20412D - Lab Answer Key Module 1 - Implementing Advanced Network Services
20412D - Lab Answer Key Module 1 - Implementing Advanced Network Services
4. On the Scope Name page, in the Name box, type Scope1, and then click Next.
Es
5. On the IPteAddress
do Range page, in the Start IP address box, type 192.168.0.50, and then in the End IP
cu
address box, type m en192.168.0.100.
to
pe
No rte
6. e
In the Subnet smask ne
tán box, a
ensure
ce that 255.255.255.0 is entered, and then click Next.
pe t i l a aJ
rm .9 e su
7. On the Add Exclusions itidand99Delay sA
as @gm page, lfo click Next.
las ail n
co .co so G
8. On the Lease Duration page, click pia Next. m on
ss za
in lez
au Vic
tor en to configure these options now, and then click
9. On the Configure DHCP Options page, select iza Yes, I want tin
ció .
Next. n.
10. On the Router (Default Gateway) page, in the IP address box, type 192.168.0.1, click Add, and then click
Next.
Es
te
11. On the Domain do Name and DNS Servers page, ensure that the parent domain is Adatum.com, and then
cu
me
click Next. nto
pe
No rte
es ne
12. On the WINS Serverstán page, ceclick Next.
pe a ti a
rm la.99 Jesu
iti 9 sA
13. On the Activate Scope dpage, as @ lfoI will activate this scope later, and then click Next.
las click
gm No, ns
ail oG
co .
pia com on
14. On the Completing the New Scope s sWizard page, za click Finish.
in lez
au Vic
tor en
15. Right-click IPv4, and then click New Scope. aci i z tin
ón .
.
16. In the New Scope Wizard, click Next.
17. On the Scope Name page, in the Name box, type Scope2, and then click Next.
Es
te
do
18. On the IP Address Range page, in the Start IP address box, type 192.168.1.50, and then in the End IP
cu
me
n
address box, type 192.168.1.100.
to
pe
No rte
es ne
tán ce
pe atila aJ
e
9
19. In the Subnet mask box, ensure that 255.255.255.0 is entered, and then click Next.
22. On the Configure DHCP Options page, select Yes, I want to configure these options now, and then click
Next. Es
te
do
cu
23. me
On the Router (Default Gateway) page, in the IP address box, type 192.168.1.1, click Add, and then click
nto
Next. p e
No rte
es ne
tán ce
p ati aJ
24. On the Domain Name erm and l a.9DNS eservers page, ensure the parent domain is Adatum.com, and then click
9 s
itid 9@ us A
Next. a sl g lf
as mail onso
co .co Go
pia m nz
25. On the WINS Servers page, click Next. ss ale
in zV
au ice
tor n
26. On the Activate Scope page, click No, I will activate i z ac thistinscope later, and then click Next.
ión .
.
27. On the Completing the New Scope Wizard page, click Finish.
28. Right-click the IPv4 node, and then click New Superscope.
Es
te
do
29. In the New Superscope Wizard, click Next.
cu
me
nto
30. On the Superscope pe
Name
No rte page, in the Name box, type AdatumSuper, and then click Next.
es ne
tán ce
a
pe page, t i aJ
31. On the Select Scopes rm l a .9 selecte Scope1, hold down the Ctrl key, select Scope2, and then click Next.
itid 99@ sus A
as gm lfo
32. On the Completing the New lasSuperscope
a ns Wizard page, click Finish.
co il.co oG
pia m on
ss za
33. In the DHCP console, under IPv4, select in and then lright-click
ez
Superscope Adatum Super, and then click
au Vic
tor en
Activate. i z a t i n
ció .
n.
Task 2: Configure
Es DHCP name protection
te
do
cu
me
nto
1. On LON-DC1, pe
No in the DHCP rte console, expand lon-dc1.adatum.com.
es ne
tán ce
a
pe then ti aJ
2. Right-click IPv4, and rm laclick.99 Properties.
es
us
itid 9
as @gm Alfo
3. In the IPv4 Properties dialog lasbox, click
a ns
co il.co theoDNS Go tab.
pia m nz
ss ale
4. In the Name Protection pane, click Configure. in zV
au ice
tor nti
iza n.
c
5. Select the Enable Name Protection check box,ióand n. then click OK.
6. Click OK again.
Es
te
do
cu
me
Task 3: Configure and nverify
to
pe DHCP failover
No rte
es ne
tán ce
pe atila aJ
e
9
1. On LON-SVR1, in Server Manager, click Tools, and then from the drop-down list, click DHCP. Note that the
server is authorized, but that no scopes are configured.
