Web, Application & IPS Policies
Sophos Firewall Sophos VM (GUI + CLI)
مقصدObjectiveObjective
اس لیب میں آپ ویب فلٹرنگ پالیسیز بنائیں گے، ایپلیکیشن کنٹرول سے ایپلیکیشنز بلاک کریں گے اور فائر وال رولز پر IPS پالیسیز enable کریں گے۔Is lab mein aap web filtering policies banayenge, application control se applications block kareinge aur firewall rules par IPS policies enable kareinge.In this lab you will create web filtering policies, block applications with application control, and enable IPS policies on firewall rules.
آسان مثالSimple AnalogySimple Analogy
ویب پالیسی دفتر کے انٹرنیٹ رول بک جیسی ہے: 'سوشل میڈیا صرف لنچ میں، جوئے کی سائٹس کبھی نہیں۔' ایپلیکیشن کنٹرول وہ سخت گارڈ ہے جو ویب سائٹ کے ساتھ فون پر Facebook ایپ کو بھی روکتا ہے۔ IPS وہ الارم ہے جو چوروں کے پہچانے طریقوں کو پہچانتا ہے اور روک دیتا ہے۔Web policy office ke internet rulebook jaisi hai: 'social media sirf lunch mein, gambling sites kabhi nahi.' Application control woh sakht guard hai jo website ke saath phone par Facebook app ko bhi rokta hai. IPS woh alarm hai jo choron ke pehchane tareeqon ko pehchanta hai aur rok deta hai.A web policy is like the office internet rulebook: 'social media only at lunch, gambling sites never.' Application control is the stricter guard who also blocks the Facebook app on your phone, not just the website. IPS is the alarm that recognizes known thief techniques and blocks them.
سیٹ اپLab SetupLab Setup
sophos-03 سے جاری رکھیں جہاں LAN→WAN انٹرنیٹ کام کر رہا ہو۔ براؤزر والا ٹیسٹ LAN PC چاہیے۔ اختیاری: blocked کیٹیگری ٹیسٹ کرنے کے لیے کوئی جانی پہچانی سائٹ اور IPS ٹیسٹ کے لیے DMZ سرور۔sophos-03 se continue karein jahan LAN→WAN internet kaam kar raha ho. Browser wala test LAN PC chahiye. Optional: blocked category test karne ke liye koi jaani pehchani site aur IPS test ke liye DMZ server.Continue from sophos-03 with working LAN→WAN internet access. You need a test LAN PC with a browser. Optional: test access to a known blocked category and a DMZ server for IPS testing.
اقداماتStepsSteps
Step 1
ویب پالیسی بنائیں۔ Web-Standard نام کی پالیسی ایڈ کریں۔ خطرناک کیٹیگریز (gambling, malware, phishing) بلاک کریں اور social networking کو لیب پلان کے مطابق 'warn' یا block سیٹ کریں۔Web policy banayein. Web-Standard naam ki policy add karein. Khatarnaak categories (gambling, malware, phishing) block karein aur social networking ko lab plan ke mutabiq 'warn' ya block set karein.Create a web policy. Add a policy named Web-Standard. Block risky categories (gambling, malware, phishing) and set social networking to 'warn' or block per your lab plan.
🖱️ Protect > Web > Policies > AddProtect > Web > Policies > AddProtect > Web > Policies > Add
Step 2
ویب پالیسی کو رول سے جوڑیں۔ اپنے LAN→WAN فائر وال رول کو ایڈیٹ کر کے Web-Standard پالیسی منتخب کریں۔ ویب پالیسی صرف تب کام کرتی ہے جب فائر وال رول سے linked ہو۔Web policy ko rule se jorein. Apne LAN→WAN firewall rule ko edit kar ke Web-Standard policy select karein. Web policy sirf tab kaam karti hai jab firewall rule se linked ho.Attach the web policy to the rule. Edit your LAN→WAN firewall rule and select the Web-Standard policy. A web policy only works when linked to a firewall rule.
