📝 Section Review: SASE & ZIA Setup
اہم نکاتKey TakeawaysKey Takeaways
- SASE نیٹ ورکنگ اور سیکیورٹی کو ایک کلاؤڈ سروس میں ملاتا ہے؛ SSE سیکیورٹی والا حصہ ہے؛ ZIA Zscaler کا Secure Web Gateway ہے۔SASE networking aur security ko ek cloud service mein milata hai; SSE security wala hissa hai; ZIA Zscaler ka Secure Web Gateway hai.SASE merges networking and security into one cloud service; SSE is the security subset; ZIA is Zscaler's Secure Web Gateway.
- ZIA میں کوئی آن پریم باکس نہیں — ٹریفک 150+ عالمی Zscaler PoP میں سے قریب ترین پر جاتا ہے۔ZIA mein koi on-prem box nahi — traffic 150+ global Zscaler PoP mein se qareebi par jata hai.ZIA has no on-prem box — traffic goes to the nearest of 150+ global Zscaler PoPs.
- لوکیشن IP سے ایک ٹریفک ماخذ پہچانتی ہے؛ GRE/IPsec ٹنل اس کا ٹریفک Zscaler پر لے جاتے ہیں۔Location IP se ek traffic source pehchanta hai; GRE/IPsec tunnel is ka traffic Zscaler par le jate hain.A Location identifies a traffic source by IP; GRE/IPsec tunnels carry its traffic to Zscaler.
- GRE انکرپشن کے بغیر تیز ہے؛ IPsec انکرپشن جوڑتا ہے؛ ZCC لیپ ٹاپس/فونز کے لیے صارف ایجنٹ ہے۔GRE encryption ke baghair tez hai; IPsec encryption jorta hai; ZCC laptops/phones ke liye user agent hai.GRE is fast without encryption; IPsec adds encryption; ZCC is the user agent for laptops/phones.
- ہمیشہ دوسرے ڈیٹا سینٹر پر بیک اپ ٹنل شامل کریں اور save کے بعد ٹنل اسٹیٹس چیک کریں۔Hamesha dosre data center par backup tunnel add karein aur save ke baad tunnel status check karein.Always add a backup tunnel to a second data center and check tunnel status after saving.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ SASE کیا ہے، اور ZIA اس میں کہاں فٹ ہوتا ہے؟SASE kya hai, aur ZIA is mein kahan fit hota hai?What is SASE, and where does ZIA fit in it?
SASE = ایک کلاؤڈ سروس میں نیٹ ورکنگ + سیکیورٹی۔ SSE = صرف سیکیورٹی والا حصہ (SWG، CASB، ZTNA)۔ ZIA Zscaler کا SWG ہے۔SASE = ek cloud service mein networking + security. SSE = sirf security wala hissa (SWG, CASB, ZTNA). ZIA Zscaler ka SWG hai.SASE = networking + security in one cloud service. SSE = only the security part (SWG, CASB, ZTNA). ZIA is Zscaler's SWG.
❓ ZIA کا ٹریفک فلو بیان کریں۔ZIA ka traffic flow bayan karein.Describe the ZIA traffic flow.
صارف کا ٹریفک GRE/IPsec ٹنل یا ZCC سے قریب ترین Zscaler PoP جاتا ہے، پالیسی انجن اسے اسکین کرتا ہے (URL، SSL، threats، DLP)، پھر انٹرنیٹ پر نکلتا ہے۔User ka traffic GRE/IPsec tunnel ya ZCC se qareebi Zscaler PoP jata hai, policy engine ise scan karta hai (URL, SSL, threats, DLP), phir internet par nikalta hai.User traffic goes via GRE/IPsec tunnel or ZCC to the nearest Zscaler PoP, the policy engine scans it (URL, SSL, threats, DLP), then it exits to the internet.
❓ لوکیشن کیا ہے، اور بیک اپ ٹنل کیوں شامل کرتے ہیں؟Location kya hai, aur backup tunnel kyun add karte hain?What is a Location, and why add a backup tunnel?
لوکیشن ایک ٹریفک ماخذ متعین کرتی ہے (مثلاً برانچ آفس) جو IP سے پہچانا جاتا ہے؛ GRE ٹنل اس کا ٹریفک Zscaler پر بھیجتی ہے۔ دوسرے ڈیٹا سینٹر پر بیک اپ ٹنل فیل اوور دیتی ہے۔Location ek traffic source define karti hai (masalan branch office) jo IP se pehchana jata hai; GRE tunnel is ka traffic Zscaler par bhejta hai. Dosre data center par backup tunnel failover deta hai.A Location defines a traffic source (e.g. branch office) identified by IP; a GRE tunnel forwards its traffic to Zscaler. A backup tunnel to a second data center gives failover.
❓ ٹنل Down نظر آ رہا ہے۔ پہلے کیا چیک کریں گے؟Tunnel Down nazar aa raha hai. Pehle kya check karein ge?A tunnel shows Down. What do you check first?
VPN کریڈینشل ٹنل کی تصدیق کرتی ہے، اسی لیے صارف نام/PSK، سورس IP، اور Zscaler گیٹ وے تک UDP 4500/500 کی رسائی چیک کریں۔VPN credential tunnel ko authenticate karti hai, isi liye username/PSK, source IP, aur Zscaler gateway tak UDP 4500/500 ki reachability check karein.VPN credentials authenticate the tunnel, so check the username/PSK, source IP, and UDP 4500/500 reachability to Zscaler gateways.