2. On LON-DC1, in the DHCP console, right-click the IPv4 node, and then click Configure Failover.
4. On the ESpecify
ste the partner server to use for failover page, in the Partner Server box, type 172.16.0.21,
d o
and then clickcNext.
um
en
to
5. On the Create pe
No a new failover rte relationship page, in the Relationship Name box, type Adatum.
es ne
tán ce
pe atLeadi aJ
6. In the Maximum Client rm la.99 Time es field, set the hours to 0, and set the minutes to 15.
us
itid 9
as @gm Alfo
l ns
7. Ensure that the Mode field isasset ail
co to Load
. oG
balance, and that the Load Balance Percentage is set to 50%.
pia com on
ss z ale
8. Select the State Switchover Interval icheck na
uto box. Keep
z V the default value of 60 minutes.
ice
riz nti
ac n.
ión
9. In the Enable Message Authentication Shared Secret . box, type Pa$$w0rd, and then click Next.
11. On LON-SVR1,
Es refresh the IPv4 node, and then note that the IPv4 node is active.
te
do
cu
12. Expand the IPv4mnode,en expand Scope [172.16.0.0] Adatum, click the Address Pool node, and note that the
to
address pool p ert
No is configured. en
es ec
tán a e
pe tilanode,a and
13. Click the Scope Options rm .99 Jesu note that the scope options are configured.
itid 9 s
as @gm Alfo
14. Start 20412D-LON-CL1, andasthen l ail innas so Adatum\Administrator with the password Pa$$w0rd.
co sign .
pia com Go
nz
ss ale
15. On the Start screen, type Control Panel. i n zV
au ice
tor nti
iza n.
ció
16. In the Apps Results box, click Control Panel. n.
17. In Control Panel, click Network and Internet, click Network and Sharing Center, click Change adapter
settings, right-click Ethernet, and then click Properties.
Es
te
18. do Properties dialog box, click Internet Protocol Version 4 (TCP/IPv4), and then click
In the Ethernet cu
me
Properties. nto
pe
No rte
es ne
19. In the Properties tán dialoga box, ceselect the Obtain an IP address automatically radio button, click Obtain DNS
pe tila aJ
r mi
server address automatically, . 9 es
tid 9 9 andusthen click OK.
as @gm Alfo
las ail ns
co box, . click o Close.
20. In the Ethernet Properties dialog pia com Go
nz
ss ale
in zV
21. Hover over the bottom right corner to expose auto the fly-out icemenu, and then click the Search charm.
riz nti
ac n.
ión
22. In the Apps search box, type Cmd, and then press. Enter.
23. In the command prompt window, type ipconfig, and then press Enter. Record your IP address.
Es
24. On LON-DC1, on the taskbar, click the Server Manager icon.
te
do
cu
me
25. In Server Manager, ntclick
o p Tools, and then click Services.
No ert
es en
tán ec
a ea
pe tila Je
9
26. In the Services window, right-click the DHCP Server service, and then click Stop to stop the service.
27. Close the Services window, and close the DHCP console.
28. On LON-CL1, in the command prompt window, type ipconfig /release, and then press Enter.
Es
Task 1: Configure
te DNSSEC
do
cu
me
nto
pe
1. On LON-DC1, No in Server rtManager,
en click Tools, and then in the drop-down list, click DNS.
es ec
tán a ea
pe ti
rm la.9Forward Je
2. Expand LON-DC1, expand itid 99@ susLookup Al
Zones, click Adatum.com, and then right-click Adatum.com.
as g
las mai fonso
co the l. Zone.
3. On the menu, click DNSSEC>Sign pia com Go
nz
ss ale
in zV
4. In the Zone Signing Wizard, click Next. uto a ice
riz nti
ac n.
ión
5. .
On the Signing options page, click Customize zone signing parameters, and then click Next.
