Tech Journal ‐ Milestone 2 - Peytonvt/SYS-350 GitHub Wiki
Milestone - 2: AD, vCenter, and SSO
Overview:
- Deploy Domain Controller (DC1-Peyton)
- Configure Domain Controller and User
- vCenter Installation
- SSO Integration
VM Configuration Table
Always select 'thin provison' when configuring storage
| VM Config | Domain Controller | vCenter |
|---|---|---|
| CPU | 2 Cores | 4 Cores |
| RAM | 6-8GB | 19GB |
| DISK | 80GB | 480GB |
| OS | WinServer 2019 | VCSA |
Deploying Domain Controller:
Requirements:
Uploaded WinServer 2019 and VCSA ISO's into datastore2-superX
- Create a new VM (dc1-peyton)
- Upload Windows Server 2019 ISO into CD/Rom Drive
- Proceed with Windows Server 2019 Installation
- Do not set the admin password
- Use Sconfig to configure static IP address and gateway
Refer to Domain Controller Network Configuration
- Install VMWare Tools to Domain Controller
- Install SSH and Sysprep the system.
Run the following script on the machine through PowerShell
- Create clean snapshot (Use sconfig to update windows before hand)
Domain Controller Network Configuration:
IP Address: 10.0.17.4
Subnet: 255.255.255.0
Gateway: 10.0.17.2
DNS: 10.0.17.2
Hostname: dc1-peyton
Domain: peyton.local
Domain Controller ADDS/DNS:
- Install ADDS/DNS with Management Tools
- Create forest and promote Domain Controller
- Created named admin user and promote to Domain Admins and Enterprise Admins Group
- Create A Records and PTR Records for
- pf-14
10.0.17.2 - mgmt-01
10.0.17.100 - dc1-peyton
10.0.17.4 - super14
192.168.3.214 - vCenter
10.0.17.3 - Reverse Lookup Zone
0.17.0.10
- pf-14
- Afterwards change your management server to use dc1-peyton as its DNS Server.
vCenter Installation:
This process takes two stages, both stages taking around 20 minutes.
Requirements:
Create DNS records within AD for vCenter and ESXi and ensure your ESXi host is synced to pool.ntp.org. Make sure your Management and ESXi hosts time servers are synced.
- Mount your VCSA ISO to Management (mgmt01)
- Begin the installer
/media/user/VMWare VCSA/vcsa-ui-installer/lin64 - Select small install size, and use 'thin disk', on datastore2-superX
- Configure VCSA root password and Default admin password
- Create default vCenter domain and Admin
- Update vCenter
vCenter Configuration:
- Create a DataCenter in vCenter called SYS-350
- Add superX (super14) as a host to SYS-350 DataCenter
- Licensing - Use Eval License
SSO Integration:
Double check time servers, before proceeding
- Join vCenter to the domain
- Add yourdomain.local SSO provider as default
This is hidden under Administration>Single Sign On>Configuration
- Reboot the vCenter Server for the source to be added (Use MGMT)
- Add yourdomain.local Domain Admins to the vCenter Administrators group
Users & Groups>Groups>Administrators>Add Members>yourdomain.local
Connectivity Testing:
Domain Controller AD Admin Accounts should be able to login to vCenter using yourdomain.local