


DRAG DROP





* stub zone
A Stub Zones allows an organization to resolve names to a private namespace or speed up name resolution to a public namespace without the use of Conditional Forwarders or Secondary Zones.
DNS Stub Zones in each domain will be configured to forward request for the other organization name space to a DNS server that is authoritative. All other names needing resolved will use the default name resolution method.
Reference: How to configure a DNS Stub Zone in Windows Server
http://blogs.interfacett.com/how-to-configure-a-dns-stub-zone-in-windows-server
DRAG DROP


Launch the active directory users and computers applet by using domain admin credentials Add the existing users to the replication list and set access level to deny.
On GLA-DC, configure the LON-DC1 account.
Topic 3, Contoso Ltd Case A
Overview
Contoso, Ltd., is a healthcare company in Europe that has 2,000 users. The company is migrating to Windows Server 2012.
The company has two main offices and two branch offices. The main offices are located in Paris and Amsterdam. One of the branch offices is a sales office located in Berlin. The other branch office is a research office located in Brussels.
The offices connect to each other by using a WAN link.
Current Environment
Active Directory
The network contains an Active Directory forest named contoso.com. An Active Directory site exists for each office.
The forest contains a child domain named research.contoso.com.
The functional level of both the domains is Windows Server 2008.
In each site, there are two domain controllers for the contoso.com domain and two domain controllers for the research.contoso.com domain. The domain controllers run Windows Server
2008 R2.
All of the domain controllers are global catalog servers.
The FSMO roles were not moved since the domains were deployed.
Network Infrastructure
All servers run Windows Server 2008 R2.
Each user has a laptop computer that runs Windows 7.
The company has 10 print servers. Each print server contains several shared printers.
The company has 10 file servers that have the following disk configurations:
*A simple volume named C that is the System and Boot volume and is formatted NTFS
*A mounted virtual hard disk (VHD) named DATA that is formatted NTFS
*A simple volume named D that is formatted FAT32
*A simple volume named E that is formatted NTFS
*A Clustered Shared Volume (CSV)
The Paris office contains a server named PA1. The Amsterdam office contains a server named AM1.
Both servers have the following server roles installed:
*DNS Server
*DHCP Server
*Remote Access
The DNS servers are configured to use the DNS servers of the company's Internet Service Provider (ISP) as forwarders.
Users often work remotely. The users access the internal network by using an SSTP-based VPN connection.
Requirements
Planned Changes
The company plans to implement the following changes:
*Create a child domain named sales.contoso.com. Only the domain controllers in sales.contoso.com will host a zone for the sales.contoso.com domain. The domain controllers in sales.contoso.com will run Windows Server 2012. The client computers in sales.contoso.com will use the sales.contoso.com domain controllers as their DNS servers.
*Implement two servers in the Amsterdam office and two servers in the Paris office to replace PA1 and AMI. These new servers will run Windows Server 2012 and will not have shared storage.
*Decommission the research.contoso.com domain. All of the users and the Group Policy objects (GPOs) in research.contoso.com will be migrated to contoso.com.
*Migrate the existing print queues to virtualized instances of Windows Server
2012.
*Migrate the file servers to new servers that run Windows Server 2012.
*Implement RADIUS authentication for VPN connections.
*Deploy Windows Server 2012 to all new servers.
Technical Requirements
The company identifies following technical requirements:
*All changes to Group Policies must be logged.
*Network Access Protection (NAP) policies must be managed centrally.
*Core networking services in each office must be redundant if a server
fails.
*The possibility of IP address conflicts during the DHCP migration must be minimized.
*A central log of the IP address leases and the users associated to those leases must be created.
*All of the client computers must be able to resolve internal names and internet names.
*Administrators in the Paris office need to deploy a series of desktop
restrictions to the entire company by using Group Policy.
*The new sales.contoso.com domain will contain a web application that
will access data from a Microsoft SQL Server located in the contoso.com domain. The web application must use integrated Windows authentication. Users' credentials must be passed from the web applications to the SQL Server.
DRAG DROP


Box 2: L2TP VPN
Box 3: SSTP VPN
Note:
*Direct is supported in Windows 7 and newer so second answer is not correct it should be L2TP VPN.
* DirectAccess, introduced in the Windows 7 and Windows Server 2008 R2 operating systems, allows remote users to securely access enterprise shares, web sites, and applications without connecting to a virtual private network (VPN).
* Both L2TP and IPsec must be supported by both the VPN client and the VPN server. Client support for L2TP is built in to the Windows Vista and Windows XP remote access clients, and VPN server support for L2TP is built in to members of the Windows Server 2008 and Windows Server 2003 family.
* Secure Socket Tunneling Protocol (SSTP) is a form of VPN tunnel that provides a mechanism to transport PPP or L2TP traffic through an SSL 3.0 channel. SSL provides transport-level security with key- negotiation, encryption and traffic integrity checking. The use of SSL over TCP port 443 allows SSTP to pass through virtually all firewalls and proxy servers.
DRAG DROP





Box 1: Server 3 (Network Policy Server)
We use a Network Policy Server, Server3, to configure health policies.
Box 2: Server 1
* Server1 (Domain Controller)
'You can configure NAP clients through Group Policy or local computer policy. This feature is installed automatically on a domain controller running Windows Server 2008 and Windows Server 2008 R2. This feature can be installed on a member server running Windows Server 2008 or Windows Server 2008 R2.
You can use Group Policy to configure NAP settings on NAP clients running Windows Server 2008, Windows Server 2008 R2, Windows Vista, Windows 7, and Windows XP SP3.
Box 3: Server 3 (Network Policy Server)
You configure remediation server groups on the Network Policy Server and reference a particular remediation server group as part of the network policy for non-compliant computers
HOTSPOT



