Skip to content

Commit

Permalink
Merge pull request clong#622 from clong/exchange_esxi_azure
Browse files Browse the repository at this point in the history
Adding Exchange for Azure and ESXi
  • Loading branch information
clong authored Mar 14, 2021
2 parents d8b40fc + 4bde98f commit 363454c
Show file tree
Hide file tree
Showing 17 changed files with 466 additions and 20 deletions.
6 changes: 6 additions & 0 deletions Azure/Ansible/detectionlab.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,9 @@
- win10
- common
tags: win10

- hosts: exchange
roles:
- exchange
- common
tags: exchange
4 changes: 4 additions & 0 deletions Azure/Ansible/inventory.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,7 @@ win10:
hosts:
z.z.z.z:

#exchange:
#hosts:
#w.w.w.w:

136 changes: 136 additions & 0 deletions Azure/Ansible/roles/exchange/tasks/main.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,136 @@
---

- name: Hostname -> EXCHANGE
win_hostname:
name: EXCHANGE
register: res

- name: Reboot
win_reboot:
when: res.reboot_required

- name: Set HostOnly IP Address
win_shell: "If (-not(get-netipaddress | where {$_.IPAddress -eq '192.168.38.106'})) {$adapter = (get-netadapter | where {$_.MacAddress -eq '00-50-56-A1-B4-C5'}).Name; New-NetIPAddress –InterfaceAlias $adapter –AddressFamily IPv4 -IPAddress 192.168.38.106 –PrefixLength 24 -DefaultGateway 192.168.38.1 } Else { Write-Host 'IP Address Already Created.' }"

- name: Set HostOnly DNS Address
win_shell: "$adapter = (get-netadapter | where {$_.MacAddress -eq '00-50-56-A1-B4-C5'}).Name; Set-DnsClientServerAddress -InterfaceAlias $adapter -ServerAddresses 192.168.38.102,8.8.8.8"

- name: Install git
win_chocolatey:
name: git
state: present

- name: Check if existing DetectionLab directory
win_stat:
path: 'c:\DetectionLab'
register: dir

- name: Git clone Detectionlab
win_shell: git clone https://github.com/clong/DetectionLab.git
args:
chdir: 'c:\'
when: not dir.stat.exists

- name: Copy scripts to c:\vagrant
win_shell: Copy-Item -Recurse c:\DetectionLab\Vagrant c:\vagrant

- name: Join the Domain
win_shell: .\\provision.ps1
args:
chdir: 'c:\vagrant\scripts'
register: exchange_join_domain
changed_when: "'HasSucceeded : True' in exchange_join_domain.stdout"

- debug: msg="{{ exchange_join_domain.stdout_lines }}"

- name: Reboot After Joining the Domain
win_reboot:
msg: "Joining the domain. Rebooting..."
pre_reboot_delay: 5
reboot_timeout: 600
post_reboot_delay: 60

- name: Install Exchange Prereqs
win_shell: .\\install-exchange.ps1
args:
chdir: 'c:\vagrant\scripts'
register: exchange_prereqs
changed_when: "'A reboot is required to continue installation of exchange.' in exchange_prereqs.stdout"

- name: Reboot After Installing Exchange PreReqs
win_reboot:
msg: "Exchange Prereqs installed. Rebooting..."
pre_reboot_delay: 5
reboot_timeout: 600
post_reboot_delay: 60

- name: Download Exchange ISO and Mount It
win_shell: .\\install-exchange.ps1
args:
chdir: 'c:\vagrant\scripts'
register: download_exchange_iso

- name: Prepare Schema
win_package:
path: E:\Setup.exe
arguments: >-
/IAcceptExchangeServerLicenseTerms
/PrepareSchema
product_id: '{CD981244-E9B8-405A-9026-6AEB9DCEF1F1}'
vars:
ansible_become: yes
ansible_become_method: runas
ansible_become_user: WINDOMAIN.local\Administrator
ansible_become_password: vagrant
register: prepare_schema
changed_when: "prepare_schema.rc == 0"

