[go: up one dir, main page]

0% found this document useful (0 votes)
204 views31 pages

Implementing and Managing IPAM

Download as pdf or txt
Download as pdf or txt
Download as pdf or txt
You are on page 1/ 31

Module 5

Implementing and managing IPAM


Module Overview

• Overview of IPAM
• Deploying IPAM
• Managing IP address spaces by using IPAM
Lesson 1: Overview of IPAM

• What is IPAM?
• IPAM architecture
• IPAM deployment requirements
• Considerations for IPAM deployment
• Integrating IPAM with Virtual Machine Manager
What is IPAM?

IPAM consists of four modules that provide the following


functionality:
• IPAM discovery
• IP address space management
• Multiserver management and monitoring
• Operational auditing and IP address tracking
IPAM architecture

IPAM consists of two main components:


• IPAM server
• IPAM client

When deploying IPAM, you can select from three


topologies:
• Distributed
• Centralized
• Hybrid
IPAM deployment requirements

To ensure a successful IPAM implementation, an


organization’s network infrastructure must meet the
following prerequisites:
• The IPAM server must be a domain member
• The IPAM server should be a single-purpose server
• To manage the IPv6 address space, enable IPv6 on the
IPAM server
• Sign in to the IPAM server with a domain account
• Belong to the correct IPAM local security group on the
IPAM server
• Enable logging of account sign-in events for IPAM’s IP
address tracking and auditing feature
• Meet software and hardware requirements
Considerations for IPAM deployment

When designing an IPAM deployment, consider the following factors:


• You can manage multiple AD DS forests if the required trusts exist
between those forests
• IPAM servers do not communicate with one another
• You can define the scope of discovery to a subset of domains in the
forest
• A single IPAM server can support many DHCP servers and DNS zones
• IPAM stores three years of forensics data
• IPAM supports WID or Microsoft SQL Server databases
• IP address utilization trends are provided only for IPv4
• IP address reclamation support is provided only for IPv4
• IPAM does not check for IP address consistency with routers and
switches
Integrating IPAM with Virtual Machine Manager
Lesson 2: Deploying IPAM

• Process of implementing IPAM


• Demonstration: Installing and provisioning the
IPAM role
• IPAM administration
• Demonstration: Administering IPAM
• Configuring IPAM options
• How to manage DNS by using IPAM
• Demonstration: Managing DNS with IPAM
• How to configure DHCP servers by using IPAM
• Demonstration: Managing DHCP scopes with
IPAM
Process of implementing IPAM

Perform the following steps to implement IPAM:


1. Install the IPAM Server feature
2. Provision IPAM servers
3. Configure and run server discovery
4. Choose and manage discovered servers
Demonstration: Installing and provisioning the
IPAM role

In this demonstration, you will learn how to:


• Install IPAM
• Provision IPAM
IPAM administration

• You implement role-based management in IPAM


by using:
• Role-based security groups
• Access scopes
• Access policies

• IPAM includes several built-in roles


• You can also create and configure custom roles
IPAM administration

IPAM has several built-in role-based security groups that


you can use for managing your IPAM infrastructure:
• IPAM DNS Administrator
• IPAM MSM Administrator
• IPAM ASM Administrator
• IP Address Record Administrator
• IPAM Administrator
• IPAM DHCP Administrator
• IPAM DHCP Reservations Administrator
• IPAM DHCP Scope Administrator
• DNS Record Administrator
Demonstration: Administering IPAM

In this demonstration, you will learn how to:


• Add a custom role group
• Add a custom scope
• Add an IPAM access policy
• Set the access scope
Configuring IPAM options

• You can configure IPAM by using the following


GPOs:
• <Prefix>_DHCP
• <Prefix>_DNS
• <Prefix>_DC_NPS

• To finalize the IPAM configuration, run the Invoke-


IpamGpoProvisioning cmdlet
How to manage DNS by using IPAM

You can perform the following DNS management


tasks in IPAM:
• View DNS servers and zones
• Create new zones
• Open the DNS console for any server that IPAM
manages
• Create DNS records
• Manage conditional forwarders
Demonstration: Managing DNS with IPAM

