Capstone: Secure Internet / SASE Policy Deployment
Zscaler Internet Access (ZIA) Zscaler portal — demo tenant (GUI)
مقصدObjectiveObjective
اس کیپ اسٹون میں آپ ZIA کے تمام اہم پالیسی ماڈیولز — URL فلٹرنگ، SSL انسپیکشن، DLP اور تھریٹ پروٹیکشن — کو ایک مکمل SASE پالیسی سیٹ کے طور پر ڈپلائے اور ٹیسٹ کریں گے۔Is capstone mein aap ZIA ke tamam ahem policy modules — URL filtering, SSL inspection, DLP aur threat protection — ko ek mukammal SASE policy set ke tor par deploy aur test karenge.In this capstone you will deploy and test all the key ZIA policy modules — URL filtering, SSL inspection, DLP and threat protection — as one complete SASE policy set.
آسان مثالSimple AnalogySimple Analogy
یہ ایسے ہے جیسے آپ ایک نئی عمارت کے لیے تمام حفاظتی انتظامات ایک ساتھ لگائیں — دروازے پر چوکی (URL فلٹرنگ)، سامان کی جانچ (SSL انسپیکشن)، قیمتی دستاویزات کی نگرانی (DLP) اور دھماکا خیز مواد کا اسکینر (سینڈ باکس)۔Yeh aisa hai jaise aap ek nayi imarat ke liye tamam hifazati intizamaat ek saath lagayen — darwaze par chowki (URL filtering), saman ki janch (SSL inspection), qeemti dastavezat ki nigrani (DLP) aur dhamaka-khez mawaad ka scanner (sandbox).This is like fitting out a new building with all its security at once — a guard post at the door (URL filtering), baggage screening (SSL inspection), valuables monitoring (DLP) and an explosives scanner (sandbox).
سیٹ اپLab SetupLab Setup
Zscaler ڈیمو ٹیننٹ کے پورٹل میں لاگ اِن کریں۔ آپ کو ایک ٹیسٹ لوکیشن، ایک ٹیسٹ یوزر اور ٹیسٹ ٹریفک بھیجنے کے لیے ایک لیپ ٹاپ درکار ہے۔ تمام مراحل GUI میں ہیں — کوئی کمانڈ نہیں۔Zscaler demo tenant ke portal mein log in karein. Aap ko ek test location, ek test user aur test traffic bhejne ke liye ek laptop darkar hai. Tamam marahil GUI mein hain — koi command nahi.Log in to the Zscaler demo tenant portal. You need one test location, one test user, and one laptop to send test traffic. All steps are GUI — no commands.
اقداماتStepsSteps
Step 1
پہلے اپنی ٹیسٹ لوکیشن بنائیں۔ لوکیشن کے بغیر ZIA کو معلوم نہیں ہوتا کہ ٹریفک کہاں سے آ رہا ہے۔ IP رینجز درج کریں اور GRE ٹنل فعال کریں۔Pehle apni test location banayen. Location ke baghair ZIA ko maloom nahi hota ke traffic kahan se aa raha hai. IP ranges darj karein aur GRE tunnel fa-aal karein.First create your test location. Without a location, ZIA cannot tell where traffic is coming from. Enter the IP ranges and enable the GRE tunnel.
🖱️ پورٹل میں جائیںPortal mein jayenAdministration > Location Management > Add Location
Step 2
اب URL فلٹرنگ پالیسی بنائیں۔ خطرناک کیٹیگریز جیسے مالویئر اور فشنگ کو Block کریں، اور سوشل میڈیا کو صرف دفتر کے اوقات میں Allow کریں۔Ab URL filtering policy banayen. Khatarnak categories jaise malware aur phishing ko Block karein, aur social media ko sirf daftar ke auqaat mein Allow karein.Now build the URL Filtering policy. Block risky categories like Malware and Phishing, and allow Social Media only during office hours.
