Configuring App Segments & Access Policies
Zscaler Private Access (ZPA) Zscaler portal — demo tenant (GUI)
مقصدObjectiveObjective
اس سبق میں آپ پورٹل میں Application Segment بنائیں گے اور Access Policy rules لکھ کر طے کریں گے کہ کون سے صارفین اس تک پہنچ سکتے ہیں۔Is lesson mein aap portal mein Application Segment banayenge aur Access Policy rules likh kar tay karenge ke kaun se users us tak pahunch sakte hain.In this lesson you will create an Application Segment in the portal and write Access Policy rules to decide which users can reach it.
آسان مثالSimple AnalogySimple Analogy
Application Segment ایسے ہے جیسے مینو کارڈ پر کھانے کا نام لکھنا — یہ طے کرتا ہے کہ کون سا کھانا serve ہو گا۔ Access Policy وہ ویٹر ہے جو صرف اسی مہمان کو serve کرتا ہے جس کا نام لسٹ میں ہو۔Application Segment aise hai jaise menu card par khane ka naam likhna — ye tay karta hai ke kaun sa khana serve hoga. Access Policy woh waiter hai jo sirf usi mehman ko serve karta hai jis ka naam list mein ho.An Application Segment is like writing the dish's name on a menu card — it decides exactly which dish gets served. The Access Policy is the waiter who only serves it to the guest whose name is on the list.
سیٹ اپLab SetupLab Setup
Zscaler پورٹل ڈیمو ٹیننٹ۔ Administration > Application Segments اور Policy > Access Policy کھولیں۔ ایک نمونہ internal app مثال FQDN کے ساتھ publish کی جائے گی۔Zscaler portal demo tenant. Administration > Application Segments aur Policy > Access Policy kholein. Ek sample internal app example FQDN ke saath publish ki jayegi.Zscaler portal demo tenant. Open Administration > Application Segments and Policy > Access Policy. A sample internal app will be published with an example FQDN.
اقداماتStepsSteps
Step 1
پورٹل کھولیں اور Administration > Application Segments پر جائیں، پھر Add Application Segment پر کلک کریں۔ Segment کو واضح نام دیں، جیسے 'HR Portal'۔Portal kholein aur Administration > Application Segments par jayein, phir Add Application Segment par click karein. Segment ko wazeh naam dein, jaise 'HR Portal'.Open the portal and go to Administration > Application Segments, then click Add Application Segment. Give the segment a clear name, e.g. 'HR Portal'.
🖱️ Administration > Application Segments > Add Application SegmentAdministration > Application Segments > Add Application SegmentAdministration > Application Segments > Add Application Segment
Step 2
Domain Names میں ایپ کا FQDN لکھیں (جیسے hr.internal.example.com)۔ TCP Port Ranges میں پورٹ لکھیں (جیسے HTTPS کے لیے 443)۔ FQDN کی جگہ IP ranges بھی دے سکتے ہیں۔Domain Names mein app ka FQDN likhein (jaise hr.internal.example.com). TCP Port Ranges mein port likhein (jaise HTTPS ke liye 443). FQDN ki jagah IP ranges bhi de sakte hain.In Domain Names add the app's FQDN (e.g. hr.internal.example.com). In TCP Port Ranges add the port (e.g. 443 for HTTPS). IP ranges may also be used instead of FQDNs.
🖱️ Administration > Application Segments > Domain Names / TCP Port RangesAdministration > Application Segments > Domain Names / TCP Port RangesAdministration > Application Segments > Domain Names / TCP Port Ranges
Step 3
اس Server Group کو assign کریں جس میں ایپ کے قریبی App Connector ہو۔ Double discovery آن ہو تو ایپ کے پورٹس خود سیکھ لیتے ہیں۔Us Server Group ko assign karein jis mein app ke qareebi App Connector ho. Double discovery on ho to app ke ports khud seekh lete hain.Assign a Server Group that contains the App Connector near the app. Double discovery, if on, learns the app's ports automatically.
Step 4
اب Policy > Access Policy پر جائیں اور rule بنائیں: Action ALLOW, Segment = HR Portal، اور وہ users/groups چنیں (IdP سے) جن کو رسائی دینی ہے۔Ab Policy > Access Policy par jayein aur rule banayein: Action ALLOW, Segment = HR Portal, aur woh users/groups chunein (IdP se) jin ko access dena hai.Now go to Policy > Access Policy and add a rule: Action ALLOW, Segment = HR Portal, and pick the users or groups (from the IdP) who may access it.
