Lab answer key - Implementing and configuring network infrastructure services in Windows Server
Lab answer key - Implementing and configuring network infrastructure services in Windows Server
Exercise 1:
Lab answer key: Implementing and configuring
Deploying and
configuring
DHCP
network infrastructure services in Windows
Exercise 2: Server
Deploying and
configuring DNS Note: An interactive lab simulation is available that allows you to click through this lab at your own pace. You
may find slight differences between the interactive simulation and the hosted lab, but the core concepts and
ideas being demonstrated are the same.
❕ Note: Perform the next two steps in case you have not already installed Windows Admin Center on SEA-ADM1.
3. In the Windows PowerShell console, enter the following command, and then press Enter to download the
latest version of Windows Admin Center:
Code Copy
4. Enter the following command, and then press Enter to install Windows Admin Center:
Code Copy
❕ Note: Wait until the installation completes. This should take about 2 minutes.
❕ Note: If the link does not work, on SEA-ADM1, open File Explorer, select Downloads folder, in the Downloads folder
select WindowsAdminCenter.msi file and install manually. After the install completes, refresh Microsoft Edge.
❕ Note: If you get NET::ERR_CERT_DATE_INVALID error, select Advanced on the Edge browser page, at the bottom
of page select Continue to sea-adm1-contoso.com (unsafe).
6. If prompted, in the Windows Security dialog box, enter the following credentials, and then select OK:
Username: CONTOSO\Administrator
Password: Pa55w.rd
7. In the All connections pane, select + Add.
8. In the Add or create resources pane, on the Servers tile, select Add.
9. In the Server name text box, enter sea-svr1.contoso.com.
10. Ensure that Use another account for this connection option is selected, enter the following credentials,
and then select Add with credentials:
Username: CONTOSO\Administrator
Password: Pa55w.rd
❕ Note: To perform single sign-on, you would need to set up a Kerberos constrained delegation.
11. On the sea-svr1.contoso.com page, in the Tools list, select Roles & features.
12. In the Roles and features pane, select the DHCP Server checkbox, and then select + Install.
❕ Note: Wait until the notification indicating that the DHCP role is installed. If necessary, select the Notifications icon
to verify the current status.
14. Refresh the Microsoft Edge page back on the sea-svr1.contoso.com page, in the Tools list, select DHCP,
and then, in the details pane, select Install to install the DHCP PowerShell tools.
❕ Note: If the DHCP entry is not available in the Tools list for sea-svr1.contoso.com, refresh the Microsoft Edge
page and try again. Depending on your network performance, it may take upto 5 minutes for the DHCP server to
appear.
15. Wait for a notification that the DHCP PowerShell tools are installed. If necessary, select the Notifications
icon to verify the current status.
1. On SEA-ADM1, switch to Windows Admin Center in the Microsoft Edge window displaying the DHCP
settings on SEA-SVR1.
❕ Note: It might take a few minutes for the DHCP option to appear in the menu. If necessary, refresh the connection
to sea-svr1. If prompted to install the DHCP Powershell tools, select Install.
3. In the Create a new scope pane, specify the following settings, and then select Create.
Protocol: IPv4
Name: ContosoClients
Starting IP address: 10.100.150.50
Ending IP address: 10.100.150.254
DHCP client subnet mask: 255.255.255.0
Router (default gateway): 10.100.150.1
Lease duration for DHCP clients: 4 days
4. On SEA-ADM1, switch to Server Manager, in Server Manager, select Tools, and then select DHCP.
5. In the DHCP window, in the Actions pane, select More Actions, and then select Manage Authorized
Servers.
6. In the Manage Authorized Servers window, select Refresh, ensure that sea-svr1.contoso.com appears in
the list of authorized DHCP servers, and then close the Manage Authorized Servers window.
7. In the DHCP window, in the Actions pane, select More Actions, and then select Add Server.
8. In the Add Server dialog box, select This authorized DHCP server, select sea-svr1.contoso.com, and
then select OK.
9. In the DHCP window, expand sea-svr1 **, expand **IPv4, expand Scope [10.100.150.0] ContosoClients,
and then select Scope Options.
10. In the Actions pane, select More Actions, and then select Configure Options.
11. In the Scope Options dialog box, select the 006 DNS Servers checkbox.
12. In the Server name text box, enter sea-dc1.contoso.com, select Resolve, verify that the name resolves to
172.16.10.10, select Add, and then select OK.
1. On SEA-ADM1, in the DHCP window, select IPv4, in the Actions pane, select More Actions, and then
select Configure Failover.
2. In the Configure Failover window, verify that the Select all checkbox is selected, and then select Next.
3. On the Specify the partner server to use for failover screen, select Add Server.
4. In the Add Server dialog box, select This authorized DHCP server, select sea-dc1.contoso.com, and then
select OK.
5. Back on the Specify the partner server to use for failover screen, ensure that sea-dc1 appears in the
Partner Server drop-down list, and then select Next.
6. On the Create a new failover relationship screen, enter the following information, and then select Next.
4. In the Ethernet Properties dialog box, select Internet Protocol Version 4 (TCP/IPv4), and then select
Properties.
5. In the Internet Protocol Version 4 (TCP/IPv4) Properties dialog box, select Obtain an IP address
automatically, select Obtain DNS server address automatically, and then select OK.
6. Select Close, and then, in the Ethernet Status window, select Details.
7. In the Network Connection Details dialog box, verify that DHCP is enabled, an IP address was obtained,
and that the **sea-svr1 ** DHCP server issued the lease.