6. On the Key Master page, ensure that the Domain Name System (DNS) server LON-DC1 is selected as the
Key Master, and then click Next.
Es
te
do
7. cu
On the Key Signing me Key (KSK) page, click Next.
nto
pe
8. N
On the Key oSigning Key rte(KSK) page, click Add.
es ne
tán ce
pe a tila aJ
9. On the New Key Signing r mi Key . 9 es page, click OK.
tid 9 9 (KSK)us
as @gm Alfo
las ail ns
copage, . oG
10. On the Key Signing Key (KSK) pia coclick m Next. on
ss za
in lez
11. On the Zone Signing Key (ZSK) page, click auto Next. Vice
riz nti
ac n.
ión
12. On the Zone Signing Key (ZSK) page, click Add..
13. On the New Zone Signing Key (ZSK) page, click OK.
18. On the DNS Security Extensions (DNSSEC) page, click Next, and then click Finish.
24. In the right pane, under Create Rules, in the Suffix box, type Adatum.com to apply the rule to the suffix of
the namespace.
Es
te
do
25. Select both the cuEnable DNSSEC in this rule check box and the Require DNS clients to check that the
me
n
name and addresstodata pe has been validated by the DNS server check box, and then click Create.
No rte
es ne
tán ce
26. Close the Group Policy pe a t
Management
i aJ Editor and Group Policy Management Console.
rm l a .9 e
itid 99@ sus A
as g l
las mai fonso
co l.c Go
pia om nz
ss ale
in zV
Task 2: Configure the DNS socket pool auto ice
riz nti
ac n.
ión
.
2. In the Windows
Es PowerShell window, type the following command, and then press Enter:
te
do
cu
me
Get-DNSServer nto p
No ert
es en
tán ec
a ea
pe tila
rm .99 Jesu
This command displaysitidthe current 9 s of the DNS socket pool (on the fourth line in the ServerSetting
size
as @gm Alfo
section). Note that the currents sizel a a ns
co isil.2,500. oG
pia com on
ss za
i n lez
3. Type the following command, and then press au Enter to Vchange
ice the socket pool size to 3,000.
tor nti
iza n.
ció
n.
dnscmd /config /socketpoolsize 3000
4. Esfollowing command, and then press Enter to stop the DNS server:
Type the te
do
cu
me
nto
net stopN dns pe
oe rte
stá ne
ce
np ati aJ
e la e
9
5. Type the following command, and then press Enter to start the DNS server.
6. Type the
Esfollowing command, and then press Enter to confirm the new socket pool size.
te
do
cu
me
n
Get-DnsServer to p
No ert
es en
tán ec
a ea
pe tila
rm .99 Jesu
itid 9 s
as @gm Alfo
las ail ns
co . oG
pia com on
s za
Task 3: Configure DNS cache locking sin a lez
Vic
uto en
riz tin
ac .
ión
.
1. In the Windows PowerShell window, type the following command, and then press Enter.
E
Get-Dnsserver
ste
do
cu
en m
to
This displays the pe percentage value of the DNS cache lock. Note that the current value is 100 percent.
current
No rte
es ne
tán in the
The value displays ce
ServerCache section.
pe a t i a
rm l a .99 Jesu
itid 9@ sA
2. Type the following command, as and lfpress
las mthen Enter:
g on
a so
co il.co Go
pia m nz
ss ale
in zV
Set-DnsServerCache –LockingPercent au 75 ice
tor nti
iza n.
ció
n.
3. Type the following command, and then press Enter to stop the DNS server.
Es
te
do
cu
m
net stop dns ento
pe
No rte
es ne
tán ce
pe a ti a
rm la.99 Jesu
4. Type the following command,itid 9and thens press Enter to start the DNS server:
as @gm Alfo
las ail ns
co . oG
pia com on
ss za
net start dns in lez
au Vic
tor en
iza tin
ció .
n.
5. Type the following command, and then press Enter:
E
Get-DnsServer
ste
do
cu
en m
to
p
No displayserthe
This command ten current percentage value of the DNS cache lock. Note that the new value is 75
es ec
tán ea
pe atila Je
9
percent.
