ISP

New-NetIPAddress 1.1.1.2 -InterfaceAlias Ethernet0 -PrefixLength 30
New-NetIPAddress 1.1.1.6 -InterfaceAlias Ethernet0 -PrefixLength 30
New-NetIPAddress 2.2.2.2 -InterfaceAlias Ethernet1 -PrefixLength 30
New-NetIPAddress 2.2.2.6 -InterfaceAlias Ethernet1 -PrefixLength 30
New-NetIPAddress 3.3.3.1 -InterfaceAlias Ethernet2 -PrefixLength 24

!방화벽
netsh advfirewall set allprofile state off
Rename-Computer -NewName ISP -Restart

!라우팅
Install-WindowsFeature routing -IncludeManagementTools
Install-RemoteAccess -VpnType RoutingOnly

HQ-R

New-NetIPAddress 192.168.0.254 -InterfaceAlias Ethernet0 -PrefixLength 24
New-NetIPAddress 1.1.1.1 -InterfaceAlias Ethernet1 -PrefixLength 30
New-NetIPAddress 1.1.1.5 -InterfaceAlias Ethernet1 -PrefixLength 30 -DefaultGateway 1.1.1.6

!방화벽
netsh advfirewall set allprofile state off
Rename-Computer -NewName HQ-R -Restart

!routing 활성화
Install-WindowsFeature routing -IncludeManagementTools
Restart-Computer
Install-RemoteAccess -VpnType RoutingOnly

!site to site vpn
Install-RemoteAccess -VpnType VpnS2S
**Add-VpnS2SInterface -Name VPN -Protocol IKEv2 -AuthenticationMethod PSKOnly -SharedSecret "Skill39**" -SourceIpAddress 1.1.1.1 -Destination 2.2.2.1 -Persistent:$true -IPv4Subnet 192.168.1.0/24:100
Connect-VpnS2SInterface -Name VPN**

!NAT 설정
New-NetNat -Name NAT -ExternalIPInterfaceAddressPrefix 1.1.1.4/30
Add-NetNatExternalAddress -NatName NAT -IPAddress 1.1.1.5

**Add-NetNatExternalAddress -NatName NAT -IPAddress 1.1.1.5 -PortStart 53 -PortEnd 53
Add-NetNatStaticMapping -NatName NAT -Protocol UDP -ExternalIPAddress 1.1.1.5 -ExternalPort 53 -InternalIPAddress 192.168.0.1 -InternalPort 53**

BR-R

New-NetIPAddress 192.168.1.254 -InterfaceAlias Ethernet0 -PrefixLength 24
New-NetIPAddress 2.2.2.1 -InterfaceAlias Ethernet1 -PrefixLength 30
New-NetIPAddress 2.2.2.5 -Interfacealias Ethernet1 -PrefixLength 30 -DefaultGateway 2.2.2.6

netsh advfirewall set allprofile state off
Rename-Computer -NewName BR-R -Restart

Install-WindowsFeature routing -IncludeManagementTools
Restart-Computer
Install-RemoteAccess -VpnType Routing

Install-RemoteAccess -VpnType VpnS2S
**Add-VpnS2SInterface -Name VPN -Protocol IKEv2 -AuthenticationMethod PSKOnly -SharedSecret "Skill39**" -SourceIpAddress 2.2.2.1 -Destination 1.1.1.1 -Persistent:$true -IPv4Subnet 192.168.0.0/24:100
Connect-VpnS2SInterface -Name VPN**

New-NetNat -Name NAT -ExternalIPInterfaceAddressPrefix 2.2.2.4/30
Add-NetNatExternalAddress -NatName NAT -IPAddress 2.2.2.5

DC

New-NetIPAddress 192.168.0.1 -InterfaceAlias Ethernet0 -PrefixLength 24 -DefaultGateway 192.168.0.254
netsh advfirewall set allprofile state off
Rename-Computer -NewName DC -Restart

Install-WindowsFeature DNS, AD-Domain-Services -IncludeManagementTools
Install-ADDSForest -DomainName corp.local

HQDC

New-NetIPAddress 192.168.0.2 -InterfaceAlias Ethernet0 -PrefixLength 24 -DefaultGateway 192.168.0.254
netsh advfirewall set allprofile state off
Rename-Computer -NewName HQDC -Restart

BRDC

New-NetIPAddress 192.168.1.1 -InterfaceAlias Ethernet0 -PrefixLength 24 -DefaultGateway 192.168.1.254
netsh advfirewall set allprofile state off
Rename-computer -NewNAme BRDC -Restart

STORAGE

New-NetIPAddress 192.168.0.213 -InterfaceAlias Ethernet0 -PrefixLength 24 -DefaultGateway 192.168.0.254
netsh advfirewall set allprofile state off
Rename-Computer -NewName STORAGE -Restart