📝 Section Review: Security Policies
اہم نکاتKey TakeawaysKey Takeaways
- رولز فرسٹ میچ ونز ہیں، ٹاپ سے باٹم — اسپیسفک رولز جنرل سے اوپر۔Rules first-match-wins hain, top se bottom — specific rules general se upar.Rules are first-match-wins, top to bottom — specific rules above general ones.
- لیسٹ پریولیج رولز لکھیں: ایگزیکٹ زونز، ایڈریسز اور ایپلی کیشنز — ’اینی‘ نہیں۔Least-privilege rules likhein: exact zones, addresses aur applications — 'any' nahi.Write least-privilege rules: exact zones, addresses, and applications — not 'any'.
- ہمیشہ لاگ ایٹ سیشن اینڈ اینیبل رکھیں تاکہ ٹریفک لاگز میں ایپلی کیشن کالم نظر آئے۔Hamesha log-at-session-end enable rakhein taake traffic logs mein Application column nazar aaye.Always enable log-at-session-end so the Application column is visible in traffic logs.
- باٹم پر امپلی سٹ ڈینائی سب کچھ پکڑتا ہے — اپنا کلین اپ ڈینائی ایکسپلی سٹ بنائیں۔Bottom par implicit deny sab kuch pakarta hai — apna cleanup deny explicit banayein.The implicit deny at the bottom catches everything — make your cleanup deny explicit.
- ہٹ کاؤنٹس ڈیڈ رولز ریویل کرتے ہیں؛ کلین رول بیس ہی آڈیٹیبل رول بیس ہے۔Hit counts dead rules reveal karte hain; clean rulebase hi auditable rulebase hai.Hit counts reveal dead rules; a clean rulebase is an auditable rulebase.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ اگر براڈ الاؤ اسپیسفک ڈینائی کے اوپر ہو تو کیا ہوتا ہے؟Agar broad allow specific deny ke upar ho to kya hota hai?What happens if a broad allow sits above a specific deny?
پہلی میچ جیتتی ہے، ٹاپ سے باٹم ایویلوایٹ ہوتی ہیں — اس لیے اسپیسفک رول کے اوپر براڈ رول اسے شیڈو کر دے گی۔Pehli match jeet ti hai, top se bottom evaluate hoti hain — is liye specific rule ke upar broad rule use shadow kar degi.First match wins, evaluated top to bottom — so a broad rule above a specific one will shadow it.
❓ انٹرا زون بمقابلہ انٹر زون؟Intrazone vs interzone?Intrazone vs interzone?
انٹرا زون = دونوں طرف سیم زون؛ انٹر زون = ڈفرنٹ زونز۔ زیرو ٹرسٹ کے لیے دونوں کو ایکسپلی سٹ رولز چاہئیں۔Intrazone = dono taraf same zone; interzone = different zones. Zero Trust ke liye dono ko explicit rules chahiye.Intrazone = same zone both sides; interzone = different zones. Both need explicit rules for Zero Trust.
❓ کیسے ٹیسٹ کرتے ہیں کہ کون سی رول میچ ہوگی؟Kaise test karte hain ke kaun si rule match hogi?How do you test which rule will match?
’ٹیسٹ سیکیورٹی پالیسی میچ‘ بتاتا ہے کہ سیمپل فلو کون سی رول ہٹ کرے گا، اصل ٹریفک سے پہلے۔'test security-policy-match' batata hai ke sample flow kaun si rule hit karega, asal traffic se pehle.'test security-policy-match' shows which rule a sample flow hits, before real traffic.
❓ ان یوزڈ رولز کا کیا کرتے ہیں؟Unused rules ka kya karte hain?What do you do with unused rules?
ان کے ہٹ کاؤنٹس 0 ہیں — ڈس ایبل کر کے ہٹا دیں تاکہ رول بیس آڈیٹیبل رہے۔Unke hit counts 0 hain — disable karke hata dein taake rulebase auditable rahe.They have 0 hit counts — disable and remove them to keep the rulebase auditable.