No video

How to setup an isolated Hyper-V lab with internet access

  Рет қаралды 21,240

Danny Moran

Danny Moran

Күн бұрын

Learn how to setup Hyper-V so that you can use it to create a test lab environment. In this example, I show you how to setup pfSense and virtual switches so that the test lab virtual machines can only communicate with other lab virtual machines but also still reach the internet.
View the blog post with all the commands and step-by-step instructions here: www.dannymoran...
Hi, I’m Danny, a London based IT consultant and sporadic blogger. You can view all my blog posts at: www.dannymoran...

Пікірлер: 86
@IrlymMylros
@IrlymMylros 9 ай бұрын
Danny you have the bad habit of making training videos easy to follow. Thank you and hope you tackle more advanced videos.
@danny_moran
@danny_moran 9 ай бұрын
Thanks for watching!
@lindsaydunlap7220
@lindsaydunlap7220 4 ай бұрын
I have been reading articles on how to do this and struggling for days. This is straight forward and useful, thank you.
@danny_moran
@danny_moran 4 ай бұрын
Thanks for watching!
@MichaelCook-oo8lj
@MichaelCook-oo8lj 10 ай бұрын
This is fantastic. Thanks so much for creating this.
@danny_moran
@danny_moran 10 ай бұрын
Thanks for watching!
@isurindajayawardana5751
@isurindajayawardana5751 7 ай бұрын
Excellent stuff Danny. Thanks
@danny_moran
@danny_moran 7 ай бұрын
Thanks for watching!
@KeysOfClassics
@KeysOfClassics Жыл бұрын
Great guide, Thanks for sharing your knowledge.
@danny_moran
@danny_moran Жыл бұрын
Thanks for watching!
@a.dursun7581
@a.dursun7581 Ай бұрын
Great job done!
@danny_moran
@danny_moran Ай бұрын
Thanks for watching!
@dezz26
@dezz26 11 ай бұрын
Great video, I would like to see a video on using HV Manager which is the web interface to access Hyper-V via a web browser? That would be good to see since not everyone wants to use ESXi or Proxmox to build their lab environments
@danny_moran
@danny_moran 10 ай бұрын
Without integrating to something like WAC or Azure Stack HCI, there are no official web interfaces for Hyper-V. I don't cover anything that is developed by third-parties unless it's something that I personally use. I think it's best to just stick with the Hyper-V Manager and PowerShell to manage Hyper-V. Thanks for watching!
@user-lb6tw7zw8w
@user-lb6tw7zw8w 7 ай бұрын
Awesome explanation Danny, seriously, straight to the point and no BSs in the middle 1 question tho, how do I go about setting up vlans? Do i still assign the same LAN network/switch and enable VLAN ID?
@danny_moran
@danny_moran 7 ай бұрын
I haven't used VLANs for Hyper-V for a while, but, you should still be able to do this under the network adapter settings in the Hyper-V settings for the VM. Thanks for watching!
@mohm7047
@mohm7047 Жыл бұрын
Must say, this is a really good video and thanks for that. I have subscribed your and given a like. BTW, I was thinking couldn't you install pfsense with Gen 2 but disable Secure Boot?
@danny_moran
@danny_moran Жыл бұрын
I've never actually tried using a Gen2 VM for pfSense. If it lets your install it on a Gen2 with Secure Boot disabled, then I can't see it causing any issues. Thanks for watching!
@dmbrv
@dmbrv Жыл бұрын
Awesome video. Thanks
@danny_moran
@danny_moran Жыл бұрын
Thanks for watching!
@ranting8677
@ranting8677 Ай бұрын
Holy damn it works! One question though, if the domain controller VM got infected with virus, it shouldn't be able to infect the main host right? Thanks for the video!
@danny_moran
@danny_moran Ай бұрын
Technically, I think it might be able to. I wouldn't use this to test malware, I would use a dedicated sandbox solution. Thanks for watching!
@williamguru
@williamguru Ай бұрын
So how is it that the DC01 is on lab-switch-lan and can still reach the internet?
@danny_moran
@danny_moran Ай бұрын
The internet traffic goes through the LAN side of the pfSense firewall and then out of the WAN side of the pfSense firewall to reach the internet. Thanks for watching!
@1N0v4.3
@1N0v4.3 6 ай бұрын
Amazing video! Thank you so much. I had a quick question however and was wondering if it was necessary to have your own domain for the DNS/DHCP configuration part of this video?
@danny_moran
@danny_moran 6 ай бұрын
No, you can just use the pfSense for DHCP and DNS. Thanks for watching!
@SharePointMark
@SharePointMark 3 ай бұрын
