📝 Section Review: VPN
اہم نکاتKey TakeawaysKey Takeaways
- فیز 1 (آئی کے ای گیٹ وے) پیئرز کو آتھینٹی کیٹ کرتا ہے؛ فیز 2 (آئی پی سیک ٹنل + پراکسی آئی ڈیز) ٹریفک کو پروٹیکٹ کرتا ہے۔Phase 1 (IKE gateway) peers ko authenticate karta hai; Phase 2 (IPsec tunnel + proxy IDs) traffic ko protect karta hai.Phase 1 (IKE gateway) authenticates peers; Phase 2 (IPsec tunnel + proxy IDs) protects the traffic.
- ٹنل انٹرفیسز وی پی این زون میں رہتے ہیں — وی پی این ٹریفک پر بھی ویسی ہی پالیسی لگتی ہے جیسی کسی اور پر۔Tunnel interfaces VPN zone mein rehte hain — VPN traffic par bhi waisi hi policy lagti hai jaisi kisi aur par.Tunnel interfaces live in a VPN zone — policy applies to VPN traffic like any other.
- ٹریفک ٹیسٹ کرنے سے پہلے ’شو وی پی این آئی کے ای ایس اے‘ اور ’شو وی پی این آئی پی سیک ایس اے‘ سے ویریفائی کریں۔Traffic test karne se pehle 'show vpn ike-sa' aur 'show vpn ipsec-sa' se verify karein.Verify with 'show vpn ike-sa' and 'show vpn ipsec-sa' before testing traffic.
- 90 فیصد وی پی این فیلیئرز پی ایس کے یا پراکسی آئی ڈی مس میچز ہیں — پہلے دونوں اینڈز کمپیئر کریں۔90% VPN failures PSK ya proxy-ID mismatches hain — pehle dono ends compare karein.90% of VPN failures are PSK or proxy-ID mismatches — compare both ends first.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ آئی کے ای گیٹ وے بمقابلہ ٹنل انٹرفیس بمقابلہ پراکسی آئی ڈیز؟IKE gateway vs tunnel interface vs proxy IDs?IKE gateway vs tunnel interface vs proxy IDs?
آئی کے ای گیٹ وے = فیز 1 (پیئرز، آتھ، انکرپشن)؛ ٹنل انٹرفیس زون میں ٹریفک اٹھاتا ہے؛ پراکسی آئی ڈیز = فیز 2 لوکل/ریموٹ سب نیٹس۔IKE gateway = Phase 1 (peers, auth, encryption); tunnel interface zone mein traffic uthata hai; proxy IDs = Phase 2 local/remote subnets.IKE gateway = Phase 1 (peers, auth, encryption); tunnel interface carries traffic in a zone; proxy IDs = Phase 2 local/remote subnets.
❓ فیز 1 فیلیئر کی ٹاپ وجوہات؟Phase 1 failure ki top wajuhat?Top causes of Phase 1 failure?
مس میچڈ پری شیئرڈ کیز، غلط آئی کے ای ورژن، یا بلاکڈ یو ڈی پی 500/4500۔Mismatched pre-shared keys, galat IKE version, ya blocked UDP 500/4500.Mismatched pre-shared keys, wrong IKE version, or blocked UDP 500/4500.
❓ آئی کے ای ایس اے اپ ہے لیکن آئی پی سیک ایس اے فیل — پہلا چیک؟IKE SA up hai lekin IPsec SA fail — pehla check?IKE SA is up but IPsec SA fails — first check?
پراکسی آئی ڈیز مرر ہونے چاہئیں: ایک طرف کا لوکل دوسری طرف کے ریموٹ کے برابر۔Proxy IDs mirror hone chahiye: ek taraf ka local doosri taraf ke remote ke barabar.Proxy IDs must mirror: local on one side equals remote on the other.
❓ کیا وی پی این ٹریفک کو سیکیورٹی رولز چاہئیں؟Kya VPN traffic ko security rules chahiye?Does VPN traffic need security rules?
ہاں — انکرپٹڈ ٹریفک کو بھی وی پی این زون پیئر پر الاؤ رولز چاہئیں۔Haan — encrypted traffic ko bhi VPN zone pair par allow rules chahiye.Yes — encrypted traffic still needs allow rules on the VPN zone pair.