305 lines
16 KiB
HTML
305 lines
16 KiB
HTML
<!DOCTYPE html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="UTF-8" />
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
|
<title>ByteGeist Windows Server / AD Homelab — Keith Casko</title>
|
|
<meta name="description" content="A verified Windows Server 2022 Active Directory homelab: DC01 with AD DS and DNS, FILE01 with role-based SMB share access, a Windows 11 domain client, and an OPNsense routing/segmentation lab. Audited with PowerShell and WinRM." />
|
|
<link rel="stylesheet" href="css/styles.css" />
|
|
</head>
|
|
<body class="homelab-page">
|
|
|
|
<header class="site-header" role="banner">
|
|
<div class="container">
|
|
<div class="brand">
|
|
<a class="brand-home" href="index.html#home" aria-label="Keith Casko home">
|
|
<span class="name">Keith Casko</span>
|
|
<span class="tagline">
|
|
IT Support | Systems Administration | Cloud Operations
|
|
<span class="location">Kalamazoo, MI</span>
|
|
</span>
|
|
</a>
|
|
</div>
|
|
<button class="nav-toggle" aria-expanded="false" aria-controls="primary-nav">Menu</button>
|
|
<nav class="site-nav" id="primary-nav" aria-label="Primary">
|
|
<ul>
|
|
<li><a href="index.html#projects" class="active">Projects</a></li>
|
|
<li><a href="index.html#skills">Skills</a></li>
|
|
<li><a href="index.html#credentials">Credentials</a></li>
|
|
<li><a href="index.html#about">About</a></li>
|
|
<li><a href="index.html#contact">Contact</a></li>
|
|
<li><a class="nav-resume" href="assets/resume/Keith_Casko_IT_Cloud_Resume.pdf" download>Resume</a></li>
|
|
</ul>
|
|
</nav>
|
|
</div>
|
|
</header>
|
|
|
|
<main>
|
|
|
|
<section class="hero" id="top" aria-labelledby="lab-title">
|
|
<div class="container">
|
|
<div class="lab-hero">
|
|
<div class="lab-hero-text">
|
|
<p class="eyebrow"><a href="index.html#projects">← Projects</a></p>
|
|
<h1 id="lab-title">ByteGeist Windows Server / AD Homelab</h1>
|
|
<p class="lede">
|
|
A multi-VM Windows Server 2022 Active Directory environment I run on
|
|
VMware Workstation Pro to practice day-to-day Help Desk and Junior
|
|
SysAdmin work: domain services, DNS, OU and group design, SMB file
|
|
sharing with role-based access, PowerShell troubleshooting, and the
|
|
kind of break/fix that shows up in interview questions.
|
|
</p>
|
|
<p>
|
|
The topology, command output, and configuration details on this page
|
|
reflect the lab state verified on <strong>2026-10-03</strong>.
|
|
</p>
|
|
<div class="lab-tags">
|
|
<span>Windows Server 2022</span>
|
|
<span>Active Directory DS</span>
|
|
<span>DNS</span>
|
|
<span>SMB & NTFS</span>
|
|
<span>PowerShell / WinRM</span>
|
|
<span>VMware Workstation</span>
|
|
<span>OPNsense</span>
|
|
</div>
|
|
</div>
|
|
<figure class="lab-hero-figure">
|
|
<img src="assets/images/homelab-topology.svg"
|
|
alt="Topology diagram: DC01 (192.168.31.10) and FILE01 (192.168.31.20) on VMnet8/NAT, OPNsense between VMnet8 and VMnet2, WIN11-01 domain-joined client" />
|
|
<figcaption>Verified topology — generated from <code>ipconfig</code>, <code>Get-ADDomain</code>, <code>Get-SmbShare</code>, and VMware <code>vmnetdhcp.conf</code>.</figcaption>
|
|
</figure>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
<section id="systems" aria-labelledby="systems-title">
|
|
<div class="container">
|
|
<div class="section-head">
|
|