Hi Danny, excellent videos, in this video towards the end you cover DC, DNS, ADDS, DHCP. I love the list of Windows 2022 server vids, but 96 is a lot to go through - Would it be possible to list the individual videos required for what you are doing at the back of this lab starter video. My aim is simple, I am looking at doing multiple farms to cover ADDS, Exchange and Some other MS apps as part of a wider scale personal learning activity. having the "beginners" guide to the Hyper V FW01 is excellent, but it would help if I new which videos from your list of 95 would be better in the order that is best suited. Can you advise?
@danny_moran
@danny_moran 3 ай бұрын
I agree that the playlist has gotten a bit out of control, and it's something that I need to sort out. I wouldn't really say there is a recommended process to follow, this is just one of the ways I set up my lab when I need to test things. Depending on what you are trying to do and what you are trying to test, the lab would probably be setup differently. With it being a test lab, there isn't really a wrong way to do it. Thanks for watching!
@mummysboy6253
@mummysboy6253 2 ай бұрын
Thank you!
@danny_moran
@danny_moran 2 ай бұрын
Thanks for watching!
@Edmondfreak
@Edmondfreak 3 ай бұрын
hi, is this a suitable setup for malware reversing ?
@danny_moran
@danny_moran 3 ай бұрын
I would look into dedicated sandbox environments for testing malware. Thanks for watching!
@ryzon
@ryzon Жыл бұрын
I'm having trouble doing the same setup but with VLANs. I have setup the dhcp relay in pfsense and have 2 scopes in the dhcp server and setup the vlan in each machine
@danny_moran
@danny_moran Жыл бұрын
I've never set it up using VLANs, unfortunately. Thanks for watching!
@BrianLonsdale
@BrianLonsdale 8 ай бұрын
Could you do a guide on setting up Hyper-V across two hosts so that I can spread the load across multiple PCs? (i.e. PC1 has all my DCs on, PC2 has my other application servers, e.g Exchange), all domain joined. Been trying to find guides on this and haven't found anything that explains it simply enough!
@danny_moran
@danny_moran 8 ай бұрын
I do plan on doing a guide which covers this, however, I don't have the hardware available in my lab at the moment to do this, unfortunately. Thanks for watching!
@andrewenglish3810
@andrewenglish3810 6 ай бұрын
Why not just setup a VLAN on the firewall and set the port which the machine is connected on at the switch? Does Hyper-V not allow you to set the VLAN on each of the VM's?
@danny_moran
@danny_moran 6 ай бұрын
Yes, you can setup VLANs and use that method, if you prefer. Thanks for watching!
@Alayeluwa
@Alayeluwa 7 ай бұрын
Awesome. Thanks
@danny_moran
@danny_moran 7 ай бұрын
Thanks for watching!
@JDWilkerson-Butiu
@JDWilkerson-Butiu 4 ай бұрын
I got a question is this useful if i wanna download viruses and infect my vm because i have a itch to destroy vms with viruses and to have a windows destruction. Also i use virtual box
@danny_moran
@danny_moran 4 ай бұрын
Personally, I would look into the Windows Sandbox for this Guide on how to enable the Windows Sandbox: kzfaq.info/get/bejne/epahrZyKvZvPZ58.html Guide on how to configure the Windows Sandbox: kzfaq.info/get/bejne/pJeTlLt1l72wc2Q.html Thanks for watching!
@RookFett
@RookFett 10 ай бұрын
Great guide - but I seem to have hit a snag. When I turn on the pfsense vm, and tell it to use hn0 for the wan (configured as external on hyperv), it hangs for a few minutes, i see an error message about dhcp client on hn0, and no IP is given. Been pulling my hair out, this should work, but I cant get pass this one point. The virtual adapter is getting a dhcp address for hyperv (laptop). any clue on what I should look at?
@RookFett
@RookFett 10 ай бұрын
This is weird - I took the box home, and it works as expected. Something is going on with my AD DHCP not giving out an IP to the box when pfsense is asking for one. Something to dig into later...
@danny_moran
@danny_moran 10 ай бұрын
Glad you've managed to get it working. Thanks for watching!
@mikoal
@mikoal Жыл бұрын
Thanks it was very informative. I was just wondering couldn't you just assign a static IP or a reserved dhcp IP for the vm, then on the host firewall just block all incoming traffic from that ip?
@danny_moran
@danny_moran Жыл бұрын
I'm not sure I understand the question. Do you mean do this instead of the using the pfSense? You could do that, however, I think using the pfSense would give better results when expanding the lab and it also gives the ability to easily create more subnets and route them to test multi-site setups better, or even test setting up site-to-site vpns if needed. The addition of the pfSense opens up a lot more testing opportunities and I feel it makes the lab more like a production network that would be in use within a business. Thanks for watching!
