Functional Gates
The lab is approved only when every gate below is PASS.
G01 - Network foundation
HQ-CHR01answers on required gateway interfaces.H1reaches172.20.100.1.VLAN 20andVLAN 30have expected routing behavior.- NAT and firewall are active with expected counters and no loss of hypervisor management.
G02 - Identity
HQ-DC01is a healthy first domain controller.- Domain DNS resolves internally and forwards externally.
G03 - Addressing
VLAN 30clients receive valid DHCP leases.- Servers on
VLAN 20retain their static configuration.
G04 - Policy
- Baseline GPO reaches both sample clients.
- At least one security setting and one operational setting are confirmed on each client.
G05 - Resource access
- Test users can access approved shares on
HQ-FS01. - Unauthorized access is denied.
G06 - Segmentation
- Guest traffic cannot consume domain resources.
- Client-to-server traffic is limited to approved service flows.
- WAN does not have broad administrative access to the router.
G07 - Internet egress
- Internal clients resolve external names and reach the internet through CHR.
- CHR trial licensing is active so throughput validation is not distorted by the unlicensed cap.
G08 - Recovery point
- A documented restore point exists for CHR and for the Windows server layer before major role changes.
- For
HQ-DC01, the Windows gate requires a dedicated non-system target, successful backup events, and awbadmin get versionsentry that includes System State. - Recovery-point availability does not prove restoration; DSRM, authoritative/non-authoritative restore, and bare-metal recovery require a separate isolated exercise.
G09 - Windows service transport
VLAN 30clients receive leases through DHCP relay.CHRhas explicitinputrules for DHCP relay traffic beforeINPUT - Default Drop.- Workstations can reach the domain controller and file server through explicit CHR rules.
- The final forward drop remains in effect for everything else.
G09a - AD firewall posture
- Managed workstation and hypervisor subnets can reach the domain controller.
- Guest and DMZ subnets are explicitly blocked from domain controller access.
- Transitional broad lab rules are either removed or clearly marked as temporary.
G10 - Golden image integrity
VMID 4000is built onVLAN 110, validated, generalized, and converted to template.QEMU Guest Agentworks through the Proxmox VE 9qm guest cmdflow.- The golden image is not domain joined and retains no manual IPv4 configuration.
G11 - Workstation onboarding path
- Windows 11 clients deployed from the approved image can join the domain before file-service dependency is introduced.
- File services and workstation resource-access validation are tested only after basic join and policy validation already pass.