Platform and Infrastructure

Appendix A – Configuration Settings for Microsoft Identity and Access Management Series

Published: May 11, 2004 | Updated: June 26, 2006

Introduction

This appendix summarizes the settings that you can use to reproduce the Contoso environment by using Microsoft Virtual PC (VPC) 2004. The following diagram illustrates the test setup.

Figure A.1 The Identity and Access Management Series test environment

Figure A.1 The Identity and Access Management Series test environment
See full-sized image

Note   The test environment does not completely replicate the full Contoso environment in Figure 4.4, because of the number of VPC images that a single host computer can support adequately.

Host Computer

Recreating the Contoso environment with VPC images requires a host computer with very high specifications. The following table lists the settings and hardware requirements for a single host computer that can run the entire test network.

Note   The host should be able to communicate with the Extranet Domain Controller, FFL-CP-DC-01, to run the extranet Web applications installed on that computer.

Table A.1. Host computer setup requirements

SettingValue

Processor

3GHz equivalent or higher, dual core or dual processor recommended

Memory

4GB

Hard Disk

60GB free space, RAID 0 recommended

Operating System

Windows XP Professional with Service Pack 2

Computer Name

IDMTEST

DNS Domain name

n/a

NetBIOS Domain Name

WORKGROUP

IP Address

10.0.0.2/24

Default Gateway

10.0.0.254

Additional Software

Microsoft Virtual PC 2004

Service Pack 1 for Microsoft Virtual PC 2004

VPC Images

To recreate the computers in the Contoso environment, you should build and configure VPC images with the settings in the following tables. After you finish installing the operating system, install Virtual Machine Additions on all images.

Extranet Forest Root Domain Controller

Table A.2. Extranet Forest Root Domain Controller Settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

128MB

Computer Name

FFL-CP-DC-01

DNS Domain name

perimeter.contoso.com

NetBIOS Domain Name

PERIMETER

Install DNS

Yes

IP Address

10.0.0.1/24 (connected to the physical network card)

Default gateway

10.0.0.254

Primary DNS Server

10.0.0.1

Administrative Password

Pa$$w0rd

Install WWW Service

Yes  (use default settings for Application Server component)

Install Tools & Templates

Yes

Additional software

Windows Support Tools

Internal Firewall/Proxy

To simplify the setup, the test environment uses a single firewall that fulfills the functions of the internal firewall and proxy server between the perimeter network and the intranet.

Table A.3. Internal Firewall/Proxy Settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

128MB

Computer Name

FFL-SA-PROXY-01

DNS Domain name

contoso.com

NetBIOS Domain Name

WORKGROUP

Install DNS

No

IP Address

Internal – 192.168.0.254/24 (Local only)

External – 10.0.0.254/24 (connected to the physical network card)

Default gateway

 

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install WWW Service

No

Install Tools & Templates

No

Additional Software

Internet Security and Acceleration Server 2004

Intranet Forest Root Domain Controller

Table A.4. Intranet Forest Root Domain Controller settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

128MB

Computer Name

FFL-CO-DC-01

DNS Domain name

corp.contoso.com

NetBIOS Domain Name

CORP

Install DNS

Yes

IP Address

192.168.0.201/24 (Local only)

Subnet Mask

255.255.255.0

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install WWW Service

No

Install Tools & Templates

No

Additional software

Windows Support Tools

Run Exchange Setup with the FORESTPREP switch

Run Exchange Setup with the DOMAINPREP switch

Intranet Child Domain Controller

Table A.5. Intranet Child Domain Controller settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

128MB

Computer Name

FFL-NA-DC-01

DNS Domain name

na.corp.contoso.com

NetBIOS Domain Name

NA

Install DNS

No

IP Address

192.168.0.202/24 (Local only)

Default gateway

192.168.0.254

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install WWW Service

No

Install Tools & Templates

Yes

Global Catalog Server

Yes

Additional Software

CA Type

Common Name

Distinguished name

Certificate Services

Enterprise Subordinate CA

IssuingCA

DC=na, DC=corp, DC=contoso, DC=com

Obtain certificate from IntermediateCA

Run Exchange Setup with the DOMAINPREP switch

Install Windows Server 2003 Support tools

MIIS Server

Table A.6. MIIS Server settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

256MB

Computer Name

FFL-NA-MIIS-01

DNS Domain name

na.corp.contoso.com

NetBIOS Domain Name

NA

Install DNS

No

IP Address

192.168.0.203/24 (Local only)

Default gateway

192.168.0.254

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install WWW Service

No

Install Tools & Templates

Yes

Additional Software

SQL Server 2000, Enterprise Edition

Windows Authentication

Local System Account
    Per seat for 2 devices

SQL Server 2000 Service Pack 4

MIIS 2003, Enterprise Edition with SP1

Lotus Notes Client 6.5.4

Visual Studio .NET Enterprise Architect 2003

Exchange Server

Table A.7. Exchange Server settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

