Solved

Need help creating test environment with VMWare Workstation.

Posted on 2009-04-14
20
1,603 Views
Last Modified: 2012-08-13
So I am studying to get my MCSE and am trying to apply some of the concepts I read about. I want to create a test environment using VMWare workstation to create two seperate Active Directory forests and establish a forest trust. I have spent a good two days trying to figure this out and numerous headaches later I have to ask for help.

I have one forest using the custom network adapter VMnet2 and the other forest using VMnet3. My question is...how do I establish a connection between them so I can create a trust? I have tried using a RRAS in a separate VM (it had two NICs, one with an IP address from VMnet2 and the other from VMnet3) but for the life of me I cannot figure it out.

I understand this is not a "just click this button" sort of question. I just need some direction to a good resource or any sort of advice as to what I am doing wrong or if I should just persue a career in the fast food business. ;-)

Thanks in advance for any assistance provided.
0
Comment
Question by:jeabou
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 9
  • 5
  • 5
20 Comments
 
LVL 96

Expert Comment

by:Experienced Member
ID: 24143986
To what end do you need custom VMnet's?  I just pulled up to Virtual Machines. They are both using VMnet8 (NAT) and they both get different IP's and I just connected them together. They are workstation VM's, not Server VM's, but what would you give up by just using VMnet8?
... Thinkpads_User
0
 

Author Comment

by:jeabou
ID: 24144041
I am not sure why I would need custom VMnets...I just did it that way. I assumed that since each DC would need a static IP on it's own subnet that using a custom VMnet would be the best way to do it.
0
 
LVL 96

Expert Comment

by:Experienced Member
ID: 24144084
NAT was meant to be a DHCP server, and once a VM gets an address, it usually keeps it, but you can increase the lease time with the VM Network Editor.

You can also put your host machine behind a small router and used Bridged Networking.

I think (looking at the Network Editor) that you must use one of the two. But I would keep them on the same subnet. You cannot put two SBS machines on the same domain, but I think they can be on the same subnet with different domains.

Introducing different subnets is probably why you are having difficulty. Start with one subnet, make your connection and see if you have any limitations.
... Thinkpads_User

0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:jeabou
ID: 24144091
The environment I want to have will consist of two forests with separate subnets with DNS and DHCP installed for any client VMs I create in the respective forest.
0
 

Author Comment

by:jeabou
ID: 24144113
By the way, I am using Windows Server 2003 Enterprise version....not SBS. I am not familiar with SBS at all.

So....the problem I am running into is because I want to have different subnets for each forest?
0
 
LVL 96

Expert Comment

by:Experienced Member
ID: 24144130
I am not familiar with Enterprise :)   SBS 2003 has Active Directory, but Server 2003 does not appear to have. My clients are small and do not use Enterprise.

Typically, when I have stuff at two different subnets, I connect them with VPN. I don't know if you can do that within VMware. ... Thinkpads_User
0
 
LVL 96

Expert Comment

by:Experienced Member
ID: 24158360
This thread has only been alive for two days. The best answer I have to connect two different subnets is via a VPN connection. Should we allow time for others to provide answers?
... Thinkpads_User
0
 
LVL 8

Assisted Solution

by:aldanch
aldanch earned 500 total points
ID: 24163127
jeabou,

Since you're using VMware Workstation, why not consider using the LAN segments. Create a Team and add your VMs to this team. Add two LAN segments that will represent your two subnets (LAN 1, LAN 2). Assign your VMs according to their LAN segment (VM A to LAN 1, VM B to LAN 2).

If you need to route between the two segments or require Internet access, try using the FreeSCO router VM (runs on a virtual floppy). This will allow you to communicate between the LAN segments. You may also use one of the router/firewall virtual appliances found in the VMware Virtual Appliance market.

Here's a link to the virtual floppy image of FreeSCO: http://www.rtfm-ed.co.uk/?p=101
It also provides instructions to set it up.
0
 
LVL 96

Expert Comment

by:Experienced Member
ID: 24174982
jeabou,

Another and different approach would be to get a small, inexpensive VPN router (LinkSys/Cisco, for example). Put your host machine on the the router and put your first server in Bridged Networking mode (gets an IP from the router). Put your second server in NAT mode or in custom VMnet mode as a NAT device. Now your servers have different subnets and you can connect the second server to the first server using a VPN connection. This will very much emulate the real world scenario you are trying to achieve.  ... Thinkpads_User
0
 

Author Comment

by:jeabou
ID: 24177284
If I use FreeSCO will I need to add the VM of it to both teams? What is the difference between creating a Team for each forest using LAN segements compared to having each forest use the same Custom vmnet adapter for their respective forest?
0
 
LVL 8

Assisted Solution

by:aldanch
aldanch earned 500 total points
ID: 24186376
jeabou,

The difference is that LAN segments gives you options to customize your Bandwidth speed and Packet loss percentage for more accurate simulations, an added bonus when using Teams in Workstation 6.x. The LAN segments aren't assigned to any VMnet, isolating your forest from your other network segments (similar to Host Only, but you get to choose your own subnets instead of settling for VMware's predefined one). In this scenario, you can create your NAT/Firewall routers with FreeSCO and attach them to a VMnet (like NAT or Bridged) to route traffic to your other network subnets or Internet traffic.

If you follow the link to set up your FreeSCO VM, it makes it easy for you to get routing going between your forests.

