Capstone: Sophos Build
Sophos Firewall Sophos VM (GUI + CLI)
مقصدObjectiveObjective
اس capstone میں آپ scratch سے مکمل Sophos Firewall deploy کریں گے اور deployment چیک لسٹ سے ہر لیئر ویریفائی کریں گے۔Is capstone mein aap scratch se mukammal Sophos Firewall deploy kareinge aur deployment checklist se har layer verify kareinge.In this capstone you will deploy a complete Sophos Firewall from scratch and verify every layer with a deployment checklist.
آسان مثالSimple AnalogySimple Analogy
یہ capstone عمارت کی فائنل انسپیکشن ہے: ہر کمرہ لیبل شدہ، ہر تالا ٹیسٹڈ، CCTV ریکارڈنگ پر، اور spare چابی محفوظ جگہ پر۔ Deployment صرف تب مکمل ہوتا ہے جب سب کچھ ویریفائی اور بیک اپ ہو جائے۔Ye capstone building ki final inspection hai: har kamra label shuda, har taala tested, CCTV recording par, aur spare chaabi mehfooz jagah par. Deployment sirf tab complete hota hai jab sab kuch verify aur backup ho jaye.This capstone is the final inspection of the building: every room labeled, every lock tested, the CCTV recording, and a spare key in a safe place. A deployment is only done when everything is verified and backed up.
سیٹ اپLab SetupLab Setup
Fresh Sophos Firewall VM (factory defaults)۔ ٹوپولوجی: LAN (192.168.10.0/24)، WAN (DHCP/public)، DMZ ویب سرور (10.10.20.10)، ایک remote SSL VPN یوزر، ایک IPsec peer ڈیوائس۔ چیک لسٹ اوپر سے نیچے مکمل کریں۔Fresh Sophos Firewall VM (factory defaults). Topology: LAN (192.168.10.0/24), WAN (DHCP/public), DMZ web server (10.10.20.10), ek remote SSL VPN user, ek IPsec peer device. Checklist upar se neeche mukammal karein.Fresh Sophos Firewall VM (factory defaults). Topology: LAN (192.168.10.0/24), WAN (DHCP/public), DMZ web server (10.10.20.10), one remote SSL VPN user, one IPsec peer device. Work through the checklist top to bottom.
اقداماتStepsSteps
Step 1
فاؤنڈیشن چیک لسٹ۔ setup wizard چلائیں، LAN/WAN/DMZ انٹرفیسز اور زونز سیٹ کریں، ڈیفالٹ روٹ ایڈ کریں، اور basic LAN→WAN ping کنفرم کریں۔Foundation checklist. Setup wizard chalayein, LAN/WAN/DMZ interfaces aur zones set karein, default route add karein, aur basic LAN→WAN ping confirm karein.Foundation checklist. Run the setup wizard, set LAN/WAN/DMZ interfaces and zones, add the default route, and confirm basic LAN→WAN ping works.
🖱️ Wizard + Network > Zones + Network > InterfacesWizard + Network > Zones + Network > InterfacesWizard + Network > Zones + Network > Interfaces
Step 2
رولز اور NAT چیک لسٹ۔ صحیح ترتیب میں LAN→WAN، LAN→DMZ اور WAN→DMZ (پبلشڈ سرور کے لیے) رولز بنائیں۔ MASQ (SNAT) اور DMZ ویب سرور کے لیے DNAT رول ایڈ کریں۔Rules aur NAT checklist. Sahi tartib mein LAN→WAN, LAN→DMZ aur WAN→DMZ (published server ke liye) rules banayein. MASQ (SNAT) aur DMZ web server ke liye DNAT rule add karein.Rules and NAT checklist. Build LAN→WAN, LAN→DMZ, and WAN→DMZ (for the published server) rules in the right order. Add MASQ (SNAT) and the DNAT rule for the DMZ web server.
🖱️ Rules and policies > Firewall rules + Network > NAT > NAT rulesRules and policies > Firewall rules + Network > NAT > NAT rulesRules and policies > Firewall rules + Network > NAT > NAT rules
Step 3
سیکیورٹی پالیسیز چیک لسٹ۔ LAN→WAN رول سے ویب پالیسی، ایپلیکیشن کنٹرول پالیسی اور IPS پالیسی جوڑیں۔ ٹیسٹ کریں کہ blocked کیٹیگریز اور ایپس رک جائیں۔Security policies checklist. LAN→WAN rule se web policy, application control policy aur IPS policy jorein. Test karein ke blocked categories aur apps ruk jayein.Security policies checklist. Attach a web policy, application control policy, and IPS policy to the LAN→WAN rule. Test that blocked categories and apps are stopped.
🖱️ Protect > Web + Protect > Application control + Protect > Intrusion preventionProtect > Web + Protect > Application control + Protect > Intrusion preventionProtect > Web + Protect > Application control + Protect > Intrusion prevention
Step 4
Authentication چیک لسٹ۔ AD سرور کے ساتھ STAS کنفیگر کریں (یا کسٹمر کے لیے دستاویز کریں)، ایڈمن اور VPN یوزرز کے لیے OTP enable کریں اور لاگ اِنز ویریفائی کریں۔Authentication checklist. AD server ke saath STAS configure karein (ya customer ke liye document karein), admin aur VPN users ke liye OTP enable karein aur logins verify karein.Authentication checklist. Configure STAS with the AD server (or document it for the customer), enable OTP for admin and VPN users, and verify logins.
