📝 Section Review: SD-WAN Security
اہم نکاتKey TakeawaysKey Takeaways
- SD-WAN tunnels default IPsec ہوتے ہیں؛ encapsulation ipsec ہونا چاہیے (gre نہیں) اور SAs show security ipsec sa سے verify کریں۔SD-WAN tunnels default IPsec hote hain; encapsulation ipsec hona chahiye (gre nahi) aur SAs show security ipsec sa se verify karen.SD-WAN tunnels are IPsec by default; encapsulation must be ipsec (not gre) and SAs verified with show security ipsec sa.
- Pairwise keys: ہر tunnel کی منفرد key، vSmart تقسیم کرتا ہے، auto-rotate ہوتی ہے۔ ایک shared key کبھی جواب نہیں۔Pairwise keys: har tunnel ki munfarid key, vSmart taqseem karta hai, auto-rotate hoti hai. Aik shared key kabhi jawab nahi.Pairwise keys: one unique key per tunnel, distributed by vSmart, auto-rotated. A single shared key is never the answer.
- Service VPNs (VPN 1 users، VPN 2 guests...) کے ذریعے segmentation plus vSmart پر VPN topology policy طے کرتی ہے کہ کون کس سے بات کرے گا۔Service VPNs (VPN 1 users, VPN 2 guests...) ke zariye segmentation plus vSmart par VPN topology policy tay karti hai ke kaun kisse baat karega.Segmentation via service VPNs (VPN 1 users, VPN 2 guests...) plus VPN topology policy on vSmart controls who talks to whom.
- Zone-based firewall: zones interfaces/VPNs کو group کرتے ہیں، zone-pairs کو inspect policies ملتی ہیں — default deny، صرف ضروری چیز کی اجازت۔Zone-based firewall: zones interfaces/VPNs ko group karte hain, zone-pairs ko inspect policies milti hain — default deny, sirf zaroori cheez ki ijazat.Zone-based firewall: zones group interfaces/VPNs, zone-pairs get inspect policies — deny by default, allow only what is needed.
- Versa routing instances/VRFs + policy سے وہی نتیجہ حاصل کرتا ہے — سیکیورٹی مقصد ایک، اوزار مختلف۔Versa routing instances/VRFs + policy se wahi nateeja hasil karta hai — security maqsad aik, auzaar mukhtalif.Versa achieves the same outcome with routing instances/VRFs + policy — same security goal, different tools.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ Pairwise IPsec keys کیا ہیں؟Pairwise IPsec keys kya hain?What are pairwise IPsec keys?
ہر tunnel کی اپنی encryption key ہوتی ہے جو vSmart تقسیم کرتا ہے؛ compromised key صرف ایک tunnel کو متاثر کرتی ہے اور keys خودبخود rotate ہوتی ہیں۔Har tunnel ki apni encryption key hoti hai jo vSmart taqseem karta hai; compromised key sirf aik tunnel ko mutasir karti hai aur keys khud-ba-khud rotate hoti hain.Every tunnel gets its own encryption key distributed via vSmart; a compromised key affects only one tunnel and keys rotate automatically.
❓ ٹریفک کو service VPNs میں کیوں بانٹتے ہیں؟Traffic ko service VPNs mein kyun baant-te hain?Why segment traffic into service VPNs?
الگ تھلگ: users، guests، IoT کے لیے الگ VPNs تاکہ ایک VPN کی breach یا storm دوسری تک نہ پہنچ سکے۔Alag thalg: users, guests, IoT ke liye alag VPNs taake aik VPN ki breach ya storm doosri tak na pohanch sake.Isolation: separate VPNs for users, guests, IoT so a breach or storm in one VPN cannot reach the others.
❓ SD-WAN edge device پر management VPN کو کیسے secure کریں گے؟SD-WAN edge device par management VPN ko kaise secure karenge?How do you secure the management VPN on an SD-WAN edge device?
VPN کو اپنے zone میں ڈالیں اور ڈیوائس کی طرف صرف DNS/DHCP کی اجازت دیں — باقی سب default deny۔VPN ko apne zone mein dalen aur device ki taraf sirf DNS/DHCP ki ijazat den — baqi sab default deny.Put the VPN in its own zone and allow only DNS/DHCP to the device itself — deny everything else by default.