🖱️ Policy > Access Policy > Add RulePolicy > Access Policy > Add RulePolicy > Access Policy > Add Rule
Step 5
دوسرا rule بنائیں جو باقی سب کو deny کرے۔ مخصوص allow rules اوپر رکھیں اور general deny نیچے — rule order اہم ہے۔Doosra rule banayein jo baqi sab ko deny kare. Makhsoos allow rules oopar rakhein aur general deny neeche — rule order ahem hai.Add a second rule that denies everyone else. Keep the specific allow rules on top and the general deny at the bottom — rule order matters.
Step 6
Save پر کلک کریں۔ تصدیق کریں کہ segment لسٹ میں ہے اور policy میں دونوں rules صحیح ترتیب میں ہیں، پھر client سے test کریں۔Save par click karein. Confirm karein ke segment list mein hai aur policy mein dono rules sahi order mein hain, phir client se test karein.Click Save. Verify the segment is listed and the policy shows both rules in the right order before testing from the client.
تصدیقVerifyVerify
Client سے ایپ کا FQDN کھولیں — کھلنا چاہیے۔ Group سے باہر کے user سے test کریں — رسائی deny ہونی چاہیے۔Client se app ka FQDN kholein — khulna chahiye. Group se bahar ke user se test karein — access deny hona chahiye.From the client, open the app's FQDN — it should load. Test with a user outside the group — access should be denied.
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ Client سے ایپ نہیں کھل رہی حالانکہ policy صحیح لگ رہی ہے۔Client se app nahi khul rahi halan ke policy sahi lag rahi hai.The app does not open from the client even though the policy looks correct.
✅ چیک کریں کہ Client Connector signed-in ہے اور اس کا ZPA module فعال ہے۔ پھر Administration > App Connectors میں ایپ کے قریب healthy connector دیکھیں۔Check karein ke Client Connector signed-in hai aur us ka ZPA module enabled hai. Phir Administration > App Connectors mein app ke qareeb healthy connector dekhein.Check that the Client Connector is signed in and its ZPA module is enabled. Then check Administration > App Connectors for a healthy connector near the app.
⚠️ Rule match ہی نہیں ہوتا — allowed group کے users بھی deny ہو جاتے ہیں۔Rule match hi nahi hota — allowed group ke users bhi deny ho jate hain.The rule never matches — users get denied even in the allowed group.
✅ Rules اوپر سے نیچے چیک ہوتے ہیں۔ اگر general deny allow rule سے اوپر ہے تو پہلے وہی لگتا ہے — ALLOW rule کو deny سے اوپر لے جائیں۔Rules oopar se neeche check hote hain. Agar general deny allow rule se oopar hai to pehle wahi lagta hai — ALLOW rule ko deny se oopar le jayein.Rules evaluate top to bottom. A broader deny above the allow rule blocks first — move the specific ALLOW rule above any general deny.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Application Segment میں کون سے فیلڈز ضروری ہوتے ہیں؟Application Segment mein kaun se fields zaroori hote hain?What fields must an Application Segment have?
Segment Name, Domain Names (FQDN), TCP/UDP Port Ranges, Server Groups، اور Browser Access فعال ہے یا نہیں۔Segment Name, Domain Names (FQDN), TCP/UDP Port Ranges, Server Groups, aur Browser Access enabled hai ya nahi.Segment Name, Domain Names (FQDN), TCP/UDP Port Ranges, Server Groups, and whether Browser Access is enabled.
❓ Access Policy rules کیسے evaluate ہوتے ہیں؟Access Policy rules kaise evaluate hote hain?How are Access Policy rules evaluated?
Access Policy rules اوپر سے نیچے چیک ہوتے ہیں؛ جو پہلا rule match کرے وہی لگتا ہے، اس لیے سب سے مخصوص rule اوپر رکھیں۔Access Policy rules oopar se neeche check hote hain; jo pehla rule match kare wahi lagta hai, is liye sab se makhsoos rule oopar rakhein.Access Policy rules are evaluated top to bottom; the first matching rule applies, so the most specific rule goes on top.