<h2 id="systems-title">Systems</h2>
|
|
<span class="subtitle">Four VMs, verified from <code>vmrun</code> and in-guest audits</span>
|
|
</div>
|
|
<div class="lab-table-wrap">
|
|
<table class="lab-table">
|
|
<thead>
|
|
<tr><th>System</th><th>Operating System</th><th>Role</th><th>Address</th><th>Purpose</th></tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr><td><strong>DC01</strong></td><td>Windows Server 2022 Standard</td><td>Domain Controller</td><td>192.168.31.10</td><td>AD DS, DNS, PDC Emulator, Schema & Domain Naming Master, Global Catalog</td></tr>
|
|
<tr><td><strong>FILE01</strong></td><td>Windows Server 2022 Standard</td><td>Member server</td><td>192.168.31.20</td><td>SMB file services; <code>IT</code> departmental share</td></tr>
|
|
<tr><td><strong>WIN11-01</strong></td><td>Windows 11 Education</td><td>Domain client</td><td>192.168.31.x (NAT)</td><td>Domain-joined workstation</td></tr>
|
|
<tr><td><strong>OPNSENSE</strong></td><td>OPNsense (FreeBSD)</td><td>Firewall / router</td><td>VMnet8 ↔ VMnet2</td><td>Segmentation lab; VMnet2 client placement is planned, while current systems remain on VMnet8</td></tr>
|
|
</tbody>
|
|
</table>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
<section id="ad" aria-labelledby="ad-title">
|
|
<div class="container">
|
|
<div class="section-head">
|
|
<h2 id="ad-title">Active Directory & DNS</h2>
|
|
<span class="subtitle">Captured from <code>Get-ADDomain</code> / <code>Get-ADForest</code> on DC01</span>
|
|
</div>
|
|
<div class="lab-grid-2">
|
|
<div class="lab-panel">
|
|
<h3>Forest & Domain</h3>
|
|
<ul class="kv">
|
|
<li><span>Forest / Domain</span><code>ad.bytegeist.lab</code></li>
|
|
<li><span>NetBIOS</span><code>BGLAB</code></li>
|
|
<li><span>Forest mode</span><code>Windows2016Forest</code></li>
|
|
<li><span>Domain mode</span><code>Windows2016Domain</code></li>
|
|
<li><span>FSMO roles</span>all held by <code>DC01</code></li>
|
|
<li><span>Global Catalog</span><code>DC01</code></li>
|
|
<li><span>DNS zones</span><code>ad.bytegeist.lab</code>, <code>_msdcs.ad.bytegeist.lab</code>, 3 reverse</li>
|
|
<li><span>PDC time source</span><code>time.windows.com</code> (fixed from <code>Local CMOS</code>)</li>
|
|
</ul>
|
|
</div>
|
|
<div class="lab-panel">
|
|
<h3>Organizational Units</h3>
|
|
<pre class="lab-tree">ad.bytegeist.lab/
|
|
├── ByteGeist/
|
|
│ ├── Groups
|
|
│ ├── Servers
|
|
│ ├── Workstations
|
|
│ └── Users/
|
|
│ ├── HR
|
|
│ ├── IT
|
|
│ └── Sales
|
|
└── Domain Controllers</pre>
|
|
<h3 class="h3-sub">Lab-created groups</h3>
|
|
<p class="mono-list">
|
|
Accounting · Help Desk · HR Employees ·
|
|
IT Employees · Management · Sales Employees ·
|
|
VPN Users
|
|
</p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
<section id="files" aria-labelledby="files-title">
|
|
<div class="container">
|
|
<div class="section-head">
|
|
<h2 id="files-title">File services & permissions</h2>
|
|
<span class="subtitle">FILE01 — <code>Get-SmbShareAccess</code> and <code>Get-Acl</code></span>
|
|
</div>
|
|
<p>
|
|
FILE01 publishes one departmental share and uses the <code>IT Employees</code>
|
|
security group to grant access — accounts never get rights directly on
|
|
resources, groups do. The share-level cap is <strong>Change</strong>; NTFS
|
|
grants <strong>Modify</strong> explicitly to <code>BGLAB\IT Employees</code>.