🖱️ پورٹل میں جائیںPortal mein jayenPolicy > URL Filtering > Add URL Filtering Rule
Step 3
SSL انسپیکشن فعال کریں تاکہ خفیہ (HTTPS) ٹریفک بھی اسکین ہو سکے۔ یاد رکھیں: اینڈپوائنٹس پر Zscaler کا روٹ سرٹیفکیٹ انسٹال ہونا ضروری ہے، ورنہ صارفین کو سرٹیفکیٹ کی خرابیاں نظر آئیں گی۔SSL inspection fa-aal karein taake khufia (HTTPS) traffic bhi scan ho sake. Yaad rakhen: endpoints par Zscaler ka root certificate install hona zaroori hai, warna users ko certificate ki kharabiyan nazar ayengi.Enable SSL inspection so encrypted (HTTPS) traffic can be scanned too. Remember: the Zscaler root certificate must be installed on endpoints, otherwise users will see certificate errors.
🖱️ پورٹل میں جائیںPortal mein jayenPolicy > SSL Inspection > Add SSL Inspection Rule
Step 4
DLP پالیسی بنائیں۔ ایک DLP انجن میں کریڈٹ کارڈ نمبروں کی ڈکشنری شامل کریں، پھر ایک رول بنائیں جو ایسی حساس معلومات کی اپ لوڈ کو Block کرے۔DLP policy banayen. Ek DLP engine mein credit card numbers ki dictionary shaamil karein, phir ek rule banayen jo aisi hassas maloomat ki upload ko Block kare.Create the DLP policy. Add a credit-card-number dictionary to a DLP engine, then create a rule that blocks uploads containing such sensitive data.
🖱️ پورٹل میں جائیںPortal mein jayenPolicy > Data Loss Prevention > Add DLP Engine, then Add DLP Rule
Step 5
تھریٹ پروٹیکشن آن کریں: Advanced Threat Protection میں اینٹی وائرس، اینٹی اسپائی ویئر اور IPS فعال کریں، اور Cloud Sandbox میں نامعلوم فائلوں کے لیے Quarantine منتخب کریں۔Threat protection on karein: Advanced Threat Protection mein antivirus, anti-spyware aur IPS fa-aal karein, aur Cloud Sandbox mein namaloom files ke liye Quarantine muntakhib karein.Turn on threat protection: enable antivirus, anti-spyware and IPS under Advanced Threat Protection, and select Quarantine for unknown files in Cloud Sandbox.
🖱️ پورٹل میں جائیںPortal mein jayenPolicy > Advanced Threat Protection, then Policy > Cloud Sandbox
Step 6
اب اپنی تبدیلیاں فعال (Activate) کریں۔ ZIA میں پالیسیاں محفوظ کرنے کے بعد الگ سے Activate کرنا پڑتا ہے، ورنہ وہ کلاؤڈ پر نافذ نہیں ہوتیں۔Ab apni tabdeeliyan activate karein. ZIA mein policies save karne ke baad alag se Activate karna parta hai, warna woh cloud par nafiz nahi hotin.Now activate your changes. In ZIA, policies must be activated separately after saving, otherwise they are never enforced in the cloud.
🖱️ پورٹل میں جائیںPortal mein jayenAdministration > Activation > Activate
Step 7
ٹیسٹ ٹریفک بھیجیں: ایک بلاک شدہ کیٹیگری کی سائٹ کھولیں اور ایک نارمل سائٹ کھولیں۔ پھر Web Insights میں چیک کریں کہ بلاک اور الاؤ دونوں لاگز صحیح رول دکھا رہے ہیں۔Test traffic bhejen: ek blocked category ki site kholen aur ek normal site kholen. Phir Web Insights mein check karein ke block aur allow dono logs sahi rule dikha rahe hain.Send test traffic: open a site from a blocked category and one normal site. Then check Web Insights to confirm the block and allow logs show the correct rules.
🖱️ پورٹل میں جائیںPortal mein jayenAnalytics > Web Insights
تصدیقVerifyVerify
Web Insights میں ٹیسٹ ٹریفک کے لاگز دیکھیں — بلاک شدہ سائٹ پر آپ کی URL فلٹرنگ رول نظر آنی چاہیے، اور نارمل سائٹ الاؤ ہونی چاہیے۔ پھر Policy > URL Filtering میں رول کے ہٹ کاؤنٹر چیک کریں۔Web Insights mein test traffic ke logs dekhen — blocked site par aap ki URL filtering rule nazar aani chahiye, aur normal site allow honi chahiye. Phir Policy > URL Filtering mein rule ke hit counter check karein.Check the test traffic logs in Web Insights — the blocked site should show your URL Filtering rule, and the normal site should be allowed. Then check the rule hit counters under Policy > URL Filtering.
