Logging, Central Management & Troubleshooting
Sophos Firewall Sophos VM (GUI + CLI)
مقصدObjectiveObjective
اس لیب میں آپ لاگ ویوئر استعمال کریں گے، Sophos Central مینجمنٹ سمجھیں گے، بیک اپس لیں گے اور troubleshooting ورک فلو کی پریکٹس کریں گے۔Is lab mein aap log viewer istemal kareinge, Sophos Central management samjhenge, backups leinge aur troubleshooting workflow ki practice kareinge.In this lab you will use the log viewer, understand Sophos Central management, take backups, and practice a troubleshooting workflow.
آسان مثالSimple AnalogySimple Analogy
لاگز فائر وال کی CCTV فوٹیج ہیں — جب کچھ غلط ہو تو آپ rewind کر کے دیکھتے ہیں کہ کیا ہوا۔ Sophos Central وہ ہیڈ آفس ہے جو تمام برانچز کے کیمرے ایک کمرے سے دیکھتا ہے۔ Diagnostics ٹولز گارڈ کا walkie-talkie اور ٹارچ ہیں: ping، traceroute اور packet capture، خرابی ڈھونڈنے کے لیے۔Logs firewall ki CCTV footage hain — jab kuch ghalat ho to aap rewind kar ke dekhte hain ke kya hua. Sophos Central woh head office hai jo tamam branches ke cameras ek kamre se dekhta hai. Diagnostics tools guard ka walkie-talkie aur torch hain: ping, traceroute aur packet capture, kharabi dhoondne ke liye.Logs are the firewall's CCTV footage — when something goes wrong, you rewind and watch what happened. Sophos Central is the head office that watches all branch cameras from one room. Diagnostics tools are the guard's walkie-talkie and torch: ping, traceroute, and packet capture for finding the fault.
سیٹ اپLab SetupLab Setup
sophos-06 سے جاری رکھیں جہاں تمام پچھلی لیبز کام کر رہی ہوں (رولز، NAT، VPN، پالیسیز)۔ اس لیب میں جان بوجھ کر کچھ خراب کریں (مثلاً کوئی رول disable کر دیں) اور لاگز اور ٹولز سے اسے ڈھونڈیں۔sophos-06 se continue karein jahan tamam pichli labs kaam kar rahi hon (rules, NAT, VPN, policies). Is lab mein jaan boojh kar kuch kharab karein (masalan koi rule disable kar dein) aur logs aur tools se use dhoondein.Continue from sophos-06 with all previous labs working (rules, NAT, VPN, policies). Break something on purpose in this lab (e.g. disable a rule) and use logs and tools to find it.
اقداماتStepsSteps
Step 1
لاگ ویوئر میں مہارت حاصل کریں۔ اسے کھول کر ماڈیول (Firewall، Web filter، IPS، VPN) اور سورس IP سے فلٹر کرنے کی پریکٹس کریں۔ action اور rule ID کالمز دیکھیں تاکہ پتا چلے ہر پیکٹ کو کس رول نے ہینڈل کیا۔Log viewer mein maharat hasil karein. Isay khol kar module (Firewall, Web filter, IPS, VPN) aur source IP se filter karne ki practice karein. Action aur rule ID columns dekhein taake pata chale har packet ko kis rule ne handle kiya.Master the log viewer. Open it and practice filtering by module (Firewall, Web filter, IPS, VPN) and by source IP. Check the action and rule ID columns to see which rule handled each packet.
🖱️ Log viewer > View log viewer — فلٹرز لگائیںLog viewer > View log viewer — filters lagayeinLog viewer > View log viewer — apply filters
Step 2
رپورٹس پڑھیں۔ built-in رپورٹس کھولیں (top users، top blocked categories، VPN usage)۔ رپورٹس کچے لاگز کو مینیجرز اور آڈیٹرز کے لیے جوابوں میں بدل دیتی ہیں۔Reports parhein. Built-in reports kholein (top users, top blocked categories, VPN usage). Reports kacche logs ko managers aur auditors ke liye jawabon mein badal deti hain.Read reports. Open the built-in reports (top users, top blocked categories, VPN usage). Reports turn raw logs into answers for managers and auditors.