256MB

Computer Name

FFL-NA-MSG-01

DNS Domain name

na.corp.contoso.com

NetBIOS Domain Name

NA

Install DNS

No

IP Address

192.168.0.204/24 (Local only)

Default gateway

192.168.0.254

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install Tools & Templates

Yes

Install WWW Service

Yes, including SMTP and NNTP services

Additional Software

Exchange Server 2003, default settings

Exchange Server 2003 SP2

Windows Server 2003 Support Tools

Lotus Notes

Table A.8. Lotus Notes settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

128MB

Computer Name

FFL-SA-LOTUS

DNS Domain name

fabrikam.com

NetBIOS Domain Name

WORKGROUP

Install DNS

No

IP Address

192.168.0.205/24 (Local only)

Default gateway

192.168.0.254

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install WWW Service

No

Install Tools & Templates

Yes

Additional Software

Lotus Domino Server 6.5.4

Lotus Notes Client 6.5.4

Notes Installation Settings

Partitioned Server

Installation Locations

Setup Type

Startup Type

First or Additional Server?

Server Name

Organization Name

Organization Certifier Password

Domino Domain Name

Specify an Administrator name and Password

Also save a local copy of the ID file:


No

Default

Domino Messaging Server

Start Domino as a Windows Service

Set up the first server or a stand-alone server

FFL-SA-LOTUS

Fabrikam

Pa$$w0rd

Fabrikam

Last name: Administrator, Pa$$w0rd

Yes

Sun One Directory Server

Table A.9. Sun One Directory Server settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

128MB

Computer Name

FFL-SA-IPLANET

DNS Domain name

fabrikam.com

NetBIOS Domain Name

WORKGROUP

Install DNS

No

IP Address

192.168.0.206/24 (Local only)

Default gateway

192.168.0.254

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install WWW Service

No

Additional Software

Sun One Directory Server

Install Tools & Templates

Yes

Administrative Domain

fabrikam.com

Administrative Password

Pa$$w0rd

Directory Manager Password

Pa$$w0rd

iPlanet Installation Settings

Server or Console Installation

Type of Installation

Installation Directory

Components to Install

Configuration Directory Server

Directory to store data

General Settings




Configuration Directory Server Administrator

Administration Domain

Directory Manager Settings

Administration Port



iPlanet Servers

Typical

Default

Default

This instance will be the configuration directory server

Store data in this directory server

Server Identifier: FFL-SA-IPLANET

Server Port: 389

Suffix: dc=fabrikam, dc=com

Configuration Directory Administrator ID: admin, Password: Pa$$w0rd

fabrikam.com

Directory Manager DN: cn=Directory Manager Password: Pa$$w0rd,

Port 20000

Offline Root CA

Table A.10. Offline Root CA settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

128MB

Computer Name

FFL-SA-CERT-01

DNS Domain name

contoso.com

NetBIOS Domain Name

WORKGROUP

Install DNS

No

IP Address

192.168.0.207/24 (Local only)

Default gateway

 

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install WWW Service

Yes

Install Tools & Templates

No

Additional Software

CA Type

Common Name

Distinguished name

Certificate Services

Stand alone Root CA

RootCA

DC=na, DC=corp, DC=contoso, DC=com

Offline Intermediate CA

Table A.11. Offline Intermediate CA settings

SettingValue

Operating System

Windows Server 2003 with SP1

VPC RAM

128MB

Computer Name

FFL-SA-CERT-02

DNS Domain name

contoso.com

NetBIOS Domain Name

WORKGROUP

Install DNS

No

IP Address

192.168.0.208/24 (Local only)

Default gateway

 

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install WWW Service

Yes

Install Tools & Templates

No

Additional Software

CA Type

Common Name

Distinguished name

Certificate Services

Stand alone Subordinate CA

IntermediateCA

DC=na, DC=corp, DC=contoso, DC=com

Obtain certificate from RootCA

Windows XP Client

Table A.12. Windows XP Client settings

SettingValue

Operating System

Windows XP Professional with SP2

VPC RAM

128MB

Computer Name

FFL-NA-SUN-01

DNS Domain name

na.corp.contoso.com

IP Address

192.168.0.209/24 (Local only)

Default gateway

192.168.0.254

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Install WWW Service

Yes

Install Tools & Templates

No

Additional Software

Microsoft Office Professional 2003

UNIX Client

Sun Solaris is not supported on VPC 2004, so the test environment uses an alternative UNIX distribution that runs on VPC.

Table A.13. UNIX Client settings

SettingValue

Operating System

UNIX Distribution

VPC RAM

128MB

Computer Name

FFL-SA-UNIX-01

DNS Domain name

na.corp.contoso.com

IP Address

192.168.0.220/24 (Local only)

Default gateway

192.168.0.254

Primary DNS Server

192.168.0.201

Administrative Password

Pa$$w0rd

Additional Software

None


**
**