📝 Section Review: Firewall Rules & NAT
اہم نکاتKey TakeawaysKey Takeaways
- فائر وال رول میں سورس زون/نیٹ ورک، ڈیسٹینیشن زون/نیٹ ورک، سروسز اور ایکشن (allow/deny) ہوتے ہیں۔Firewall rule mein source zone/network, destination zone/network, services aur action (allow/deny) hote hain.A firewall rule has source zone/network, destination zone/network, services, and an action (allow/deny).
- رولز اوپر سے نیچے میچ ہوتے ہیں؛ پہلا میچنگ رول جیتتا ہے — order matter کرتا ہے۔Rules upar se neeche match hote hain; pehla matching rule jeetta hai — order matter karta hai.Rules are matched top-down; the first matching rule wins — order matters.
- SNAT (masquerading) انٹرنیٹ رسائی کے لیے LAN کے پرائیویٹ IPs کو WAN IP کے پیچھے چھپاتا ہے۔SNAT (masquerading) internet access ke liye LAN ke private IPs ko WAN IP ke peeche chhupata hai.SNAT (masquerading) hides LAN private IPs behind the WAN IP for internet access.
- DNAT (Full NAT) اندرونی سرور کو انٹرنیٹ پر پبلش کرتا ہے؛ اسے میچنگ فائر وال رول بھی چاہیے۔DNAT (Full NAT) internal server ko internet par publish karta hai; isay matching firewall rule bhi chahiye.DNAT (Full NAT) publishes an internal server to the internet; it needs a matching firewall rule too.
- رولز کو لاگ ویوئر سے ویریفائی کریں: ہر ایونٹ پر action اور rule ID دیکھیں۔Rules ko log viewer se verify karein: har event par action aur rule ID dekhein.Verify rules with the log viewer: check the action and rule ID on each event.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ فائر وال رول کے حصے کون سے ہیں اور رولز کیسے evaluate ہوتے ہیں؟Firewall rule ke hisse kaun se hain aur rules kaise evaluate hote hain?What are the parts of a firewall rule, and how are rules evaluated?
سورس زون/نیٹ ورک، ڈیسٹینیشن زون/نیٹ ورک، سروسز اور ایکشن۔ رولز اوپر سے نیچے چیک ہوتے ہیں؛ پہلا میچ جیتتا ہے۔Source zone/network, destination zone/network, services aur action. Rules upar se neeche check hote hain; pehla match jeetta hai.Source zone/network, destination zone/network, services, and action. Rules are evaluated top-down; the first match wins.
❓ سرور پبلش کرنے کے لیے صرف DNAT رول کافی نہیں۔ اور کیا چاہیے؟Server publish karne ke liye sirf DNAT rule kaafi nahi. Aur kya chahiye?A DNAT rule alone is not enough. What else is needed to publish a server?
میچنگ فائر وال رول (مثلاً WAN→DMZ اس سروس پورٹ پر) جو ٹریفک allow کرے، plus سرور translated پورٹ پر listen کر رہا ہو۔Matching firewall rule (masalan WAN→DMZ us service port par) jo traffic allow kare, plus server translated port par listen kar raha ho.A matching firewall rule (e.g. WAN→DMZ on the service port) that allows the traffic, plus the server listening on the translated port.
❓ وسیع allow رول کے نیچے block رول ignore ہو رہا ہے۔ ٹھیک کیسے کریں؟Wasee allow rule ke neeche block rule ignore ho raha hai. Theek kaise karein?A block rule under a broad allow rule is ignored. How do you fix it?
خاص block رول کو وسیع allow رول سے اوپر لے جائیں۔ رولز اوپر سے نیچے میچ ہوتے ہیں، اس لیے block پہلے آنا چاہیے۔Khaas block rule ko wasee allow rule se upar le jayein. Rules upar se neeche match hote hain, is liye block pehle aana chahiye.Move the specific block rule above the broad allow rule. Rules are matched top-down, so the block must come first.