|
|
</p>
|
|
|
|
<div class="lab-grid-2">
|
|
<div class="lab-panel">
|
|
<h3>Share <code>IT</code> at <code>C:\Shares\IT</code></h3>
|
|
<h4>Share-level ACL</h4>
|
|
<table class="lab-table lab-table-sm">
|
|
<thead><tr><th>Account</th><th>Type</th><th>Right</th></tr></thead>
|
|
<tbody>
|
|
<tr><td><code>BGLAB\Domain Admins</code></td><td>Allow</td><td>Full</td></tr>
|
|
<tr><td><code>BGLAB\IT Employees</code></td><td>Allow</td><td>Change</td></tr>
|
|
</tbody>
|
|
</table>
|
|
<h4>NTFS ACL</h4>
|
|
<table class="lab-table lab-table-sm">
|
|
<thead><tr><th>Identity</th><th>Rights</th><th>Inherited</th></tr></thead>
|
|
<tbody>
|
|
<tr><td><code>BGLAB\IT Employees</code></td><td>Modify, Synchronize</td><td>No (explicit)</td></tr>
|
|
<tr><td><code>NT AUTHORITY\SYSTEM</code></td><td>FullControl</td><td>Yes</td></tr>
|
|
<tr><td><code>BUILTIN\Administrators</code></td><td>FullControl</td><td>Yes</td></tr>
|
|
<tr><td><code>BUILTIN\Users</code></td><td>ReadAndExecute + CreateFiles + AppendData</td><td>Yes</td></tr>
|
|
<tr><td><code>CREATOR OWNER</code></td><td>Full on child objects</td><td>Yes</td></tr>
|
|
</tbody>
|
|
</table>
|
|
<p><strong>Hardening note:</strong> the inherited <code>BUILTIN\Users</code> entry is broader than the intended IT-only access model. The next ACL change is to disable inheritance and retain only the required administrative and IT group permissions.</p>
|
|
</div>
|
|
<div class="lab-panel">
|
|
<h3>How it was verified</h3>
|
|
<pre class="lab-code">PS> Invoke-Command FILE01 {
|
|
Get-SmbShare |
|
|
Where-Object Name -NotIn 'ADMIN$','C$','IPC$' |
|
|
Get-SmbShareAccess
|
|
(Get-Acl C:\Shares\IT).Access
|
|
}</pre>
|
|
<p>
|
|
Run from DC01 as a Domain Admin via WinRM, output captured to a transcript
|
|
on the host (not inside the VM) so no sensitive data lives on a shared
|
|
share.
|
|
</p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
<section id="validation" aria-labelledby="validation-title">
|
|
<div class="container">
|
|
<div class="section-head">
|
|
<h2 id="validation-title">Validation & fixes applied</h2>
|
|
<span class="subtitle">Real problems found & resolved during the audit</span>
|
|
</div>
|
|
<div class="lab-grid-2">
|
|
<div class="lab-panel">
|
|
<h3>Problem: PDC was using the local CMOS clock</h3>
|
|
<p>
|
|
The PDC Emulator is the authoritative time source for a Windows forest.
|
|
If it drifts, Kerberos tickets outside the 5-minute skew window fail —
|
|
a classic "I can't log in" root cause. <code>w32tm /query /source</code>
|
|
returned <code>Local CMOS Clock</code>.
|
|
</p>
|
|
<pre class="lab-code">w32tm /config /manualpeerlist:"time.windows.com,0x9 pool.ntp.org,0x9 time.nist.gov,0x9" `
|
|
/syncfromflags:manual /reliable:yes /update
|
|
Restart-Service W32Time
|
|
w32tm /resync /rediscover</pre>
|
|
<p class="status-ok">Verified: <code>Source: time.windows.com,0x9</code>, Stratum 5.</p>
|
|
</div>
|
|
<div class="lab-panel">
|
|
<h3>Problem: stale <code>dcdiag</code> SystemLog failure</h3>
|
|
<p>
|
|
A past unexpected shutdown left an entry that <code>dcdiag</code> flagged on
|
|
every run. I confirmed the stale shutdown event was the source, cleared the
|
|
lab System log, and re-ran <code>dcdiag /q</code>. In a production workflow,
|
|
I would export the log before clearing it to preserve evidence.
|
|
</p>
|
|
<pre class="lab-code"># Production-safe sequence:
|
|
wevtutil epl System C:\Temp\System-before-clear.evtx
|
|
wevtutil cl System
|
|
dcdiag /q</pre>
|
|
<p class="status-ok">Verified: <code>dcdiag /q</code> now silent (clean).</p>
|
|
<h3 class="h3-sub">Client domain restoration (completed)</h3>
|
|
<p>
|
|
WIN11-01's NIC was moved from a bridged physical-LAN adapter to the lab
|
|
NAT network, DNS was pointed at DC01, and the machine account trust was
|
|
repaired. Verified domain authentication and DC discovery:
|
|
</p>
|
|
<pre class="lab-code">PS> Test-ComputerSecureChannel -Verbose
|
|
VERBOSE: The secure channel between the local computer and the domain ad.bytegeist.lab is in good condition.