@mikoal
@mikoal Жыл бұрын
@@danny_moran hey Danny, thanks for the response. Yes, I was wondering for simplicity if doing the firewall+static IP block would yield you the same results in terms of protection and internet access (vm isolated from host+can access the net). I agree that this would be good for expansion of large number of vms, since once its setup you can just keep adding. Would one be more secure/reliable than the other? If the pfsense vm stopped or froze, you'd lose internet to all vms connected to it. Whereas host firewall should be stable. Once again I'm still learning a lot about this and would most likely be applying the pfsense route over the firewall method, but I just wanted to confirm that the firewall would be an acceptable backup plan if I wasn't able to set up the pfsense vm.
@danny_moran
@danny_moran Жыл бұрын
As it's a lab, I wouldn't say one was better than the other. It's just whatever is easier or more convenient for you to setup. I can't think of any reason why the method you are suggesting wouldn't work.
@mikoal
@mikoal Жыл бұрын
@@danny_moran SUBSCRIBED! fascinating stuff. I've been playing around with Pfsense and Hyper-V. Using PFsense as DHCP server I've tried to create 2 private LAN swtiches using your guide and it works I've tried creating 2 internal LAN switches and it also works Ive also tried creating 1 private LAN with multiple vlans underneath the LAN and it works as well May i ask, what are the differences from these 3 methods i used? pros and cons of each?
@danny_moran
@danny_moran Жыл бұрын
Within Hyper-V there are three different virtual switch types. External, Internal, and Private. Depending on which one you select, it gives different types of network access. learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/plan-hyper-v-networking-in-windows-server
@Jonnie_Rich
@Jonnie_Rich Жыл бұрын
when turning on my DC01 VM , it says Start PXE over IPv4, and then it fails and goes into Virtual Machine Booty Sumary - Network adapter - a boot image was not found
@Jonnie_Rich
@Jonnie_Rich Жыл бұрын
I fixed it.. I moved IPv4 all the way down on boot configuration and moved the boot from cd to the top
@danny_moran
@danny_moran Жыл бұрын
Glad you got it fixed updating the boot order. Thanks for watching!
@Jonnie_Rich
@Jonnie_Rich Жыл бұрын
@@danny_moran You have helped me tremendously. I am terrible at networking things let alone VMs. Thanks Danny!
@omrrhino3844
@omrrhino3844 11 ай бұрын
hello pfSense Virtual iso is not working it not boot can you help ? 🤔
@danny_moran
@danny_moran 11 ай бұрын
Are you getting any error messages?
@Jonnie_Rich
@Jonnie_Rich Жыл бұрын
Danny, when I try to sign into my VM with windows 10, in the lab environment you setup in the video, it says " to sign in remotely, you need the right to sign in through Remote Desktop Services. By default, members of the Remote Desktop Users group have this right. If the group you're in doesn't have this right, or if the right has been removed from the Remote Desktop Users group, you need to be granted this right manually." Do I need to adjust group policy for this users OU ? Or do I need to install a Remote feature on my server ( roles and features) ? Thanks
@danny_moran
@danny_moran Жыл бұрын
That will be because the user account you are trying to login to the Windows 10 machine with isn't a member of either the Administrators or Remote Desktop Users group on the Windows 10 machine. If you add the user you are trying to login to the machine with to one of those groups, it should then work fine. As it's a lab, it's probably easier to just give all the user account Domain Admin and then you won't run into any permission issues. But don't give everyone Domain Admin in a production environment. Thanks for watching!
@Jonnie_Rich
@Jonnie_Rich Жыл бұрын
@@danny_moran Danny, I've noticed that when my Domain Controller VM is turned off, I'm not getting any internet connection on my other VM Server.. I'm not sure the reasoning behind this.
@danny_moran
@danny_moran Жыл бұрын
Is your domain controller hosting the DNS for your lab? If it is, other VMs won't be able to resolve any hostnames to IP addresses. It could also be that if your domain controller is hosting your DHCP server, then the other VMs in the lab won't be getting an IP address.
