🎤 Sophos Firewall — Interview Q&A

❓ Sophos Firewall میں زون کیا ہوتا ہے؟Sophos Firewall mein zone kya hota hai?What is a zone in Sophos Firewall?

زون ایک جیسی سیکیورٹی پالیسی والے انٹرفیسز کا گروپ ہے۔ ڈیفالٹ زونز: LAN (اندرونی)، WAN (انٹرنیٹ)، DMZ (عوامی سرورز)، WiFi اور VPN۔Zone ek jaisi security policy wale interfaces ka group hai. Default zones: LAN (internal), WAN (internet), DMZ (public servers), WiFi aur VPN.A zone is a group of interfaces sharing one security policy. Default zones: LAN (internal), WAN (internet), DMZ (public servers), WiFi, and VPN.

❓ فائر وال رول آرڈر کی اہمیت کیوں ہے؟Firewall rule order ki ahmiyat kyun hai?Why does firewall rule order matter?

رولز اوپر سے نیچے میچ ہوتے ہیں؛ پہلا میچنگ رول جیتتا ہے۔ وسیع allow رول خاص block رول کے اوپر اسے چھپا (shadow) دیتا ہے، اس لیے خاص رولز پہلے آنے چاہئیں۔Rules upar se neeche match hote hain; pehla matching rule jeetta hai. Wasee allow rule khaas block rule ke upar use chhupa (shadow) deta hai, is liye khaas rules pehle aane chahiyein.Rules are matched top-down; the first matching rule wins. A broad allow rule above a specific block rule hides (shadows) it, so specific rules must come first.

❓ SNAT اور DNAT میں فرق کیا ہے؟SNAT aur DNAT mein farq kya hai?What is the difference between SNAT and DNAT?

SNAT سورس IP بدلتا ہے — LAN یوزرز انٹرنیٹ پر جاتے ہیں (masquerading)۔ DNAT ڈیسٹینیشن IP بدلتا ہے — اندرونی سرور انٹرنیٹ پر پبلش ہوتا ہے (port forwarding)۔SNAT source IP badalta hai — LAN users internet par jaate hain (masquerading). DNAT destination IP badalta hai — internal server internet par publish hota hai (port forwarding).SNAT rewrites the source IP — LAN users going out to the internet (masquerading). DNAT rewrites the destination IP — publishing an internal server to the internet (port forwarding).

❓ STAS کیا ہے اور یہ کیسے کام کرتا ہے؟STAS kya hai aur ye kaise kaam karta hai?What is STAS and how does it work?

STAS Windows ڈومین کنٹرولرز پر انسٹال ہونے والا ایجنٹ ہے جو یوزر لاگ اِنز کی خبر فائر وال کو دیتا ہے، جس سے transparent single sign-on ملتا ہے — یوزرز captive portal لاگ اِن کے بغیر پہچانے جاتے ہیں۔STAS Windows domain controllers par install hone wala agent hai jo user logins ki khabar firewall ko deta hai, jis se transparent single sign-on milta hai — users captive portal login ke baghair pehchane jate hain.STAS is an agent installed on Windows domain controllers that reports user logins to the firewall, giving transparent single sign-on — users are identified without a captive portal login.

❓ IPsec vs SSL VPN — ہر ایک کب استعمال ہوتا ہے؟IPsec vs SSL VPN — har ek kab istemal hota hai?IPsec vs SSL VPN — when do you use each?

IPsec VPN site-to-site ہے — پوری برانچ آفسز کو مستقل جوڑتا ہے۔ SSL VPN user-to-site ہے — الگ الگ remote یوزرز کلائنٹ یا براؤزر سے کہیں سے بھی کنیکٹ ہوتے ہیں۔IPsec VPN site-to-site hai — poori branch offices ko mustaqil jorta hai. SSL VPN user-to-site hai — alag alag remote users client ya browser se kahin se bhi connect hote hain.IPsec VPN is site-to-site — it permanently connects whole branch offices. SSL VPN is user-to-site — individual remote users connect from anywhere via a client or browser.

❓ ویب فلٹرنگ پالیسی کیسے apply کرتے ہیں؟Web filtering policy kaise apply karte hain?How do you apply a web filtering policy?

ویب پالیسی ویب سائٹس کو کیٹیگری اور URL سے فلٹر کرتی ہے، اور صرف تب کام کرتی ہے جب فائر وال رول سے attached ہو۔ HTTPS سائٹس کی پوری فلٹرنگ کے لیے TLS انسپیکشن چاہیے۔Web policy websites ko category aur URL se filter karti hai, aur sirf tab kaam karti hai jab firewall rule se attached ho. HTTPS sites ki poori filtering ke liye TLS inspection chahiye.A web policy filters websites by category and URL, and only works when attached to a firewall rule. HTTPS sites need TLS inspection for full filtering.

❓ Sophos پر ٹریفک کا مسئلہ troubleshoot کرنے کا طریقہ بتائیں۔Sophos par traffic ka masla troubleshoot karne ka tareeqa batayein.Walk me through troubleshooting a traffic problem on Sophos.

لاگ ویوئر کھولیں، صحیح ماڈیول اور IP سے فلٹر کریں، اور action اور rule ID پڑھیں۔ پھر Diagnostics > Tools سے ping/traceroute سے ویریفائی کریں، رول آرڈر، NAT اور روٹس چیک کریں — اور تبدیلی سے پہلے اور بعد میں بیک اپ کنفرم کریں۔Log viewer kholein, sahi module aur IP se filter karein, aur action aur rule ID parhein. Phir Diagnostics > Tools se ping/traceroute se verify karein, rule order, NAT aur routes check karein — aur tabdeeli se pehle aur baad mein backup confirm karein.Open the log viewer, filter by the right module and IP, and read the action and rule ID. Then verify with ping/traceroute from Diagnostics > Tools, check rule order, NAT, and routes — and confirm the change with a backup before and after.