6. Leave the Windows PowerShell window open for the next task.
11. Es then right-click the GlobalNames zone, and then click New Alias (CNAME).
Select and
te
do
cu
12. In the New Resourceme
nto Record dialog box, in the Alias name box, type App1.
pe
No rte
es ne
tán ce
pe atila aJ
e
9
13. In the Fully qualified domain name (FQDN) for target host box, type App1.Contoso.com, and then click
OK.
Es completing this exercise, you will have configured DNSSEC, the DNS socket pool, DNS cache
Results: Afterte
locking, and thedGlobalName
oc
um zone.
en
to
pe
No rte
es ne
tán ce
pe atila. a
Exercise 3: Configuring r mi IPAM 99 Jesu
tid 9 s
as @gm Alfo
las ail ns
co . oG
pia com on
ss za
Task 1: Install the IPAM feature in lez
au Vic
tor en
iza tin
ció .
n.
1. On LON-SVR2, in the Server Manager Dashboard, click Add roles and features.
4. In the Provision IPAM Wizard, on the Before you begin page, click Next.
Es
5. te
On the Configure database page, click Next.
do
cu
me
nto
6. On the Select provisioningpe method page, ensure that the Group Policy Based method is selected. In the
No rte
GPO name prefixes box, typene IPAM, and then click Next.
tán ce
pe atila aJ
e
9
7. On the Confirm the Settings page, click Apply. Provisioning will take a few minutes to complete.
Es
te
1. In the IPAM dOverview
oc pane, click Select or add servers to manage and verify IPAM access. Notice that
um
the IPAM Access eStatus
nto is blocked.
pe
No rte
2. Scroll down toesthe nview,
ec and note the status report, which is that the IPAM server has not yet been
tán Details
a ea
p e t i l a Je
granted permission tormmanage .99 LON-DC1
s via Group Policy.
itid 9@ us A
as gm lfo
las a n
3. On the taskbar, right-click Windows .co so G
co ilPowerShell, and then click Run as Administrator.
pia m on
ss za
in lez
4. At the Windows PowerShell prompt, typeauthe V
tor following iccommand, and then press Enter:
iza en
tin
ció .
n.
Invoke-IpamGpoProvisioning –Domain Adatum.com –GpoPrefixName IPAM –IpamServerFqdn
LON-SVR2.adatum.com –DelegatedGpoUser Administrator
Es
te
do
c
5. When you are uprompted
me to confirm the action, type Y, and then press Enter. The command will take a few
nto
minutes to complete. pe
No rte
es ne
tán ce
6. Close Windows PowerShell.
pe a ti a
rm la.99 Jesu
itid 9 s
as @gm Alfo
7. In Server Manager, in the SERVER las ns
aINVENTORY>IPv4 pane, right-click LON-DC1, and then click Edit
co il.co oG
Server. p ias m o nz
sin ale
au zV
tor ice
8. In the Add or Edit Server dialog box, set theizaManageability nti status to Managed, and then click OK.
ció n.
n.
9. Switch to LON-DC1.
16. In Server Manager, in the IPAM console, right-click LON-DC1, and then click Refresh Server Access Status.
Es
17. In Server tManager,
ed
oc in the IPAM console, right-click LON-SVR1, and then click Refresh Server Access
um
Status. en
to
pe
No rte
es completes,
18. After the refresh ne click the Server Manager console refresh button. It may take up to 10 minutes for
tán ce
ati
the status to change.p erm l a.9 a Jesrepeat both refresh tasks as needed until a green check mark displays
If necessary,
itid 99@ us A
next to LON-DC1 and LON-SVR1 as lfo IPAM Access Status shows Unblocked for both servers.
las mand the
g ns
a
co il.co oG
pia m on
19. In the Server Inventory Page, right-click s s LON-DC1 za and then click Retrieve ALL Server Data. This action will
in lez
au Vic
take a few minutes to complete. tor en
iza tin
ció .
n.
20. In the IPAM Overview pane, right click LON-SVR1, and then click Retrieve ALL Server Data. This action will
take a few minutes to complete.
Es
te
do
cu
m
Task 5: Configure andenverify
to a new DHCP scope with IPAM
pe
No rte
es ne
tán ce
pe a t i aJ
l a .9 es
1. On LON-SVR2, in thermIPAM itid 9navigation
9@ us A pane, under MONITOR AND MANAGE, click DNS and DHCP
as g l
Servers. las mai fonso
co l.c Go
pia om nz
ss ale
2. In the details pane, right-click the instance in of LON-DC1.Adatum.com
zV that contains the DHCP server role,
au ice
tor n
and then click Create DHCP Scope. iza tin
ció .
n.