🖱️ Reports > View reports — کوئی رپورٹ چنیںReports > View reports — koi report chuneinReports > View reports — pick a report
Step 3
Sophos Central سمجھیں۔ فائر وال کو Sophos Central (کلاؤڈ) سے رجسٹر کریں۔ ایک پورٹل سے آپ کئی فائر والز پر پالیسیز push کر سکتے ہیں، الرٹس مانیٹر کر سکتے ہیں اور فرم ویئر اپ ڈیٹ کر سکتے ہیں — سنگل فائر وال لیب میں بھی تصور سیکھیں۔Sophos Central samjhein. Firewall ko Sophos Central (cloud) se register karein. Ek portal se aap kai firewalls par policies push kar sakte hain, alerts monitor kar sakte hain aur firmware update kar sakte hain — single-firewall lab mein bhi concept seekhein.Understand Sophos Central. Register the firewall with Sophos Central (cloud). From one portal you can push policies, monitor alerts, and update firmware for many firewalls — learn the concept even in a single-firewall lab.
🖱️ Administration > Central management — فائر وال رجسٹر کریںAdministration > Central management — firewall register kareinAdministration > Central management — register the firewall
Step 4
diagnostics ٹولز استعمال کریں۔ فائر وال سے ہی connectivity ٹیسٹ کرنے کے لیے ping اور traceroute چلائیں۔ LAN انٹرفیس پر چھوٹا packet capture لیں اور اسے پڑھ کر اصل ٹریفک دیکھیں۔Diagnostics tools istemal karein. Firewall se hi connectivity test karne ke liye ping aur traceroute chalayein. LAN interface par chhota packet capture lein aur use parh kar asli traffic dekhein.Use diagnostics tools. Run ping and traceroute to test connectivity from the firewall itself. Take a short packet capture on the LAN interface and read it to see real traffic.
🖱️ Diagnostics > Tools — ping، traceroute، packet captureDiagnostics > Tools — ping, traceroute, packet captureDiagnostics > Tools — ping, traceroute, packet capture
Step 5
بیک اپ لیں۔ ہر تبدیلی سے پہلے — اور کام کرتی تبدیلی کے بعد — پوری کنفیگریشن کا بیک اپ ڈاؤن لوڈ کریں۔ بیک اپ غلطی سے سب سے تیز ریکوری ہے۔Backup lein. Har tabdeeli se pehle — aur kaam karti tabdeeli ke baad — poori configuration ka backup download karein. Backup ghalti se sab se tez recovery hai.Take a backup. Download a full configuration backup before any change — and after a working change. A backup is the fastest recovery from a mistake.
🖱️ System > Backup & firmware > Backup — ڈاؤن لوڈ کریںSystem > Backup & firmware > Backup — download kareinSystem > Backup & firmware > Backup — download
Step 6
troubleshooting فلو کی پریکٹس کریں۔ کچھ خراب کریں (LAN→WAN رول disable کر دیں)، پھر اسے ڈھونڈیں: لاگ ویوئر میں drop دیکھیں، کنسول سے ping سے ویریفائی کریں، رول ٹھیک کریں، اور کنفرم کریں کہ ٹریفک واپس آ گیا۔Troubleshooting flow ki practice karein. Kuch kharab karein (LAN→WAN rule disable kar dein), phir use dhoondein: log viewer mein drop dekhein, console se ping se verify karein, rule theek karein, aur confirm karein ke traffic wapas aa gaya.Practice a troubleshooting flow. Break something (disable the LAN→WAN rule), then find it: check the log viewer for the drop, verify with ping from the console, fix the rule, and confirm traffic returns.