@Jonnie_Rich
@Jonnie_Rich Жыл бұрын
@@danny_moran Ahh! So I just let the DC run in the background?
@danny_moran
@danny_moran Жыл бұрын
Yes, I always have my dc running when using the lab.
@NaturalDimples
@NaturalDimples Жыл бұрын
can you do a video on how to unistall server core 2022 and go back to gui verson
@danny_moran
@danny_moran Жыл бұрын
You can't change from server core to server gui without doing a full re-install of the operating system. You would need to boot from the installation media and do a full re-installation. Thanks for watching!
@paulwoodward8265
@paulwoodward8265 2 ай бұрын
I’d like to be able to attach test devices to the dev environment using a managed switch. Say vlan20 for the lab. Any good guides on doing that?
@danny_moran
@danny_moran 2 ай бұрын
I don't have any guides on this, unfortunately. Thanks for watching!
@user-xz9py6em3j
@user-xz9py6em3j 10 ай бұрын
Can this be done over wifi?
@danny_moran
@danny_moran 10 ай бұрын
Yes, this can be done over wifi. You just need to select your wifi network card when setting up the virtual switch. Thanks for watching!
@dg9576
@dg9576 9 ай бұрын
nice one bruv
@danny_moran
@danny_moran 9 ай бұрын
Thanks for watching!
@dg9576
@dg9576 9 ай бұрын
Nah thankyou. I had already subbed, I had pf sense VMd before, but never did anything with it, was on bucket list, but was looking at the Hyper V switch and running server with office and was going to link a DC with an AWS route 53 hosted zone and lab a hybrid, and came across ya videos, and you were using pfsense, so i thought sweet!!!.... been through a few of your vids, now in my save list... really good content. Good luck to you. Appreciate the channel. @@danny_moran
@danny_moran
@danny_moran 9 ай бұрын
I'm glad you are finding them useful!
@TangledMatyi
@TangledMatyi 6 ай бұрын
Hey! This is gonna sound very stupid, but I have no idea what all of this was about, all I know is that I wanted to setup an isolated virtual machine that has access to the internet, but can't send stuff to the host. So now if I install a normal windows 11 inside this using the "lab-switch-lan" option, will that be a safe enviroment for me to run a software that potentially contains a trojan virus? Like will it not spread to my host because of the isolation? And also if I set up gpu sharing will it still be isolated. I know I'm propably asking some stupid stuff but I'm clueless of what I'm doing XD
@danny_moran
@danny_moran 6 ай бұрын
Ideally, before you run software that might contain viruses, you would disconnect fully from any network so that it has no way to potentially spread. The method shown in this video is good for setting up test networks so that the two networks don't conflict with each other, but I wouldn't really use it to check if things contain viruses. Thanks for watching!
@TangledMatyi
@TangledMatyi 6 ай бұрын
Well I need internet connection to use a sofrware. It is a software that a lot of people say is safe, but some warn that it might contain trojan, that's why I'm trying this method. So does this somewhat prevent the trojan to go straight to my main netwrok, and infect other devices, or it doesn't do anything like that?@@danny_moran
How to setup DNS Conditional Forwarders
5:02
Danny Moran
Рет қаралды 12 М.
7 Days Stranded In A Cave
17:59
MrBeast
Рет қаралды 94 МЛН
My Cheetos🍕PIZZA #cooking #shorts
00:43
BANKII
Рет қаралды 28 МЛН
Can This Bubble Save My Life? 😱
00:55
Topper Guild
Рет қаралды 84 МЛН
This Dumbbell Is Impossible To Lift!
01:00
Stokes Twins
Рет қаралды 34 МЛН
Unlocking Hyper-V Networking Secrets: IT Admins and Virtual Network Solutions
26:35
Hyper V Network Configuration : Virtual Switch Manager
9:01
syncbricks
Рет қаралды 31 М.
How to Install pfSense on Hyper-V to Support VLANs
26:29
Tech on Fire
Рет қаралды 1 М.
Can a virus spread from the virtual machine to host machine?
20:39
pfSense CE vs OPNsense 2024 ...and that video
43:05
Sheridan Computers
Рет қаралды 8 М.
Active Directory Configuration on VM in Hyper-V Windows Server 2019
27:50
How to Setup a Basic Home Lab Running Active Directory (Hyper-V Manager)
30:39
How to Build a Hyper-V Cluster
15:07
Intellezy Learning
Рет қаралды 30 М.
microsoft doubles down on recording your screen
10:00
Low Level Learning
Рет қаралды 87 М.
7 Days Stranded In A Cave
17:59
MrBeast
Рет қаралды 94 МЛН