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ پالیسی بنائی مگر ٹریفک پر اثر نہیں ہو رہا۔Policy banayi magar traffic par asar nahi ho raha.Policy created but traffic is unaffected.
✅ Administration > Activation میں جا کر Activate دبائیں۔ بغیر ایکٹیویشن کے پالیسی نافذ نہیں ہوتی — یہ سب سے عام غلطی ہے۔Administration > Activation mein ja kar Activate dabayen. Baghair activation ke policy nafiz nahi hoti — yeh sab se aam ghalti hai.Go to Administration > Activation and press Activate. Policies are not enforced without activation — this is the most common mistake.
⚠️ SSL انسپیکشن آن کرنے کے بعد ویب سائٹس سرٹیفکیٹ ایرر دکھا رہی ہیں۔SSL inspection on karne ke baad websites certificate error dikha rahi hain.Websites show certificate errors after enabling SSL inspection.
✅ اینڈپوائنٹ ڈیوائسز پر Zscaler کا روٹ CA سرٹیفکیٹ انسٹال کریں۔ یہ سرٹیفکیٹ غائب ہو تو براؤزر ZIA کو درمیان والا (man-in-the-middle) سمجھتا ہے۔Endpoint devices par Zscaler ka root CA certificate install karein. Yeh certificate ghaib ho to browser ZIA ko darmiyan wala (man-in-the-middle) samajhta hai.Install the Zscaler root CA certificate on the endpoint devices. Without it, browsers treat ZIA as a man-in-the-middle.
⚠️ ایک جائز کاروباری سائٹ غلطی سے بلاک ہو رہی ہے۔Ek jaiz karobari site ghalti se block ho rahi hai.A legitimate business site is being blocked by mistake.
✅ Web Insights میں اس سائٹ کا لاگ دیکھیں کہ کون سی رول ہٹ ہوئی، پھر اس کیٹیگری چیک کریں یا اس URL کے لیے اوپر ایک Allow والی استثنائی رول بنائیں۔ رول کی ترتیب (order) اوپر سے نیچے چلتی ہے۔Web Insights mein is site ka log dekhen ke kaun si rule hit hui, phir us category ko check karein ya is URL ke liye upar ek Allow wali istisnai rule banayen. Rule ki tarteeb (order) upar se neeche chalti hai.Check the site's log in Web Insights to see which rule hit, review that category, or add an Allow exception rule above it for that URL. Rule order runs top to bottom.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ SSL انسپیکشن کیوں ضروری ہے؟ (پریکٹس)SSL inspection kyun zaroori hai? (practice)Why is SSL inspection needed? (practice)
آج کل زیادہ تر ٹریفک HTTPS میں خفیہ ہوتا ہے۔ بغیر SSL انسپیکشن کے ZIA خفیہ ٹریفک کے اندر چھپے مالویئر یا ڈیٹا چوری کو دیکھ ہی نہیں سکتا۔Aaj kal zyada tar traffic HTTPS mein khufia hota hai. Baghair SSL inspection ke ZIA khufia traffic ke andar chhupe malware ya data chori ko dekh hi nahi sakta.Most traffic today is encrypted in HTTPS. Without SSL inspection, ZIA simply cannot see malware or data theft hidden inside encrypted traffic.
❓ پالیسی بنانے کے بعد Activate کیوں کرنا پڑتا ہے؟ (پریکٹس)Policy banane ke baad Activate kyun karna parta hai? (practice)Why must you Activate after creating a policy? (practice)
ZIA میں Save کرنے سے پالیسی صرف ڈرافٹ میں محفوظ ہوتی ہے۔ Activate کرنے پر ہی وہ Zscaler کلاؤڈ پر نافذ ہوتی ہے اور ٹریفک پر لگتی ہے۔ZIA mein Save karne se policy sirf draft mein mehfooz hoti hai. Activate karne par hi woh Zscaler cloud par nafiz hoti hai aur traffic par lagti hai.In ZIA, saving only stores the policy as a draft. It is enforced in the Zscaler cloud and applied to traffic only after you Activate.