🖱️ Authentication > Services + Authentication > One-time passwordAuthentication > Services + Authentication > One-time passwordAuthentication > Services + Authentication > One-time password
Step 5
VPN چیک لسٹ۔ site-to-site IPsec tunnel اور SSL VPN remote رسائی بنائیں۔ دونوں phases، remote یوزر لاگ اِن اور LAN وسائل تک رسائی ویریفائی کریں۔VPN checklist. Site-to-site IPsec tunnel aur SSL VPN remote access banayein. Dono phases, remote user login aur LAN resources tak access verify karein.VPN checklist. Build the site-to-site IPsec tunnel and the SSL VPN remote access. Verify both phases, remote user login, and access to LAN resources.
🖱️ VPN > IPsec connections + VPN > SSL VPN (remote access)VPN > IPsec connections + VPN > SSL VPN (remote access)VPN > IPsec connections + VPN > SSL VPN (remote access)
Step 6
مینجمنٹ چیک لسٹ۔ کنفرم کریں کہ لاگنگ کام کرتی ہے، Sophos Central سے رجسٹر کریں، رپورٹس شیڈول کریں، اور فائنل کنفیگریشن بیک اپ ڈاؤن لوڈ کریں۔ اسے فائر وال سے باہر اسٹور کریں۔Management checklist. Confirm karein ke logging kaam karti hai, Sophos Central se register karein, reports schedule karein, aur final configuration backup download karein. Isay firewall se bahar store karein.Management checklist. Confirm logging works, register with Sophos Central, schedule reports, and download a final configuration backup. Store it off the firewall.
🖱️ Log viewer + Administration > Central management + System > Backup & firmwareLog viewer + Administration > Central management + System > Backup & firmwareLog viewer + Administration > Central management + System > Backup & firmware
Step 7
فائنل ٹیسٹ: خراب کریں اور recover کریں۔ جان بوجھ کر ایک چیز خراب کریں (رول disable کر دیں، key بدل دیں)، پھر صرف لاگ ویوئر اور diagnostics ٹولز سے اسے troubleshoot کریں۔ اگر آپ اسے ڈھونڈ کر ٹھیک کر سکیں تو deployment آپ کی ہے۔Final test: kharab karein aur recover karein. Jaan boojh kar ek cheez kharab karein (rule disable kar dein, key badal dein), phir sirf log viewer aur diagnostics tools se use troubleshoot karein. Agar aap use dhoond kar theek kar sakein to deployment aap ki hai.Final test: break and recover. Intentionally break one item (disable a rule, change a key), then troubleshoot it using only the log viewer and diagnostics tools. If you can find and fix it, the deployment is yours.
🖱️ ایک چیز خراب کریں، پھر صرف لاگز اور Diagnostics > Tools سے ٹھیک کریںEk cheez kharab karein, phir sirf logs aur Diagnostics > Tools se theek kareinBreak one thing, then fix it using only logs and Diagnostics > Tools
تصدیقVerifyVerify
ہر چیک لسٹ آئٹم پاس ہو: زونز، روٹس، ترتیب سے رولز، SNAT/DNAT، ویب/ایپ/IPS پالیسیز، STAS + MFA، IPsec + SSL VPN، لاگز، Central رجسٹریشن، اور فائر وال سے باہر بیک اپ۔Har checklist item pass ho: zones, routes, tartib se rules, SNAT/DNAT, web/app/IPS policies, STAS + MFA, IPsec + SSL VPN, logs, Central registration, aur firewall se bahar backup.Every checklist item passes: zones, routes, rules in order, SNAT/DNAT, web/app/IPS policies, STAS + MFA, IPsec + SSL VPN, logs, Central registration, and an off-box backup.
show interface show route show vpn
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ چیک لسٹ پہلے قدم پر فیل ہو گیا اور اس کے بعد کچھ کام نہیں کر رہا۔Checklist pehle qadam par fail ho gaya aur us ke baad kuch kaam nahi kar raha.The checklist fails at an early step and nothing after it works.
✅ Deployments لیئر وائز ہوتی ہیں: رولز سے پہلے روٹنگ، NAT سے پہلے رولز، اور VPN سے پہلے connectivity ہونی چاہیے۔ فیل ہونے والی لیئر پر واپس جائیں، اسے ٹھیک کریں، ویریفائی کریں، پھر آگے بڑھیں۔Deployments layer-wise hoti hain: rules se pehle routing, NAT se pehle rules, aur VPN se pehle connectivity honi chahiye. Fail hone wali layer par wapas jayein, use theek karein, verify karein, phir aage barhein.Deployments are layered: routing must work before rules, rules before NAT, and connectivity before VPN. Go back to the failing layer, fix it, verify it, then continue.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ فائر وال handover ڈاکیومنٹ میں کیا ہونا چاہیے؟Firewall handover document mein kya hona chahiye?What belongs in a firewall handover document?
کنفیگریشن کا بیک اپ لیں، ہر رول/NAT/VPN کو اس کے مقصد کے ساتھ دستاویز کریں، ویریفائی کریں کہ ایڈمن رسائی محدود ہے، اور credentials، لائسنسز اور ٹیسٹ رپورٹ handover کریں۔Configuration ka backup lein, har rule/NAT/VPN ko us ke maqsad ke saath document karein, verify karein ke admin access mehdood hai, aur credentials, licenses aur test report handover karein.Backup the configuration, document every rule/NAT/VPN with its purpose, verify admin access is restricted, and hand over credentials, licenses, and a test report.