8. Select Close to return to the Ethernet Status window.
9. On SEA-ADM1, in the DHCP window, expand the 172.16.10.12 node, expand the IPv4 node, expand the
Scope [172.16.0.0] Contoso node, and then select Address Leases.
10. Verify that there is an entry representing the SEA-ADM1.contoso.com lease.
11. On SEA-ADM1, in the DHCP window, expand the sea-dc1 node, expand the IPv4 node, expand the Scope
[172.16.0.0] Contoso node, and then select Address Leases.
12. Verify that here as well there is an entry representing the SEA-ADM1.contoso.com lease.
13. Select sea-svr1 **, in the Actions pane, select **More Actions, select All tasks, and then select Stop.
14. On SEA-ADM1, switch back to the Ethernet Status window, and then select Disable.
15. Back in the Network and Sharing Center window, select Change adapter settings, select Ethernet, and
then select Enable this network device.
16. Double-click the enabled Ethernet connection to display its status window.
17. In the Ethernet Status window, select Details.
18. In the Network Connection Details dialog box, verify that DHCP is enabled, an IP address was obtained,
and that the SEA-DC1 (172.16.10.10) DHCP server issued the lease.
19. Select Close to return to the Ethernet Status window.
20. In the Ethernet Status window, select Properties.
21. In the Ethernet Properties dialog box, select Internet Protocol Version 4 (TCP/IPv4), and then select
Properties.
22. In the Internet Protocol Version 4 (TCP/IPv4) Properties dialog box, select Use the following IP
address and specify the following settings:
IP address: 172.16.10.11
Subnet mask: 255.255.0.0
Default gateway: 172.16.10.1
23. In the Internet Protocol Version 4 (TCP/IPv4) Properties dialog box, select Use the following DNS
server addresses, set the Preferred DNS server to 172.16.10.10, and then select OK.
❕ Note: Leave the Ethernet Status window open. You will need it later in this lab.
1. On SEA-ADM1, switch back to the Microsoft Edge window displaying the connection to sea-
svr1.contoso.com in Windows Admin Center.
2. In the Tools list, select Roles & features.
3. In the Roles and features pane, select the DNS Server checkbox, and then select + Install.
❕ Note: Wait until the notification indicating that the DNS role is installed. If necessary, select the Notifications icon
to verify the current status.
5. Refresh the Microsoft Edge page, back on the sea-svr1.contoso.com page, in the Tools list, select DNS,
and then on the details pane, select Install to install the DNS PowerShell tools.
❕ Note: If the DNS entry is not available in the Tools list for sea-svr1.contoso.com, refresh the Microsoft Edge page
and try again.
6. Wait until a notification appears indicating that the DNS PowerShell tools are installed. If necessary, select
the Notifications icon to verify the current status.
1. On SEA-ADM1, in Windows Admin Center, in the DNS pane, select Actions and, on the Actions menu,
select + Create a new DNS zone.
2. In the Create a new DNS zone dialog box, specify the following settings, and then select Create:
4. In the Create a new DNS record pane, specify the following settings, and then select Create:
6. In the Windows PowerShell console, enter the following command, and then press Enter to validate that
the new DNS record provides the name resolution:
Code Copy
4. In the IP addresses of the master servers box, enter 172.16.10.10, and then select Enter.
❕ Note: Disregard the message An unknown error occurred in the validation column within the New Conditional
Forwarder dialog box.
5. Select OK.
6. On SEA-ADM1, switch to the Windows PowerShell console.
7. In the Windows PowerShell console, enter the following command, and then press Enter to validate
conditional forwarding:
Code Copy
1. On SEA-ADM1, switch back to the Microsoft Edge window displaying the connection to sea-
svr1.contoso.com in Windows Admin Center.
2. In the Tools list, select PowerShell, and when prompted, sign in as the CONTOSO\Administrator user
with Pa55w.rd as its password.
3. In the Windows PowerShell console, enter the following command, and then press Enter to create a head
office subnet:
Code Copy
4. Enter the following command, and then press Enter to create a zone scope for head office:
Code Copy
5. Enter the following command, and then press Enter to add a new resource record for the head office scope:
Code Copy
6. Enter the following command, and then press Enter to create a new policy that links the head office subnet
and the zone scope:
Code Copy
2. In the Windows PowerShell console, enter ipconfig , and then press Enter to display its current IP
configuration.
❕ Note: Note that the Ethernet adapter has an IP address that is part of the HeadOfficeSubnet configured in the
policy.
3. In the Windows PowerShell console, enter the following command, and then press Enter to test the
resolution of the testapp.treyresearch.net DNS record:
Code Copy
❕ Note: Verify that the name resolves to the IP address 172.30.99.100 that was configured in the HeadOfficePolicy.
9. In the Windows PowerShell console, enter the following command, and then press Enter to test the
resolution of the testapp.treyresearch.net DNS record:
Code Copy
❕ Note: Verify that the name resolves to 172.30.99.234. This is expected, because the IP address of SEA-ADM1 is no
longer within the HeadOfficeSubnet. DNS queries originating from the HeadOfficeSubnet of (172.16.10.0/24)
targeting testapp.treyresearch.net resolve to 172.30.99.100. DNS queries from outside of this subnet
❕ Note: Now change the IP address of SEA-ADM1 back to its original value.
10. Switch back to the Ethernet Status window and select Properties.
11. In the Ethernet Properties dialog box, select Internet Protocol Version 4 (TCP/IPv4), and then select
Properties.
12. In the Internet Protocol Version 4 (TCP/IPv4) Properties dialog box, change the currently assigned IP
address (172.16.11.11) to its original value (172.16.10.11) and select OK.
13. Select Close twice.
14. Close all open windows.