SD-WAN Security: IPsec, Segmentation & Firewall

SD-WAN — Cisco Catalyst SD-WAN + Versa SD-WAN EVE-NG — vendor VMs

مقصدObjectiveObjective

اس لیب میں آپ overlay tunnels پر pairwise keys کے ساتھ IPsec on کریں گے، ٹریفک کو service VPNs میں تقسیم کریں گے اور zones کے درمیان zone-based firewall لگائیں گے۔Is lab mein aap overlay tunnels par pairwise keys ke saath IPsec on karenge, traffic ko service VPNs mein taqseem karenge aur zones ke darmiyan zone-based firewall lagayenge.In this lab you will enable IPsec with pairwise keys on the overlay tunnels, segment traffic into service VPNs, and apply a zone-based firewall between zones.

آسان مثالSimple AnalogySimple Analogy

برانچز کے درمیان بینک والٹس کی طرح: ہر برانچ جوڑے کا اپنا منفرد تالا ہے (pairwise keys)، رقم (ٹریفک) صرف اپنی armored van (VPN) میں سفر کرتی ہے، اور گیٹ پر guards (firewall) ہر van چیک کرتے ہیں۔Branches ke darmiyan bank vaults ki tarah: har branch jore ka apna munfarid taala hai (pairwise keys), raqam (traffic) sirf apni armored van (VPN) mein safar karti hai, aur gate par guards (firewall) har van check karte hain.Like bank vaults between branches: every branch pair gets its own unique lock (pairwise keys), money (traffic) travels only in its own armored van (VPN), and guards (firewall) check every van at the gate.

سیٹ اپLab SetupLab Setup

دو برانچ vEdge راؤٹرز overlay up کے ساتھ (lessons 1-4)۔ Branch LANs: VPN 1 users (192.168.10.0/24)، VPN 2 guests (192.168.20.0/24)۔ vSmart keys تقسیم کرتا ہے۔Do branch vEdge routers overlay up ke saath (lessons 1-4). Branch LANs: VPN 1 users (192.168.10.0/24), VPN 2 guests (192.168.20.0/24). vSmart keys taqseem karta hai.Two branch vEdge routers with the overlay up (lessons 1-4). Branch LANs: VPN 1 users (192.168.10.0/24), VPN 2 guests (192.168.20.0/24). vSmart distributes the keys.

اقداماتStepsSteps

Step 1

IPsec کی موجودہ حالت دیکھیں۔ Tunnels پہلے سے encrypted ہونے چاہئیں — SD-WAN default IPsec tunnels بناتا ہے۔ ہر tunnel کی pairwise key نوٹ کریں۔IPsec ki maujooda haalat dekhen. Tunnels pehle se encrypted hone chahiyen — SD-WAN default IPsec tunnels banata hai. Har tunnel ki pairwise key note karen.Check the current IPsec status. Tunnels should already be encrypted — SD-WAN builds IPsec tunnels by default. Note the pairwise keys per tunnel.

show sdwan security-info
show security ipsec sa

Step 2

Branch vEdge پر guest VPN (VPN 2) بنائیں اور interface دیں۔ Service VPNs segmentation کا building block ہیں۔Branch vEdge par guest VPN (VPN 2) banayen aur interface den. Service VPNs segmentation ka building block hain.Create the guest VPN (VPN 2) on the branch vEdge and give it an interface. Service VPNs are the segmentation building block.

config
vpn 2
name guest
interface ge0/3
ip address 192.168.20.1/24
no shutdown
!
commit
exit

Step 3

VPN ٹوپولوجی طے کریں: VPN 1 برانچز کے درمیان fully meshed، VPN 2 صرف local برانچ تک Internet breakout کے ساتھ۔ vSmart پر activate کریں۔VPN topology tay karen: VPN 1 branches ke darmiyan fully meshed, VPN 2 sirf local branch tak Internet breakout ke saath. vSmart par activate karen.Define the VPN topology: VPN 1 fully meshed between branches, VPN 2 isolated to the local branch with Internet-only breakout. Activate on vSmart.

🖱️ VPN ٹوپولوجی بنانے کا راستہVPN topology banane ka raastaConfiguration > Policies > Custom Options > Centralized Policy > Topology

Step 4

Zone-based firewall لگائیں: guest VPN کو اپنے zone میں ڈالیں، ڈیوائس کی طرف صرف DNS/DHCP کی اجازت دیں، باقی سب deny۔ Zones firewall کی زبان ہیں۔Zone-based firewall lagayen: guest VPN ko apne zone mein dalen, device ki taraf sirf DNS/DHCP ki ijazat den, baqi sab deny. Zones firewall ki zuban hain.Add a zone-based firewall: put the guest VPN in its own zone and allow only DNS/DHCP to the device itself, deny everything else. Zones are the firewall's language.

