🎤 Palo Alto NGFW — Interview Q&A

❓ سنگل پاس آرکیٹیکچر سمجھائیں۔Single-pass architecture samjhayein.Explain the single-pass architecture.

ایک پروسیسنگ انجن جو نیٹ ورکنگ، پالیسی لک اپ، ایپ آئی ڈی آئیڈینٹیفکیشن اور کنٹینٹ اسکیننگ ایک ہی پاس میں کرتا ہے — فاسٹ اور کنسسٹنٹ، چینڈ انجنز نہیں۔Ek processing engine jo networking, policy lookup, App-ID identification aur content scanning ek hi pass mein karta hai — fast aur consistent, chained engines nahi.A single processing engine that does networking, policy lookup, App-ID identification, and content scanning in one pass — fast and consistent, no chained engines.

❓ ایپ آئی ڈی کیا ہے اور کیوں اہم ہے؟App-ID kya hai aur kyun important hai?What is App-ID and why does it matter?

یہ ایپلی کیشن کو پورٹ سے ہٹ کر پہچانتا ہے — جیسے ٹی سی پی 443 پر اسکائپ پھر بھی ’اسکائپ‘ ہے، ’ایچ ٹی ٹی پی ایس‘ نہیں۔ پالیسیز پورٹس کے بجائے ایپس پر میچ کرتی ہیں۔Ye application ko port se hat kar pehchanta hai — jaise TCP 443 par Skype phir bhi 'skype' hai, 'https' nahi. Policies ports ke bajaye apps par match karti hain.It identifies the application itself regardless of port — e.g. Skype on TCP 443 is still 'skype', not 'https'. Policies match on apps, not just ports.

❓ سیکیورٹی زونز کیا ہیں؟Security zones kya hain?What are security zones?

انٹرفیسز کے لاجیکل گروپس (ٹرسٹ، ان ٹرسٹ، ڈی ایم زیڈ)۔ پالیسیز زون ٹو زون لکھی جاتی ہیں؛ زون کے بغیر انٹرفیس کوئی ٹریفک پاس نہیں کرتا۔Interfaces ke logical groups (Trust, Untrust, DMZ). Policies zone-to-zone likhi jati hain; zone ke baghair interface koi traffic pass nahi karta.Logical groupings of interfaces (Trust, Untrust, DMZ). Policies are written zone-to-zone; an interface without a zone passes no traffic.

❓ نیٹ رول آرڈر کیسے ایویلوایٹ ہوتا ہے؟NAT rule order kaise evaluate hota hai?How is NAT rule order evaluated?

پہلی میچ جیتتی ہے، ٹاپ سے باٹم — اسپیسفک رولز جنرل سے اوپر، باٹم پر ایکسپلی سٹ کلین اپ ڈینائی۔Pehli match jeet ti hai, top se bottom — specific rules general se upar, bottom par explicit cleanup deny.First match wins, top to bottom — specific rules above general ones, explicit cleanup deny at the bottom.

❓ یوزر آئی ڈی کیا ہے؟User-ID kya hai?What is User-ID?

یہ اے ڈی ایجنٹس، سس لاگ فیڈز یا کیپٹو پورٹل سے آئی پیز کو یوزر نیمز سے میپ کرتا ہے — تاکہ رولز ایڈریسز کے بجائے یوزرز/گروپس استعمال کریں۔Ye AD agents, syslog feeds ya captive portal se IPs ko usernames se map karta hai — taake rules addresses ke bajaye users/groups use karen.It maps IPs to usernames via AD agents, syslog feeds, or captive portal — so rules can use users/groups instead of addresses.

❓ وائلڈ فائر کیا ہے؟WildFire kya hai?What is WildFire?

ایک کلاؤڈ سینڈ باکس جو ان نون فائلز کو ڈیٹونیٹ کرتا ہے اور بینائن/گرے ویئر/میلیشس ورڈکٹس دیتا ہے؛ اِن لائن ایم ایل فائلز کو لوکلی جج کرتا ہے زیرو ڈے اسپیڈ کے لیے۔Ek cloud sandbox jo unknown files ko detonate karta hai aur benign/grayware/malicious verdicts deta hai; inline ML files ko locally judge karta hai zero-day speed ke liye.A cloud sandbox that detonates unknown files and returns benign/grayware/malicious verdicts; inline ML judges files locally for zero-day speed.

❓ پینوراما کس کام آتا ہے؟Panorama kis kaam aata hai?What is Panorama used for?

سینٹرل مینیجر: ٹیمپلیٹس نیٹ ورک/ڈیوائس کنفگ پش کرتے ہیں، ڈیوائس گروپس پالیسیز پش کرتے ہیں، اے پی آئی/ایس ڈی کے آٹومیشن دیتا ہے — ایک کمیٹ، کئی فائر والز۔Central manager: templates network/device config push karte hain, device groups policies push karte hain, API/SDK automation deta hai — ek commit, kai firewalls.The central manager: templates push network/device config, device groups push policies, API/SDK enables automation — one commit, many firewalls.

❓ ٹریفک ڈینائی ہو رہا ہے — ٹرابل شوٹ کیسے کریں گے؟Traffic deny ho raha hai — troubleshoot kaise karenge?Traffic is denied — how do you troubleshoot?

باٹم اپ: انٹرفیس اپ؟ زون اسائنڈ؟ نیٹ میچڈ؟ سیکیورٹی رول میچڈ (’ٹیسٹ سیکیورٹی پالیسی میچ‘)؟ پروفائل بلاکنگ؟ ہر لیئر پر ٹریفک لاگ پڑھیں۔Bottom-up: interface up? zone assigned? NAT matched? security rule matched ('test security-policy-match')? profile blocking? Har layer par traffic log parhein.Bottom-up: interface up? zone assigned? NAT matched? security rule matched ('test security-policy-match')? profile blocking? Read the traffic log at each layer.