- name: Prepare AD
win_package:
path: E:\Setup.exe
arguments: >-
/IAcceptExchangeServerLicenseTerms
/PrepareAD
/OrganizationName: DetectionLab
product_id: '{CD981244-E9B8-405A-9026-6AEB9DCEF1F1}'
vars:
ansible_become: yes
ansible_become_method: runas
ansible_become_user: WINDOMAIN.local\Administrator
ansible_become_password: vagrant
register: prepare_ad
changed_when: "prepare_ad.rc == 0"

- name: Install Exchange
win_package:
path: E:\Setup.exe
arguments: >-
/IAcceptExchangeServerLicenseTerms
/Mode:Install
/Role:Mailbox
product_id: '{CD981244-E9B8-405A-9026-6AEB9DCEF1F1}'
vars:
ansible_become: yes
ansible_become_method: runas
ansible_become_user: WINDOMAIN.local\Administrator
ansible_become_password: vagrant
register: install_exchange
changed_when: "install_exchange.rc == 0"

- name: Reboot after Exchange Installation
win_reboot:
msg: "Exchange installed. Rebooting..."
pre_reboot_delay: 5
reboot_timeout: 600
post_reboot_delay: 60

- name: Clear Event Logs
win_shell: "wevtutil el | Select-String -notmatch \"Microsoft-Windows-LiveId\" | Foreach-Object {wevtutil cl \"$_\"}"

- name: Configure EXCHANGE with raw Commands
win_shell: "{{ item }}"
with_items:
- "wevtutil el | Select-String -notmatch \"Microsoft-Windows-LiveId\" | Foreach-Object {wevtutil cl \"$_\"}"
- "Set-SmbServerConfiguration -AuditSmb1Access $true -Force"


1 change: 1 addition & 0 deletions Azure/Terraform/locals.tf
Original file line number Diff line number Diff line change
Expand Up @@ -4,4 +4,5 @@ locals {
ata_url = "https://${azurerm_public_ip.wef-publicip.ip_address}"
guacamole_url = "http://${azurerm_public_ip.logger-publicip.ip_address}:8080/guacamole"
velociraptor_url = "https://${azurerm_public_ip.logger-publicip.ip_address}:9999"
exchange_url = "https://${azurerm_public_ip.exchange-publicip.ip_address}"
}
85 changes: 85 additions & 0 deletions Azure/Terraform/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -366,6 +366,33 @@ resource "azurerm_public_ip" "win10-publicip" {
}
}

resource "azurerm_network_interface" "exchange-nic" {
count = var.create_exchange_server ? 1 : 0
name = "exchange-nic"
location = var.region
resource_group_name = azurerm_resource_group.detectionlab.name

ip_configuration {
name = "myNicConfiguration"
subnet_id = azurerm_subnet.detectionlab-subnet.id
private_ip_address_allocation = "Static"
private_ip_address = "192.168.38.106"
public_ip_address_id = azurerm_public_ip.exchange-publicip.id
}
}

resource "azurerm_public_ip" "exchange-publicip" {
count = var.create_exchange_server ? 1 : 0
name = "exchange-public-ip"
location = var.region
resource_group_name = azurerm_resource_group.detectionlab.name
allocation_method = "Static"

tags = {
role = "exchange"
}
}

resource "azurerm_virtual_machine" "dc" {
name = "dc.windomain.local"
location = var.region
Expand Down Expand Up @@ -479,6 +506,64 @@ resource "azurerm_virtual_machine" "wef" {
}
}

resource "azurerm_virtual_machine" "exchange" {
count = var.create_exchange_server ? 1 : 0
name = "exchange.windomain.local"
location = var.region
resource_group_name = azurerm_resource_group.detectionlab.name
network_interface_ids = [azurerm_network_interface.exchange-nic.id]
vm_size = "Standard_D3_v2"

delete_os_disk_on_termination = true

storage_image_reference {
publisher = "MicrosoftWindowsServer"
offer = "WindowsServer"
sku = "2016-Datacenter"
version = "latest"
}

os_profile {
computer_name = "exchange"
admin_username = "vagrant"
admin_password = "Vagrant123"
custom_data = local.custom_data_content
}

os_profile_windows_config {
provision_vm_agent = true
enable_automatic_upgrades = false