config
policy
zone-pair security zp-guest-self source-zone guest destination-zone self
service-policy type inspect fw-guest-self
!
commit
exit

Step 5

تصدیق کریں کہ policy vSmart سے آئی اور zone-pair active ہے۔ پھر test کریں: guest VPN 1 کو ping نہیں کر سکتا، مگر برانچ VPN 1 hosts tunnel کے پار آپس میں پہنچ سکتے ہیں۔Tasdeeq karen ke policy vSmart se aayi aur zone-pair active hai. Phir test karen: guest VPN 1 ko ping nahi kar sakta, magar branch VPN 1 hosts tunnel ke paar aapas mein pohanch sakte hain.Verify the policy arrived from vSmart and the zone-pair is active. Then test: guest cannot ping VPN 1, but branch VPN 1 hosts can reach each other across the tunnel.

show policy from-vsmart
show zone-pair security

تصدیقVerifyVerify

show security ipsec sa میں ہر tunnel کے لیے unique keys کے ساتھ encrypted SAs ہوں۔ Guest VPN 1 تک نہ پہنچ سکے، مگر VPN 1 hosts برانچز کے پار آپس میں پہنچ سکیں۔show security ipsec sa mein har tunnel ke liye unique keys ke saath encrypted SAs hon. Guest VPN 1 tak na pohanch sake, magar VPN 1 hosts branches ke paar aapas mein pohanch saken.show security ipsec sa must show encrypted SAs with unique keys per tunnel. Guest must fail to reach VPN 1 while VPN 1 hosts reach each other across branches.

show security ipsec sa
show policy from-vsmart

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Tunnels up ہیں مگر ٹریفک unencrypted ہے۔Tunnels up hain magar traffic unencrypted hai.Tunnels are up but traffic is unencrypted.

✅ چیک کریں کہ TLOC encapsulation ipsec ہو (gre نہیں) اور pairwise keys انسٹال ہوئی ہوں — show security ipsec sa missing SAs بتاتا ہے۔Check karen ke TLOC encapsulation ipsec ho (gre nahi) aur pairwise keys install hui hon — show security ipsec sa missing SAs batata hai.Check that the TLOC encapsulation is ipsec (not gre) and that the pairwise keys were installed — show security ipsec sa reveals missing SAs.

⚠️ Guest ٹریفک VPN 1 میں leak ہو رہا ہے۔Guest traffic VPN 1 mein leak ho raha hai.Guest traffic is leaking into VPN 1.

✅ VPN ٹوپولوجی policy اور route leaking دیکھیں — guest کے پاس VPN 1 کے prefixes کا کوئی route نہیں ہونا چاہیے۔ Centralized policy اور zone-pair ٹھیک کریں۔VPN topology policy aur route leaking dekhen — guest ke paas VPN 1 ke prefixes ka koi route nahi hona chahiye. Centralized policy aur zone-pair theek karen.Check the VPN topology policy and any route leaking — guest must have no route into VPN 1's prefixes. Fix the centralized policy and the zone-pair.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ Pairwise IPsec keys کیا ہیں اور shared key سے بہتر کیوں ہیں؟Pairwise IPsec keys kya hain aur shared key se behtar kyun hain?What are pairwise IPsec keys and why are they better than a shared key?

Pairwise keys کا مطلب ہے کہ دو ڈیوائسز کے درمیان ہر tunnel کی اپنی encryption key ہوتی ہے جو vSmart تقسیم کرتا ہے۔ Compromised key صرف ایک tunnel کو متاثر کرتی ہے، اور keys خودبخود rotate ہوتی ہیں۔Pairwise keys ka matlab hai ke do devices ke darmiyan har tunnel ki apni encryption key hoti hai jo vSmart taqseem karta hai. Compromised key sirf aik tunnel ko mutasir karti hai, aur keys khud-ba-khud rotate hoti hain.Pairwise keys mean every tunnel between two devices gets its own encryption key, distributed via vSmart. A compromised key only affects one tunnel, and keys rotate automatically.

❓ SD-WAN میں segmentation traffic کو کیسے isolate کرتی ہے؟SD-WAN mein segmentation traffic ko kaise isolate karti hai?How does segmentation isolate traffic in SD-WAN?

Segmentation ٹریفک کو الگ الگ VPNs میں بانٹ دیتی ہے (مثال VPN 1 users، VPN 2 guests، VPN 3 IoT کے لیے) تاکہ ایک VPN کی breach یا broadcast storm دوسری تک نہ پہنچ سکے۔Segmentation traffic ko alag alag VPNs mein baant deti hai (misal VPN 1 users, VPN 2 guests, VPN 3 IoT ke liye) taake aik VPN ki breach ya broadcast storm doosri tak na pohanch sake.Segmentation isolates traffic into separate VPNs (e.g. VPN 1 for users, VPN 2 for guests, VPN 3 for IoT) so a breach or broadcast storm in one VPN cannot reach the others.