Your setup should be similar to this:
Network = 10.1.0.0
=============================
Forest A - LAN1 = 10.1.32.0
A-DC1 - LAN1 = 10.1.32.1 (DNS, DHCP), 255.255.255.0 (Subnet Mask), 10.1.32.254 (Gateway)
A-Client1 - LAN1 = 10.1.32.100 (assigned by DHCP)
=============================
Forest B LAN2 = 10.1.64.0 (Subnet 2)
B-DC1 - LAN2 = 10.1.64.1 (DNS, DHCP), 255.255.255.0 (Subnet Mask), 10.1.64.254 (Gateway)
B-Client2 - LAN2 = 10.1.64.100 (assigned by DHCP)
=============================
FreeSCO
LAN1 - 10.1.32.254
LAN2 - 10.1.64.254
VMnet#X (Bridged or NAT) - Your main network or Workstation's NAT network
LAN-Segments.png
LAN-Segments-2.png
0
 

Author Comment

by:jeabou
ID: 24200654
Thank you for the detailed response...I appreciate it!

I will attempt to create the environment you laid out and will let you know how it goes.
0
 

Author Comment

by:jeabou
ID: 24200679
I do have one question before I begin though....when I create the VM for FreeSCO do I add it to both teams? I am assuming it needs to have three NICs based on your response and in order for it to have LAN1 and LAN2 it will need to be in both teams....am I correct? Or do I just create one team and add all of the VMs to it and assign the NIC per VM accordingly?
0
 
LVL 8

Assisted Solution

by:aldanch
aldanch earned 500 total points
ID: 24200918
jeabou,

Your assumption is partially correct - 3 NICs (LAN1, LAN2, VMnet0 or VMnet1 - NAT) for the FreeSCO VM.

"just create one team and add all of the VMs to it and assign the NIC per VM accordingly" is what you will choose.

0
 
LVL 8

Accepted Solution

by:
aldanch earned 500 total points
ID: 24200924
It should be similar to the previous post. You can choose the IP network of course.

Network = 10.1.0.0
=============================
Forest A - LAN1 = 10.1.32.0
A-DC1 - LAN1 = 10.1.32.1 (DNS, DHCP), 255.255.255.0 (Subnet Mask), 10.1.32.254 (Gateway)
A-Client1 - LAN1 = 10.1.32.100 (assigned by DHCP)
=============================
Forest B LAN2 = 10.1.64.0 (Subnet 2)
B-DC1 - LAN2 = 10.1.64.1 (DNS, DHCP), 255.255.255.0 (Subnet Mask), 10.1.64.254 (Gateway)
B-Client2 - LAN2 = 10.1.64.100 (assigned by DHCP)
=============================
FreeSCO
LAN1 - 10.1.32.254
LAN2 - 10.1.64.254
VMnet#X (Bridged or NAT) - Your main network or VMware Workstation's NAT network
0
 

Author Comment

by:jeabou
ID: 24232566
OK, well I have the environment setup but am having trouble using FreeSCO. I am choosing an ethernet router during the setup. Why does eth0 have a field for a gateway address but the other eth adapters do not?

I can ping the IP that FreeSCO is using on each LAN.

I just can't get communication between the subnets working.

This is what I have:

Network = 10.10.0.0
=============================
Forest A - LAN1 = 10.10.10.0
A-DC1 - LAN1 = 10.10.10.1 (DNS, DHCP), 255.255.255.0 (Subnet Mask), 10.10.10..254 (Gateway)
A-Client1 - LAN1 = 10.10.10.x (assigned by DHCP)
=============================
Forest B LAN2 = 10.10.20.0 (Subnet 2)
B-DC1 - LAN2 = 10.10.20.1 (DNS, DHCP), 255.255.255.0 (Subnet Mask), 10.10.20.254 (Gateway)
B-Client2 - LAN2 = 10.10.20.x (assigned by DHCP)
=============================
FreeSCO
LAN1 - 10.10.10.254
LAN2 - 10.10.20.254



eth0.jpg
eth1-AM.jpg
0
 

Author Comment

by:jeabou
ID: 24232619
OK, so after looking at my post I figured out that eth0 needs to be connect to the physical network. So I added another NIC to FreeSCO and assigned it to use a bridged connection. I re-configured FreeSCO to the following screenshots. I can now get to the internet from the VMs in each LAN but they still cannot communicate with each other.


ETH0-new.jpg
eth1.jpg
eth2.jpg
0
 

Author Comment

by:jeabou
ID: 24233168
OK, finally got it figured out. Once I realized I could ping by IP address but not by name from each LAN I knew it had to do with name resolution. So, in each forest I configured DNS forwarding and that did it. Thanks for the help!
0
 
LVL 8

Expert Comment

by:aldanch
ID: 24243543
You're welcome! Glad that you were able to hammer in the final nail in the coffin for your Team setup.
0

Featured Post

[Webinar] Learn How Hackers Steal Your Credentials

Do You Know How Hackers Steal Your Credentials? Join us and Skyport Systems to learn how hackers steal your credentials and why Active Directory must be secure to stop them. Thursday, July 13, 2017 10:00 A.M. PDT

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When converting a physical machine to a virtual machine using VMware vCenter Converter Standalone or vCenter Converter Enterprise, if an adapter type is not selected during the initial customization the resulting virtual machine may contain an IDE d…
In this step by step tutorial with screenshots, we will show you HOW TO: Enable SSH Remote Access on a VMware vSphere Hypervisor 6.5 (ESXi 6.5). This is important if you need to enable SSH remote access for additional troubleshooting of the ESXi hos…
Teach the user how to delpoy the vCenter Server Appliance and how to configure its network settings Deploy OVF: Open VM console and configure networking:
Teach the user how to rename, unmount, delete and upgrade VMFS datastores. Open vSphere Web Client: Rename VMFS and NFS datastores: Upgrade VMFS-3 volume to VMFS-5: Unmount VMFS datastore: Delete a VMFS datastore:
Suggested Courses

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question