📝 Section Review: Firewall Rules & NAT

اہم نکاتKey TakeawaysKey Takeaways

خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)

یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.

❓ فائر وال رول کے حصے کون سے ہیں اور رولز کیسے evaluate ہوتے ہیں؟Firewall rule ke hisse kaun se hain aur rules kaise evaluate hote hain?What are the parts of a firewall rule, and how are rules evaluated?

سورس زون/نیٹ ورک، ڈیسٹینیشن زون/نیٹ ورک، سروسز اور ایکشن۔ رولز اوپر سے نیچے چیک ہوتے ہیں؛ پہلا میچ جیتتا ہے۔Source zone/network, destination zone/network, services aur action. Rules upar se neeche check hote hain; pehla match jeetta hai.Source zone/network, destination zone/network, services, and action. Rules are evaluated top-down; the first match wins.

❓ سرور پبلش کرنے کے لیے صرف DNAT رول کافی نہیں۔ اور کیا چاہیے؟Server publish karne ke liye sirf DNAT rule kaafi nahi. Aur kya chahiye?A DNAT rule alone is not enough. What else is needed to publish a server?

میچنگ فائر وال رول (مثلاً WAN→DMZ اس سروس پورٹ پر) جو ٹریفک allow کرے، plus سرور translated پورٹ پر listen کر رہا ہو۔Matching firewall rule (masalan WAN→DMZ us service port par) jo traffic allow kare, plus server translated port par listen kar raha ho.A matching firewall rule (e.g. WAN→DMZ on the service port) that allows the traffic, plus the server listening on the translated port.

❓ وسیع allow رول کے نیچے block رول ignore ہو رہا ہے۔ ٹھیک کیسے کریں؟Wasee allow rule ke neeche block rule ignore ho raha hai. Theek kaise karein?A block rule under a broad allow rule is ignored. How do you fix it?

خاص block رول کو وسیع allow رول سے اوپر لے جائیں۔ رولز اوپر سے نیچے میچ ہوتے ہیں، اس لیے block پہلے آنا چاہیے۔Khaas block rule ko wasee allow rule se upar le jayein. Rules upar se neeche match hote hain, is liye block pehle aana chahiye.Move the specific block rule above the broad allow rule. Rules are matched top-down, so the block must come first.