In this demonstration, you will learn how to:


• Add a conditional forwarder
• Create a DNS zone
• Add a DNS record
How to configure DHCP servers by using IPAM

• You can perform all DHCP configuration tasks for


a DHCP server in the IPAM administration
interface

• You configure DHCP servers and scopes


Demonstration: Managing DHCP scopes with IPAM

In this demonstration, you will learn how to add a


DHCP scope
Lesson 3: Managing IP address spaces by using IPAM

• Using IPAM to manage IP addressing


• Adding address spaces to IPAM
• Importing and updating address spaces
• Finding, allocating, and reclaiming IP addresses
• Maintaining IP address inventory in IPAM
• Demonstration: Managing IP addressing with
IPAM
• Monitoring and reporting in IPAM
Using IPAM to manage IP addressing
• You can view and manage an IP address space by using the
following views:
• IP address blocks

• IP address ranges

• IP addresses

• IP address inventory

• IP address range groups

• You can monitor the IP address space by using the following


views:
• DNS and DHCP servers

• DHCP scopes

• DNS zone monitoring

• Server groups
Adding address spaces to IPAM

You can add address spaces to IPAM to provide


comprehensive management of IP addressing
Importing and updating address spaces

• You can import the following into IPAM by using


CSV files:
• IP addresses
• IP address ranges
• IP address blocks

• The mandatory fields for importing are:


• IP addresses. IP address, managed by service, service
instance, device type, IP address state, and assignment type
• IP address range. Network, start IP address, end IP address,
managed by service, service instance, and assignment type
• IP address block. Network, start IP address, end IP address,
and RIR
Finding, allocating, and reclaiming IP addresses

You can use IPAM to find, allocate, and reclaim an


IP address if:
• The IP address does not exist in IPAM
• The IP address is not reserved in the range
• The IP address is not excluded from the range
• The IP address does not respond to a ping
request
• A DNS pointer (PTR) resource is not found for
the IP address
Maintaining IP address inventory in IPAM

You can use the following IPAM pages to assess and


maintain IP address inventory:
• IP Address Blocks (using IP Addresses view)
• IP Address Inventory
Demonstration: Managing IP addressing with IPAM

In this demonstration, you will learn how to:


• Add an address block in IPAM
• Create an IP address reservation
Monitoring and reporting in IPAM

With IPAM, you can:


• Monitor IP address space utilization
• Monitor DNS and DHCP health
• Configure many DHCP properties and values from
the IPAM console
• Use the event catalog to view a centralized
repository for all configuration changes
Lab: Implementing IPAM

• Exercise 1: Installing the IPAM Server feature


• Exercise 2: Provisioning the IPAM Server
• Exercise 3: Managing IP address spaces by using
IPAM
Logon Information
Virtual machines: 20741A-LON-DC1
20741A-LON-SVR1
20741A-LON-SVR2
20741A-TOR-SVR1
20741A-SYD-SVR1
20741A-EU-RTR
User name: Adatum\Administrator
Password: Pa$$w0rd
Estimated Time: 90 minutes
Lab Scenario

With the distribution of network services in


multiple locations, it is becoming increasingly
complex to manage the networking environment
at A. Datum Corporation. The IT management at
A. Datum has decided to deploy IPAM and use it
to manage the IP address configuration centrally
in the organization.
Lab Review

• Why did you run the Invoke-IpamGpoProvisioning


cmdlet?
• Why do only IP addresses and ranges from the
Houston, Mexico City, and Portland locations
appear in the IPAM console? Where are the IP
addresses from the London, Toronto, and Sydney
locations?
Module Review and Takeaways

• Review Questions

You might also like