3. In the Create DHCP Scope dialog box, in the Scope Name box, type TestScope.
12. Right-click Test Scope, and then click Configure DHCP Failover.
Es
te
do
13. In the Configure cu DHCP Failover Relationship dialog box, for the Partner server field, click the Select drop-
me
nto
down arrow, and then pclick
ert lon-svr1.adatum.com.
No en
es ec
tán a ea
pe tila Je
9
14. In the Relationship Name field, type TestFailover.
16. In the Maximum Client Lead Time field, set the hours to zero, and then set the minutes to 15.
Task 6: Configure IP address blocks, record IP addresses, and create DHCP reservations and DNS records
Es
te
do
1. On LON-SVR2, cu in the Server Manager, in the IPAM console tree, click IP Address Blocks.
me
nto
pe
2. In the rightNpane,
o e click the rte Tasks drop-down arrow, and then click Add IP Address Block.
ne
stá ce
np a t i aJ
erm la.9 eBlock
su
3. In the Add or Edit IPv4it Address 99 s A dialog box, provide the following values, and then click OK:
ida @ lfo
sl g m ns
as ail oG
• Network ID: 172.16.0.0 c op .c om
ias on
za
sin lez
• Prefix length: 16 a uto Vic
riz en
ac tin
ión .
• Description: Head Office .
5. Es pane, click the Tasks drop-down arrow, and then click Add IP Address.
In the right
te
do
cu
me
6. In the Add IP Address nto dialog box, under Basic Configurations, provide the following values, and then click
pe
OK: N oe rte
stá ne
ce
np ati aJ
e r la. es
• IP address: 172.16.0.1 mi 9 9 us
tid 9
as @gm Alfo
las a ns
• MAC address: 112233445566 co il.co oG
pia m on
ss za
in lez
• Device type: Routers auto Vic
riz en
ac tin
ión .
• Description: Head Office Router .
7. Click the Tasks drop-down arrow, and then click Add IP Address.
8. Es IP Address dialog box, under Basic Configuration, provide the following values:
In the Addte
do
cu
me
• IP address: 172.16.0.10
nto
pe
No rte
• MAC address: e stá 223344556677ne
ce
np ati aJ
e la e
9
• Device type: Host
9. In the Add IPv4 Address pane, click DHCP Reservation, and then enter the following values:
• Check the Automatically create DNS records for this IP address check box.
11. On LON-DC1, open the DHCP console, expand IPv4, expand Scope (172.16.0.0) Adatum, and then click
Es
te
Reservations.do Ensure that the Webserver reservation for 172.16.0.10 displays.
cu
me
nto
12. Open the DNS console, pe expand Forward Lookup Zones, and then click Adatum.com. Ensure that a host
No rte
e
record displaysstfor Webserver. ne
án ce
pe a t i aJ
rm l a .9 e
itid 99@ sus A
as g l
las mai fonso
co l.c Go
pia om nz
s ale
Task 7: To prepare for the next module sin zV
au ice
tor nti
iza n.
ció
n.
1. On the host computer, start the Hyper-V Manager.
2. In the Virtual Machines list, right-click 20412D-LON-DC1, and then click Revert.
Es
3. te Virtual Machine dialog box, click Revert.
In the Revertdo
cu
me
n
4. Repeat steps 2 andto3 pfor ert 20412D-LON-SVR1, 20412D-LON-SVR2, and 20412D-LON-CL1.
No en
es ec
tán a ea
pe tila
rm .99 Jesu
itid 9 s
as @gm Alfo
Results: After completing this exercise, las ayou ns have installed IPAM and configured IPAM with IPAM-related
will
co il.co oG
GPOs, IP management server discovery, pia managed
m onservers, a new DHCP scope, IP address blocks, IP
ss za
addresses, DHCP reservations, and DNS records. i n lez
au Vic
tor en
iza tin
ció .
n.
Es
te
do
cu
m en
to
pe
No rte
e stá ne
ce
np ati aJ
e la e
9