Interfaces, Zones & Routing

Sophos Firewall Sophos VM (GUI + CLI)

مقصدObjectiveObjective

اس لیب میں آپ Sophos Firewall میں انٹرفیسز اور زونز کنفیگر کریں گے اور اسٹیٹک اور ڈیفالٹ روٹس ایڈ کریں گے۔Is lab mein aap Sophos Firewall mein interfaces aur zones configure kareinge aur static aur default routes add kareinge.In this lab you will configure interfaces and zones in Sophos Firewall, and add static and default routes.

آسان مثالSimple AnalogySimple Analogy

زونز دفتر کے کمروں جیسے ہیں جن میں رسائی کی سطحیں ہوتی ہیں: اسٹاف روم (LAN) سب کے لیے، سرور روم (DMZ) صرف ایڈمنز کے لیے، اور باہر کی گلی (WAN)۔ اسٹیٹک روٹس وہ ایڈریس بورڈ ہیں جو ہر راہداری کو بتاتی ہیں کہ جانا کہاں ہے۔Zones office ke kamron jaisi hain jin mein access level hote hain: staff room (LAN) sab ke liye, server room (DMZ) sirf admins ke liye, aur bahar ki gali (WAN). Static routes wali address board hain jo har corridor ko batati hain ke jana kahan hai.Zones are like rooms in an office with access levels: the staff room (LAN) is open to everyone, the server room (DMZ) only to admins, and the street (WAN) is outside. Static routes are the address boards that tell each corridor where to go.

سیٹ اپLab SetupLab Setup

sophos-01 سے جاری رکھیں۔ ٹوپولوجی: LAN PC (192.168.1.10) → Sophos Port1 (LAN zone, 192.168.1.1/24), Sophos Port2 (WAN zone, 203.0.113.2/30) → ISP router (203.0.113.1)۔ اختیاری: Port3 پر ویب سرور (10.10.10.10) (DMZ zone, 10.10.10.1/24)۔sophos-01 se continue karein. Topology: LAN PC (192.168.1.10) → Sophos Port1 (LAN zone, 192.168.1.1/24), Sophos Port2 (WAN zone, 203.0.113.2/30) → ISP router (203.0.113.1). Optional: Port3 par web server (10.10.10.10) (DMZ zone, 10.10.10.1/24).Continue from sophos-01. Topology: LAN PC (192.168.1.10) → Sophos Port1 (LAN zone, 192.168.1.1/24), Sophos Port2 (WAN zone, 203.0.113.2/30) → ISP router (203.0.113.1). Optional: a web server (10.10.10.10) on Port3 (DMZ zone, 10.10.10.1/24).

اقداماتStepsSteps

Step 1

انٹرفیسز کا جائزہ لیں۔ Network > Interfaces کھولیں اور ہر پورٹ کا IP، زون اور لنک اسٹیٹس نوٹ کریں۔Interfaces ka jaiza lein. Network > Interfaces kholein aur har port ka IP, zone aur link status note karein.Inspect the interfaces. Open Network > Interfaces and note the IP, zone, and link status of each port.

🖱️ Network > Interfaces — ہر پورٹ کو دیکھیںNetwork > Interfaces — har port ko dekheinNetwork > Interfaces — inspect each port

Step 2

LAN اور WAN اسائن کریں۔ Port1 پر LAN IP (LAN zone میں) اور Port2 پر پبلک IP (WAN zone میں) سیٹ کریں۔ WAN کا گیٹ وے (ISP روٹر کا IP) سیٹ کریں۔LAN aur WAN assign karein. Port1 par LAN IP (LAN zone mein) aur Port2 par public IP (WAN zone mein) set karein. WAN ka gateway (ISP router ka IP) set karein.Assign the LAN and WAN. Put the LAN IP on Port1 in the LAN zone, and the public IP on Port2 in the WAN zone. Set the WAN gateway (ISP router IP).

🖱️ Network > Interfaces > پورٹ پر کلک > IP اور زون ایڈیٹ کریںNetwork > Interfaces > port par click > IP aur zone edit kareinNetwork > Interfaces > click port > edit IP and zone

Step 3

زونز کے ساتھ کام کریں۔ پہلے سے بنے زونز دیکھیں۔ اگر ضرورت ہو تو کسٹم زون (مثلاً GUEST) بنائیں اور اس میں انٹرفیس شفٹ کریں — ہر انٹرفیس صرف ایک ہی زون میں ہوتا ہے۔Zones ke saath kaam karein. Pehle se bane zones dekhein. Agar zaroorat ho to custom zone (masalan GUEST) banayein aur us mein interface shift karein — har interface sirf ek hi zone mein hota hai.Work with zones. Review the pre-built zones. If needed, create a custom zone (e.g. GUEST) and move an interface into it — each interface lives in exactly one zone.

🖱️ Network > Zones — دیکھیں اور ایڈ کریںNetwork > Zones — dekhein aur add kareinNetwork > Zones — view and add

Step 4

DMZ انٹرفیس ایڈ کریں۔ Port3 کو IP دیں (10.10.10.1/24) اور DMZ زون میں رکھیں۔ ٹیسٹ ویب سرور اسی پر کنیکٹ کریں۔DMZ interface add karein. Port3 ko IP dein (10.10.10.1/24) aur DMZ zone mein rakhein. Test web server isi par connect karein.Add a DMZ interface. Give Port3 an IP (10.10.10.1/24) and put it in the DMZ zone. Connect your test web server here.

