کریں، نیٹ ٹرانسلیشن چیک کریں، پالیسی میچ سے سیکیورٹی رول میچ ویریفائی کریں، ٹریفک لاگ پڑھیں، پھر پروفائل ہٹس کے لیے تھریٹ لاگز چیک کریں۔Top-down test karein: gateway ko ping karein, NAT translation check karein, policy-match se security rule match verify karein, traffic log parhein, phir profile hits ke liye threat logs check karein.Test top-down: ping the gateway, check NAT translation, verify the security rule match with policy-match, read the traffic log, then check threat logs for profile hits.