# Auto-Login's required to configure WinRM
additional_unattend_config {
pass = "oobeSystem"
component = "Microsoft-Windows-Shell-Setup"
setting_name = "AutoLogon"
content = "<AutoLogon><Password><Value>Vagrant123</Value></Password><Enabled>true</Enabled><LogonCount>1</LogonCount><Username>vagrant</Username></AutoLogon>"
}

# Unattend config is to enable basic auth in WinRM, required for the provisioner stage.
# https://github.com/terraform-providers/terraform-provider-azurerm/blob/master/examples/virtual-machines/provisioners/windows/files/FirstLogonCommands.xml
additional_unattend_config {
pass = "oobeSystem"
component = "Microsoft-Windows-Shell-Setup"
setting_name = "FirstLogonCommands"
content = file("${path.module}/files/FirstLogonCommands.xml")
}
}

storage_os_disk {
name = "OsDiskWef"
caching = "ReadWrite"
create_option = "FromImage"
managed_disk_type = "Standard_LRS"
}

tags = {
role = "exchange"
}
}

resource "azurerm_virtual_machine" "win10" {
name = "win10.windomain.local"
location = var.region
Expand Down
8 changes: 8 additions & 0 deletions Azure/Terraform/outputs.tf
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,10 @@ output "win10_public_ip" {
value = azurerm_public_ip.win10-publicip.ip_address
}

output "exchange_public_ip" {
value = azurerm_public_ip.exchange-publicip.ip_address
}

output "ata_url" {
value = local.ata_url
}
Expand All @@ -37,3 +41,7 @@ output "guacamole_url" {
output "velociraptor_url" {
value = local.velociraptor_url
}

output "exchange_url" {
value = local.velociraptor_url
}
6 changes: 6 additions & 0 deletions Azure/Terraform/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -39,4 +39,10 @@ variable "external_dns_servers" {
description = "Configure lab to allow external DNS resolution"
type = list(string)
default = ["8.8.8.8"]
}

variable "create_exchange_server" {
description = "If set to true, adds an additional host that installs exchange"
type = bool
default = false
}
6 changes: 6 additions & 0 deletions ESXi/ansible/detectionlab.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,9 @@
- win10
- common
tags: win10

- hosts: exchange
roles:
- exchange
- common
tags: exchange
3 changes: 3 additions & 0 deletions ESXi/ansible/inventory.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,6 @@ win10:
hosts:
192.168.3.204:

exchange:
hosts:
192.168.3.206:
2 changes: 1 addition & 1 deletion ESXi/ansible/roles/dc/tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
when: res.reboot_required

- name: Set HostOnly IP Address
win_shell: "$adapter = (get-netadapter | where {$_.MacAddress -eq '00-50-56-A1-B1-C4'}).Name; New-NetIPAddress –InterfaceAlias $adapter –AddressFamily IPv4 -IPAddress 192.168.38.102 –PrefixLength 24 -DefaultGateway 192.168.38.1"
win_shell: "If (-not(get-netipaddress | where {$_.IPAddress -eq '192.168.38.102'})) {$adapter = (get-netadapter | where {$_.MacAddress -eq '00-50-56-A1-B1-C4'}).Name; New-NetIPAddress –InterfaceAlias $adapter –AddressFamily IPv4 -IPAddress 192.168.38.102 –PrefixLength 24 -DefaultGateway 192.168.38.1 } Else { Write-Host 'IP Address Already Created.' }"

- name: Set DNS Address
win_shell: "$adapter = (get-netadapter | where {$_.MacAddress -eq '00-50-56-A1-B1-C4'}).Name; Set-DnsClientServerAddress -InterfaceAlias $adapter -ServerAddresses 127.0.0.1,8.8.8.8"
Expand Down
Loading

0 comments on commit 363454c

Please sign in to comment.