| VLAN | Name | Subnet | Gateway | Purpose |
|---|
| 1 | zrh-default-v1 | 10.1.1.0/24 | 10.1.1.1 | UniFi Devices |
| 10 | zrh-mgmt-v10 | 10.10.10.0/24 | 10.10.10.1 | Management |
| 20 | zrh-san-v20 | 10.20.20.0/24 | - | Storage (isolated) |
| 30 | zrh-srv-v30 | 10.30.30.0/24 | 10.30.30.1 | Servers |
| 40 | zrh-clt-v40 | 10.40.40.0/22 | 10.40.40.1 | Clients |
| 50 | zrh-dmz-v50 | 10.50.50.0/28 | 10.50.50.1 | DMZ |
| 60 | zrh-vpn-v60 | 10.60.60.0/24 | 10.60.60.1 | VPN |
| IP Address | Hostname | Description |
|---|
| 10.10.10.1 | fw-edge-zrh-01 | Gateway |
| 10.10.10.2 | sw-core-zrh-01 | Core Switch |
| 10.10.10.3 | sw-dist-zrh-01 | Distribution Switch |
| 10.10.10.11 | srv-pve-zrh-01 | Proxmox Node 1 |
| 10.10.10.12 | srv-pve-zrh-02 | Proxmox Node 2 |
| 10.10.10.20 | srv-rpi-zrh-01 | Raspberry Pi (QDevice) |
| IP Address | Hostname | Description |
|---|
| 10.20.20.11 | srv-pve-zrh-01 | Proxmox Node 1 (Storage) |
| 10.20.20.12 | srv-pve-zrh-02 | Proxmox Node 2 (Storage) |
Note: No gateway - isolated network for storage traffic. MTU 9000.
| IP Address | Hostname | VM ID | Role |
|---|
| 10.30.30.10 | srv-dc-zrh-01 | 300 | Forest Root DC, DHCP |
| 10.30.30.15 | srv-dcc-zrh-01 | 305 | Child Domain DC |
| IP Address | Hostname | VM ID | Role |
|---|
| 10.30.30.20 | srv-rca-zrh-01 | 310 | Root CA (Offline, WORKGROUP) |
| 10.30.30.21 | srv-ica-zrh-01 | 311 | Issuing CA |
| 10.30.30.22 | srv-pki-zrh-01 | 312 | PKI Web Repository |
| 10.30.30.23 | srv-pki-zrh-02 | 313 | PKI Web Repository |
| IP Address | Hostname | VM ID | Role |
|---|
| 10.30.30.70 | srv-jump-zrh-01 | 370 | Jump Host |
| Range | Purpose |
|---|
| 10.30.30.1-9 | Network/Reserved |
| 10.30.30.10-19 | Domain Controllers |
| 10.30.30.20-29 | PKI Infrastructure |
| 10.30.30.30-39 | File Services |
| 10.30.30.40-49 | Database Servers |
| 10.30.30.50-69 | Application Servers |
| 10.30.30.70-79 | Management |
| 10.30.30.100-200 | DHCP Range |
| 10.30.30.250 | Temporary Setup |
| Setting | Value |
|---|
| Scope Name | zrh-srv-v30 |
| Start Range | 10.30.30.100 |
| End Range | 10.30.30.200 |
| Subnet Mask | 255.255.255.0 |
| Gateway | 10.30.30.1 |
| DNS Servers | 10.30.30.15, 10.30.30.10 |
| DNS Domain | corp.microsoftlab.ch |
| Lease Duration | 8 days |
| Attribute | Value |
|---|
| Network | 10.40.40.0 |
| Subnet Mask | 255.255.252.0 (/22) |
| Usable Range | 10.40.40.1 - 10.40.43.254 |
| Broadcast | 10.40.43.255 |
| Total Hosts | 1022 |
| IP Address | Hostname | VM ID | Description |
|---|
| 10.40.40.10 | clt-admin-zrh-01 | 400 | Admin Workstation (optional) |
| Setting | Value |
|---|
| Scope Name | zrh-clt-v40 |
| Start Range | 10.40.40.100 |
| End Range | 10.40.43.254 |
| Subnet Mask | 255.255.252.0 |
| Gateway | 10.40.40.1 |
| DNS Servers | 10.30.30.15, 10.30.30.10 |
| DNS Domain | corp.microsoftlab.ch |
| Lease Duration | 8 days |
| IP Address | Description |
|---|
| 10.60.60.1 | VPN Gateway (UniFi) |
| 10.60.60.2 | HP Elitebook (Maurice) |
| 10.60.60.3-254 | VPN Client Pool |
| DNS Name | IP Address(es) | Purpose |
|---|
| pki.microsoftlab.ch | 10.30.30.22, 10.30.30.23 | PKI CRL/AIA (Round Robin) |