🖱️ Network > Interfaces > Port3 — DMZ zone اسائن کریںNetwork > Interfaces > Port3 — DMZ zone assign kareinNetwork > Interfaces > Port3 — assign DMZ zone

Step 5

روٹس ایڈ کریں۔ انٹرنیٹ رسائی کے لیے ڈیفالٹ روٹ (0.0.0.0/0، ISP گیٹ وے سے) بنائیں۔ لیب کی ضرورت کے مطابق اسٹیٹک روٹس ایڈ کریں، مثلاً دوسری برانچ نیٹ ورک کسی اور گیٹ وے سے۔Routes add karein. Internet access ke liye default route (0.0.0.0/0, ISP gateway se) banayein. Lab ki zaroorat ke mutabiq static routes add karein, masalan doosri branch network kisi aur gateway se.Add routes. Create the default route (0.0.0.0/0 via the ISP gateway) for internet access. Add any static route your lab needs, e.g. a second branch network via another gateway.

🖱️ Network > Routing > Static routes — AddNetwork > Routing > Static routes — AddNetwork > Routing > Static routes — Add

Step 6

روٹنگ ویریفائی کریں۔ دیکھیں کہ ڈیفالٹ روٹ اور تمام اسٹیٹک روٹس روٹ ٹیبل میں نظر آئیں اور ریچیبل ہوں۔Routing verify karein. Dekhein ke default route aur tamam static routes route table mein nazar aayein aur reachable hon.Verify routing. Check that the default route and all static routes appear in the route table and are reachable.

show route

🖱️ Network > Routing — روٹ ٹیبل ویریفائی کریںNetwork > Routing — route table verify kareinNetwork > Routing — verify the route table

تصدیقVerifyVerify

روٹ ٹیبل میں ISP گیٹ وے کے ذریعے ڈیفالٹ روٹ نظر آنا چاہیے اور LAN PC کو WAN گیٹ وے کا IP پنگ ہونا چاہیے۔Route table mein ISP gateway ke through default route nazar aana chahiye aur LAN PC ko WAN gateway ka IP ping hona chahiye.The route table should show the default route via the ISP gateway, and a LAN PC should be able to ping the WAN gateway IP.

show route
show interface

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ LAN سے انٹرنیٹ کا ٹریفک نہیں جا رہا۔LAN se internet ka traffic nahi ja raha.Traffic from LAN cannot reach the internet.

✅ ڈیفالٹ روٹ چیک کریں: گیٹ وے ISP روٹر کا IP ہونا چاہیے اور WAN انٹرفیس up ہونا چاہیے۔ SNAT (masquerading) رول بھی ہونا ضروری ہے — یہ sophos-03 میں ہے۔Default route check karein: gateway ISP router ka IP hona chahiye aur WAN interface up hona chahiye. SNAT (masquerading) rule bhi hona zaroori hai — ye sophos-03 mein hai.Check the default route: the gateway must be the ISP router's IP and the WAN interface must be up. Also confirm a SNAT (masquerading) rule exists — covered in sophos-03.

⚠️ انٹرفیس کسی زون میں شفٹ نہیں ہو رہا۔Interface kisi zone mein shift nahi ho raha.An interface cannot be moved into a zone.

✅ شاید انٹرفیس ابھی کسی فائر وال رول یا DHCP سے ریفرنس ہو رہا ہے۔ پہلے ان ریفرنسز کو ہٹا کر پھر زون تبدیل کریں۔Shayad interface abhi kisi firewall rule ya DHCP se reference ho raha hai. Pehle un references ko hata kar phir zone tabdeel karein.The interface may still be referenced by a firewall rule or DHCP. Remove those references first, then change the zone.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ LAN، WAN اور DMZ زونز سمجھائیں۔LAN, WAN aur DMZ zones samjhayein.Explain LAN, WAN, and DMZ zones.

LAN = اندرونی نیٹ ورک، WAN = انٹرنیٹ اپ لنک، DMZ = عوامی سرورز (ویب/میل)۔ LAN, WAN تک جا سکتا ہے، مگر WAN سیدھا LAN تک نہیں پہنچ سکتا۔LAN = internal network, WAN = internet uplink, DMZ = public servers (web/mail). LAN, WAN tak ja sakta hai, magar WAN seedha LAN tak nahi pohnch sakta.LAN = internal network, WAN = internet uplink, DMZ = public servers (web/mail). LAN can reach WAN, but WAN cannot reach LAN directly.

❓ WAN پر ڈیفالٹ روٹ کی ضرورت کیوں ہوتی ہے؟WAN par default route ki zaroorat kyun hoti hai?Why is a default route needed on the WAN?

ڈیفالٹ روٹ (0.0.0.0/0) تمام نامعلوم ٹریفک کو ISP کے گیٹ وے کی طرف بھیجتا ہے۔ WAN پر یہ ضروری ہے تاکہ انٹرنیٹ کا ٹریفک جانے کہ اسے کہاں جانا ہے۔Default route (0.0.0.0/0) tamam namalum traffic ko ISP ke gateway ki taraf bhejta hai. WAN par ye zaroori hai taake internet ka traffic jana jaane.A default route (0.0.0.0/0) sends all unknown traffic to the ISP gateway. It is needed on the WAN side so internet traffic knows where to go.