🛠️Development and Testing Environment
🌐 Network Architecture
This environment is composed of three core network zones, designed to mimic a typical hybrid enterprise setup:
Development VLAN
Functions as a proxy-to-internet zone used to hijack or intercept DNS and service calls as needed. It enables testing of redirect logic, hostname spoofing, or simulating cloud resources and CDN endpoints.Internal Host Transit Network
A dedicated transit layer that links all Opnsense VMs with static routing only, simulating WAN connectivity across isolated customer domains while allowing controlled traffic flows between them.Domain Networks (White, Gray, Black)
Each domain resides in its own internal network segment with no direct internet access. These simulate fully isolated customer environments. All connectivity is routed through the Opnsense perimeter via the transit network.
🏢 Domain Setup: White, Gray, Black
Each domain represents a generation of enterprise environments, with matching OS families across Windows and Linux:
| Domain | OS Generation | Windows Stack | Linux Stack |
|---|---|---|---|
| White | Modern | Server 2022, Windows 11 | RHEL 9, Ubuntu 24 |
| Gray | Prior Gen | Server 2019, Windows 10 | RHEL 8, Ubuntu 22 |
| Black | Legacy | Server 2012 R2, Windows 7 | RHEL 6, Ubuntu 16 |
🧩 Machine Templates Per Domain
Each domain uses a consistent template to represent key enterprise services and endpoints:
Domain Controller
DNS, DHCP, NTP, Certificate Servicesdc01.ad.white.comInfrastructure Node
File Server, DFS, WSUSinfra01.ad.white.comAuthentication Node
ADFS, RADIUS, WEF Collectorauth01.ad.white.comWeb Services Node
IIS + RDS Web Gatewayweb01.adwhite.comWindows Endpoint
Domain-joined Windows desktopendpoint01.ad.white.comLinux Endpoints
RHEL Web Server:
web02.ad.white.comRHEL Desktop:
endpoint02.ad.white.comUbuntu Web Server:
web03.ad.white.comUbuntu Desktop:
endpoint03.ad.white.com
🔧 Features and Testing Capabilities
This environment supports complex enterprise simulation, including:
DNS Forwarding & Hijacking
Forward queries to internal services or simulate external CDN/identity provider endpoints.Cross-Domain Trust & User Delegation
Establish trust relationships for authenticating and authorizing access across multiple AD forests.Multi-OS Compatibility Testing
Validate GPOs, authentication mechanisms, and deployment tools across multiple OS generations.Service Simulation
Simulate production-like behavior for DFS, WSUS, ADFS, RADIUS, Kerberos, NTLM, and modern authentication flows.Security Policy Validation
Test the effect of hardening policies (e.g., disabling NTLM, enforcing Kerberos, firewall scoping) in isolated and mixed-generation domains.
🔍 Use Cases
Troubleshooting real-world client issues in a controlled replica
Cross-version validation of infrastructure tools and scripts
Legacy migration planning (e.g., WS 2012 R2 → WS 2022)
Domain join and trust failure diagnosis
Authentication policy testing (NTLM fallback, Kerberos tickets, RADIUS policies)