Enterprise Infrastructure Lab
Independent Systems Administration Project
Executive Summary
Designed and administer an enterprise-style infrastructure environment featuring Windows Server, Active Directory, Proxmox, DNS, Group Policy, PowerShell, pfSense, and enterprise security monitoring.
Architecture
Cisco Catalyst switching and VLAN segmentation route traffic through a pfSense firewall enforcing inter-VLAN access policy, with DHCP, Pi-hole, and Unbound handling DNS resolution for the segmented network.
Environment
A Dell PowerEdge R720XD running Proxmox VE as the virtualization host, with Cisco Catalyst switching and a pfSense firewall providing VLAN-segmented network infrastructure.
Technology Breakdown
Microsoft
Virtualization & Hardware
Networking
Security & Linux
Implementation
- Designed and administered a virtualized enterprise environment on Dell PowerEdge hardware using Proxmox VE
- Deployed Windows Server 2022 with Active Directory Domain Services and DNS
- Created organizational units, users, security groups, administrative accounts, and domain-joined workstations
- Implemented separation between standard and privileged administrative accounts
- Configured Cisco switching, VLAN segmentation, routing, pfSense firewall services, and DNS infrastructure
- Deployed and evaluated Wazuh and Suricata for endpoint and network security monitoring
- Diagnosed DNS resolution failures, Active Directory health warnings, DFS-R events, and service connectivity issues
- Developed PowerShell tools for system inventory, Defender status, event collection, DNS validation, and network testing
- Documented architecture, configuration decisions, validation procedures, and troubleshooting outcomes
Troubleshooting Highlights
- Restored Active Directory-related name resolution after an upstream DNS resolver interruption
- Investigated DFS-R and domain-controller health warnings using native Windows diagnostic tools
- Validated DNS records, service ports, domain connectivity, and infrastructure health using PowerShell
- Corrected deployment and service issues in Linux-hosted environments using systemd, Nginx, logs, and file validation
Current Roadmap (Planned)
- Deploy a secondary domain controller
- Implement Group Policy security baselines
- Add centralized file services
- Validate backup and recovery procedures
- Expand Wazuh agent coverage and detections
- Improve rack cabling and install structured patch-panel connectivity
- Build automated infrastructure health reporting
Transparency Note
This is an actively developed independent lab used to practice, validate, and document enterprise administration workflows. Planned components are identified separately from completed work.