🖱️ Rules and policies > Firewall rules — LAN→WAN رول ایڈیٹ > Web policyRules and policies > Firewall rules — LAN→WAN rule edit > Web policyRules and policies > Firewall rules — edit LAN→WAN rule > Web policy
Step 3
HTTPS انسپیکشن سمجھیں۔ آج زیادہ تر ٹریفک encrypted (HTTPS) ہے، اس لیے ویب فلٹرنگ کو اندر دیکھنے کے لیے TLS انسپیکشن چاہیے۔ تصور سمجھیں: فائر وال CA سرٹیفیکیٹ کے ساتھ درمیان میں کام کرتا ہے جس پر clients کو بھروسہ ہونا چاہیے۔HTTPS inspection samjhein. Aaj zyada tar traffic encrypted (HTTPS) hai, is liye web filtering ko andar dekhne ke liye TLS inspection chahiye. Concept samjhein: firewall CA certificate ke saath darmiyan mein kaam karta hai jis par clients ko bharosa hona chahiye.Understand HTTPS inspection. Most traffic today is encrypted (HTTPS), so web filtering needs TLS inspection to see inside it. Learn the concept: the firewall acts as a middleman with a CA certificate that clients must trust.
🖱️ Protect > Web > General settings — TLS inspectionProtect > Web > General settings — TLS inspectionProtect > Web > General settings — TLS inspection
Step 4
ایپلیکیشن کنٹرول پالیسی بنائیں۔ ایسی پالیسی ایڈ کریں جو منتخب ایپلیکیشنز (مثلاً گیمز، P2P فائل شیئرنگ) کو بلاک کرے۔ ایپلیکیشن کنٹرول ایپس کو random پورٹس پر بھی پہچان لیتا ہے۔Application control policy banayein. Aisi policy add karein jo muntakhab applications (masalan games, P2P file sharing) ko block kare. Application control apps ko random ports par bhi pehchan leta hai.Create an application control policy. Add a policy that blocks selected applications (e.g. games, P2P file sharing). Application control recognizes apps even when they use random ports.
🖱️ Protect > Application control > Add policyProtect > Application control > Add policyProtect > Application control > Add policy
Step 5
پالیسیز کو رول سے جوڑیں۔ LAN→WAN رول ایڈیٹ کر کے اپنی ایپلیکیشن کنٹرول پالیسی اور ایک IPS پالیسی ایڈ کریں۔ ایک رول میں ویب، ایپ کنٹرول اور IPS تینوں ساتھ لگ سکتے ہیں۔Policies ko rule se jorein. LAN→WAN rule edit kar ke apni application control policy aur ek IPS policy add karein. Ek rule mein web, app control aur IPS teeno saath lag sakte hain.Attach the policies to the rule. Edit the LAN→WAN rule and add your application control policy and an IPS policy. One rule can carry web, app control, and IPS together.
🖱️ Rules and policies > Firewall rules — رول ایڈیٹ > Application control policy + Intrusion prevention policyRules and policies > Firewall rules — rule edit > Application control policy + Intrusion prevention policyRules and policies > Firewall rules — edit rule > Application control policy + Intrusion prevention policy
Step 6
IPS پالیسی tune کریں۔ IPS پالیسی کے سگنیچر سیٹس اور ایکشنز (drop vs detect) دیکھیں۔ نئی پالیسیز کے لیے 'detect' سے شروع کریں تاکہ جائز ٹریفک بلاک نہ ہو، پھر drop پر سوئچ کریں۔IPS policy tune karein. IPS policy ke signature sets aur actions (drop vs detect) dekhein. Nayi policies ke liye 'detect' se shuru karein taake jaiz traffic block na ho, phir drop par switch karein.Tune the IPS policy. Review the IPS policy's signature sets and actions (drop vs. detect). Start with 'detect' for new policies to avoid blocking legitimate traffic, then switch to drop.