system diagnostics utilities ping host 8.8.8.8
🖱️ Device Console (console menu) — ping چلائیںDevice Console (console menu) — ping chalayeinDevice Console (console menu) — run the ping
تصدیقVerifyVerify
آپ لاگز کو ماڈیول اور IP سے فلٹر کر سکتے ہیں، رول ID سے drop کی وجہ بتا سکتے ہیں، ڈاؤن لوڈڈ بیک اپ فائل دکھا سکتے ہیں، اور بتا سکتے ہیں کہ Sophos Central اس فائر وال کو کیسے مینج کرے گا۔Aap logs ko module aur IP se filter kar sakte hain, rule ID se drop ki wajah bata sakte hain, downloaded backup file dikha sakte hain, aur bata sakte hain ke Sophos Central is firewall ko kaise manage karega.You can filter logs by module and IP, explain a drop using the rule ID, show a downloaded backup file, and describe how Sophos Central would manage this firewall.
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ میرے ٹیسٹ ٹریفک کے لیے لاگ ویوئر میں کچھ نظر نہیں آ رہا۔Mere test traffic ke liye log viewer mein kuch nazar nahi aa raha.The log viewer shows nothing for my test traffic.
✅ اپنا فلٹر چیک کریں — غلط ٹائم رینج یا ماڈیول رزلٹس چھپا دیتا ہے۔ کنفرم کریں کہ فائر وال رول پر لاگنگ on ہے (log option) اور ٹریفک واقعی فائر وال سے گزر رہا ہے۔Apna filter check karein — ghalat time range ya module results chhupa deta hai. Confirm karein ke firewall rule par logging on hai (log option) aur traffic waqai firewall se guzar raha hai.Check your filter — wrong time range or module hides results. Also confirm logging is enabled on the firewall rule (log option) and that traffic actually passes through the firewall.
⚠️ فائر وال Sophos Central سے رجسٹر نہیں ہو رہا۔Firewall Sophos Central se register nahi ho raha.The firewall cannot register with Sophos Central.
✅ فائر وال کو Sophos Central تک پہنچنے کے لیے انٹرنیٹ اور DNS چاہیے۔ ڈیفالٹ روٹ، DNS سرورز ویریفائی کریں اور کنفرم کریں کہ کوئی رول فائر وال کے اپنے outbound ٹریفک کو بلاک نہیں کر رہا۔Firewall ko Sophos Central tak pohnchne ke liye internet aur DNS chahiye. Default route, DNS servers verify karein aur confirm karein ke koi rule firewall ke apne outbound traffic ko block nahi kar raha.The firewall needs internet access and DNS to reach Sophos Central. Verify the default route, DNS servers, and that no rule blocks the firewall's own outbound traffic.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Sophos پر ٹریفک کا مسئلہ کیسے troubleshoot کریں گے؟Sophos par traffic ka masla kaise troubleshoot kareinge?How do you troubleshoot a traffic problem on Sophos?
Log viewer > View log viewer کھولیں، صحیح ماڈیول (Firewall، Web، VPN) سے فلٹر کریں، اور action، rule ID، source/destination اور reason فیلڈز دیکھیں۔Log viewer > View log viewer kholein, sahi module (Firewall, Web, VPN) se filter karein, aur action, rule ID, source/destination aur reason fields dekhein.Open Log viewer > View log viewer, filter by the right module (Firewall, Web, VPN), and look at the action, rule ID, source/destination, and reason fields.
❓ Sophos Central کیا ہے اور اسے کیوں استعمال کریں؟Sophos Central kya hai aur isay kyun use karein?What is Sophos Central and why use it?
Sophos Central کلاؤڈ مینجمنٹ ہے: ایک پورٹل سے کئی فائر والز کی پالیسیز، فرم ویئر، الرٹس اور رپورٹس مینج کرنا۔ ہر باکس میں الگ لاگ اِن کی زحمت بچتی ہے اور یہ MSPs اور multi-branch کمپنیز کے لیے ideal ہے۔Sophos Central cloud management hai: ek portal se kai firewalls ki policies, firmware, alerts aur reports manage karna. Har box mein alag login ki zahmat bachte hai aur ye MSPs aur multi-branch companies ke liye ideal hai.Sophos Central is cloud management: one portal to manage policies, firmware, alerts, and reports for many firewalls. It saves logging in to each box separately and is ideal for MSPs and multi-branch companies.