|
|
True
|
|
PS> nltest /dsgetdc:ad.bytegeist.lab
|
|
DC: \\DC01.ad.bytegeist.lab
|
|
Address: \\192.168.31.10
|
|
Flags: PDC GC DS LDAP KDC TIMESERV ... DNS_DC DNS_DOMAIN DNS_FOREST
|
|
The command completed successfully
|
|
PS> whoami
|
|
bglab\administrator</pre>
|
|
<p class="status-ok">Verified: secure channel healthy, DC01 reachable as PDC / GC / KDC / DNS.</p>
|
|
<p><strong>Security note:</strong> this repair transcript was captured from a built-in
|
|
Administrator maintenance session. A separate named administrative account and
|
|
non-privileged daily workstation sign-in are the preferred next hardening step.</p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
<section id="skills" aria-labelledby="skills-title">
|
|
<div class="container">
|
|
<div class="section-head">
|
|
<h2 id="skills-title">Skills demonstrated</h2>
|
|
<span class="subtitle">Why this project matters for IT roles</span>
|
|
</div>
|
|
<ul class="lab-skill-list">
|
|
<li><strong>Windows Server 2022</strong> — installed, promoted to a DC, operate day-to-day.</li>
|
|
<li><strong>Active Directory</strong> — domain / forest design, OUs, users and groups, FSMO awareness, Global Catalog.</li>
|
|
<li><strong>DNS</strong> — AD-integrated primary zones, reverse zones, understanding why the client's DNS must point at the DC.</li>
|
|
<li><strong>SMB & NTFS</strong> — share creation, share-level vs. NTFS permissions, and role-based access through groups. The current IT folder still inherits <code>BUILTIN\Users</code> permissions; disabling inheritance and applying explicit ACLs is a documented hardening task.</li>
|
|
<li><strong>PowerShell</strong> — <code>Get-AD*</code>, <code>Invoke-Command</code>, <code>Get-SmbShareAccess</code>, <code>Get-Acl</code>, <code>w32tm</code>, <code>Test-ComputerSecureChannel</code>.</li>
|
|
<li><strong>Troubleshooting</strong> — recognizing <em>Local CMOS Clock</em> as a future Kerberos failure; diagnosing a broken secure channel as a bridged-NIC / wrong-DNS fault and restoring it with <code>Test-ComputerSecureChannel -Repair</code>.</li>
|
|
<li><strong>Virtualization & networking</strong> — VMware Workstation Pro, VMnet subnetting, OPNsense placement, bridged vs. NAT NIC implications.</li>
|
|
<li><strong>Honest audit documentation</strong> — problems (PDC time source, bridged client NIC) recorded with the exact fix applied, not hidden.</li>
|
|
</ul>
|
|
</div>
|
|
</section>
|
|
|
|
<section>
|
|
<div class="container">
|
|
<div class="contact-cta">
|
|
<div>
|
|
<h2>Want to see the full audit log?</h2>
|
|
<p>Phases, verified command output, problem-and-fix table, security notes.</p>
|
|
</div>
|
|
<div class="contact-actions">
|
|
<a class="btn btn-primary" href="docs/windows-server-homelab.md">Project write-up</a>
|
|
<a class="btn btn-secondary" href="docs/homelab-audit.md">Full audit log</a>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
</main>
|
|
|
|
<footer class="site-footer" role="contentinfo">
|
|
<div class="container">
|
|
<div>© <span id="year">2026</span> Keith Casko. All rights reserved.</div>
|
|
<ul class="footer-links">
|
|
<li><a href="assets/resume/Keith_Casko_IT_Cloud_Resume.pdf" download>Resume</a></li>
|
|
<li><a href="https://github.com/kcasko" rel="noopener">GitHub</a></li>
|
|
<li><a href="https://www.linkedin.com/in/keith-casko/" rel="noopener">LinkedIn</a></li>
|
|
<li><a href="mailto:keith.casko@gmail.com">Email</a></li>
|
|
</ul>
|
|
</div>
|
|
</footer>
|
|
|
|
<script src="js/main.js" defer></script>
|
|
</body>
|
|
</html>
|