Scenario:
Active Directory
The company plans to use Active Directory to store personal information for employees. Users in the branch offices must not be able to view the confidential data that is stored for other users.
Active Directory Domain Services
The company plans to use the Employee-Number user property to store personal identification numbers.
Reference: Using the Confidentiality Bit to Hide Data in Active Directory
HOTSPOT




Reference: Creating a site to site (S2S) VPN to Azure with RRAS, one physical NIC and a NAT gateway
http://blogs.technet.com/b/diegoviso/archive/2014/10/28/creating-a-site-to-site-s2s-vpn-to-azure- with-rras-and-one-physical-nic.aspx
HOTSPOT




Box 1: DC02
DC02 is in New York site, which does not have a DHCP server, and it is a domain controller (which is required).
Not RAS01 as it is not a domain controller.
Not DC4 or RAS02 as they are located in Chicago, and the Chicago site already has a DHCP server.
Box 2: Host standby.
In Host standby mode only one of the servers actively leases IP addresses.
Not Load-Balanced as in this mode both DHCP servers answer client request, but according to scenario only one DHCP Server in each site must lease IP addresses at a given time.
Box 3: State switchover interval
For automatic state switchover to happen from communication interrupt to partner down state, you need to enable state switchover interval. If you don't do that then you would need to manually transition primary server to partner down mode.
* Scenario:
* All of the DHCP Server server roles must be installed on a domain controller.
* Only one DHCP server in each site must lease IP addresses at any given time.
Reference: DHCP Failover Hot-Standby Mode
https://blogs.technet.microsoft.com/teamdhcp/2012/09/03/dhcp-failover-hot-standby-mode/
Topic 5, Litware, Inc
Overview
Litware, Inc., is a manufacturing company. The company has a main office and two branch offices. The main office is located in Seattle. The branch offices are located in Los Angeles and Boston.
Existing Environment
Active Directory
The network contains an Active Directory forest named litwareinc.com. The forest contains a child domain for each office. The child domains are named boston.litwareinc.com and la.litwareinc.com. An Active Directory site exists for each office.
In each domain, all of the client computer accounts reside in an organizational unit (OU) named AllComputers and all of the user accounts reside in an OU named AllUsers.
All domain controllers run Windows Server 2008 R2 and are configured as DNS servers.
The functional level of the domain and the forest is Windows Server 2008.
Network Infrastructure
The main office has the following servers:
*Five physical Hyper-V hosts that run Windows Server 2012
*Three virtual file servers that run Windows Server 2008 R2
*One physical DHCP server that runs Windows Server 2008 R2
*Ten physical application servers that run Windows Server 2012
*One virtual IP Address Management (IPAM) server that runs Windows Server
2012
*One virtual Windows Server Update Services (WSUS) server that runs Windows Server 2008 R2
*One physical domain controller and two virtual domain controllers that run Windows Server 2008 R2 Each branch office has following servers:
*One virtual file server that runs Windows Server 2008 R2
*Two physical Hyper-V hosts that run Windows Server 2012
*One physical DHCP server that runs Windows Server 2008 R2
*One physical domain controller and two virtual domain controllers that run Windows Server 2008 R2 All of the offices have a high-speed connection to the Internet. The offices connect to each other by using T1 leased lines.
The IPAM server in the main office gathers data from the DNS servers and the DHCP servers in all of the offices.
Requirements
Planned Changes
The company plans to implement the following changes:
*Implement the Active Directory Recycle Bin.
*Implement Network Access Protection (NAP).
*Implement Folder Redirection in the Boston office only.
*Deploy an application named Appl to all of the users in the Boston office only.
*Migrate to IPv6 addressing on all of the servers in the Los Angeles office. Some application servers in the Los Angeles office will have only IPv6 addresses.
Technical Requirements
The company identifies the following technical requirements:
*Minimize the amount of administrative effort whenever possible.
*Ensure that NAP with IPSec enforcement can be configured.
*Rename boston.litwareinc.com domain to bos.litwareinc.com.
*Migrate the DHCP servers from the physical servers to a virtual server that runs Windows Server 2012.
*Ensure that the members of the Operators groups in all three domains can manage the IPAM server from their client computer.
VPN Requirements
You plan to implement a third-party VPN server in each office. The VPN servers will be configured as RADIUS clients. A server that runs Windows Server 2012 will perform RADIUS authentication for all of the VPN connections.
Visualization Requirements
The company identifies the following visualization requirements:
*Virtualize the application servers.
*Ensure that the additional domain controllers for the branch offices can be deployed by using domain controller cloning.
*Automatically distribute the new virtual machines to Hyper-V hosts based on the current resource usage of the Hyper-V hosts.
Server Deployment Requirements
The company identifies the following requirements for the deployment of new servers on the network:
*Deploy the new servers over the network.
*Ensure that all of the server deployments are done by using multicast.
Security Requirements
A new branch office will open in Chicago. The new branch office will have a single read-only domain controller (RODC). Confidential attributes must not be replicated to the Chicago office.