🖱️ Protect > Intrusion prevention — پالیسی severity چیک کریںProtect > Intrusion prevention — policy severity check kareinProtect > Intrusion prevention — check policy severity
تصدیقVerifyVerify
LAN PC سے: blocked کیٹیگریز پر Sophos بلاک پیج نظر آئے، blocked ایپس کنیکٹ نہ ہوں، اور لاگ ویوئر میں ویب، ایپ کنٹرول اور IPS ایونٹس نظر آئیں۔LAN PC se: blocked categories par Sophos block page nazar aaye, blocked apps connect na hon, aur log viewer mein web, app control aur IPS events nazar aayein.From the LAN PC: blocked categories show the Sophos block page, blocked apps fail to connect, and the log viewer shows web, app control, and IPS events.
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ بلاک کی ہوئی ویب سائٹس پھر بھی کھل رہی ہیں۔Block ki hui websites phir bhi khul rahi hain.Blocked websites still open.
✅ کنفرم کریں کہ ویب پالیسی واقعی فائر وال رول سے linked ہے — linked ہوئے بغیر پالیسیز کچھ نہیں کرتیں۔ اور یاد رکھیں: TLS انسپیکشن کے بغیر HTTPS سائٹس صرف ڈومین نیم سے فلٹر ہوتی ہیں۔Confirm karein ke web policy waqai firewall rule se linked hai — linked hue baghair policies kuch nahi kartin. Aur yaad rakhein: TLS inspection ke baghair HTTPS sites sirf domain name se filter hoti hain.Confirm the web policy is actually attached to the firewall rule — policies do nothing until linked. Also remember: without TLS inspection, HTTPS sites are only filtered by domain name.
⚠️ IPS جائز بزنس ٹریفک بلاک کر رہا ہے۔IPS jaiz business traffic block kar raha hai.IPS is blocking legitimate business traffic.
✅ پہلے IPS پالیسی کو detect-only پر سوئچ کریں، لاگ ویوئر میں سگنیچر ڈھونڈیں اور پوری پالیسی بند کرنے کے بجائے اس سگنیچر کے لیے exception ایڈ کریں۔Pehle IPS policy ko detect-only par switch karein, log viewer mein signature dhoondein aur poori policy band karne ke bajaye us signature ke liye exception add karein.Switch the IPS policy to detect-only first, find the signature in the log viewer, and add an exception for it instead of disabling the whole policy.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ ویب پالیسی اور ایپلیکیشن کنٹرول میں فرق کیا ہے؟Web policy aur application control mein farq kya hai?What is the difference between a web policy and application control?
ویب پالیسی ویب سائٹس کو کیٹیگری اور URL سے فلٹر کرتی ہے؛ ایپلیکیشن کنٹرول ایپلیکیشنز کو (جیسے Facebook یا BitTorrent) پورٹ یا پروٹوکول کی پرواہ کیے بغیر پہچانتا اور بلاک کرتا ہے۔Web policy websites ko category aur URL se filter karti hai; application control applications ko (jaise Facebook ya BitTorrent) port ya protocol se parwah kiye baghair pehchanta aur block karta hai.A web policy filters websites by category and URL; application control identifies and blocks applications (like Facebook or BitTorrent) regardless of port or protocol.
❓ IPS وہ کیا کرتا ہے جو عام فائر وال رول نہیں کر سکتا؟IPS woh kya karta hai jo aam firewall rule nahi kar sakta?What does IPS do that a plain firewall rule cannot?
IPS (Intrusion Prevention System) نیٹ ورک ٹریفک میں پہلے سے جانے گئے اٹیک سگنیچرز (جیسے SQL injection یا buffer overflow) کو پہچانتا اور بلاک کرتا ہے۔ یہ فائر وال کا ساتھ دیتا ہے جو صرف IP، پورٹ اور زون سے فلٹر کرتا ہے۔IPS (Intrusion Prevention System) network traffic mein pehle se jane gaye attack signatures (jaise SQL injection ya buffer overflow) ko pehchanta aur block karta hai. Ye firewall ka sath deta hai jo sirf IP, port aur zone se filter karta hai.IPS (Intrusion Prevention System) detects and blocks known attack signatures — like SQL injection or buffer overflows — in network traffic. It complements the firewall, which only filters by IP, port, and zone.