Skip to content

Functional Gates

The lab is approved only when every gate below is PASS.

G01 - Network foundation

  • HQ-CHR01 answers on required gateway interfaces.
  • H1 reaches 172.20.100.1.
  • VLAN 20 and VLAN 30 have expected routing behavior.
  • NAT and firewall are active with expected counters and no loss of hypervisor management.

G02 - Identity

  • HQ-DC01 is a healthy first domain controller.
  • Domain DNS resolves internally and forwards externally.

G03 - Addressing

  • VLAN 30 clients receive valid DHCP leases.
  • Servers on VLAN 20 retain their static configuration.

G04 - Policy

  • Baseline GPO reaches both sample clients.
  • At least one security setting and one operational setting are confirmed on each client.

G05 - Resource access

  • Test users can access approved shares on HQ-FS01.
  • Unauthorized access is denied.

G06 - Segmentation

  • Guest traffic cannot consume domain resources.
  • Client-to-server traffic is limited to approved service flows.
  • WAN does not have broad administrative access to the router.

G07 - Internet egress

  • Internal clients resolve external names and reach the internet through CHR.
  • CHR trial licensing is active so throughput validation is not distorted by the unlicensed cap.

G08 - Recovery point

  • A documented restore point exists for CHR and for the Windows server layer before major role changes.
  • For HQ-DC01, the Windows gate requires a dedicated non-system target, successful backup events, and a wbadmin get versions entry that includes System State.
  • Recovery-point availability does not prove restoration; DSRM, authoritative/non-authoritative restore, and bare-metal recovery require a separate isolated exercise.

G09 - Windows service transport

  • VLAN 30 clients receive leases through DHCP relay.
  • CHR has explicit input rules for DHCP relay traffic before INPUT - Default Drop.
  • Workstations can reach the domain controller and file server through explicit CHR rules.
  • The final forward drop remains in effect for everything else.

G09a - AD firewall posture

  • Managed workstation and hypervisor subnets can reach the domain controller.
  • Guest and DMZ subnets are explicitly blocked from domain controller access.
  • Transitional broad lab rules are either removed or clearly marked as temporary.

G10 - Golden image integrity

  • VMID 4000 is built on VLAN 110, validated, generalized, and converted to template.
  • QEMU Guest Agent works through the Proxmox VE 9 qm guest cmd flow.
  • The golden image is not domain joined and retains no manual IPv4 configuration.

G11 - Workstation onboarding path

  • Windows 11 clients deployed from the approved image can join the domain before file-service dependency is introduced.
  • File services and workstation resource-access validation are tested only after basic join and policy validation already pass.