TIEFGANG■

One workplace. Seven steps. No prior knowledge needed.

Static reading view · English / Deutsch

01 / 07 · Unboxing

A new day.
An empty device.

In plain words: It is Jana’s first day. Her new laptop is still in its box. Before she can work, IT has to register it, connect it and set it up.

It is Jana’s first day. Her laptop is unpacked — but without a network, operating system or identity, it is not a workplace yet.

Register the asset, assign the device, connect power. Automation starts with a reliable inventory.

Terms
Client
The device someone works on. Here: Jana’s laptop.
Tiefgang · JANA-01Exploded view of a laptop, access point, switch, firewall, servers, virtual machines and backup. Two uplinks connect switch and firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
Inventory · JANA-01

02 / 07 · The network

Jana’s laptop
says hello.

In plain words: The laptop is plugged into the company network, like a car joining the right road. A firewall makes sure it only goes where it is allowed to.

The network is the first point of contact. Jana’s device joins the client VLAN; the firewall controls the path to the services.

The laptop starts on a wired dock. The access point serves wireless clients; two independent uplinks protect the switch-to-firewall connection in this model.

Terms
VLAN
Separate “lanes” on the same cabling.
Firewall
A gatekeeper between networks: it lets only permitted traffic through.
Access point
A transmitter for the Wi-Fi.
Uplink
The link between two network devices, here between switch and firewall.
Switch
A cable distributor: it connects all devices in the building.

If the active uplink fails, transmission pauses briefly. The independent alternate path takes over; this does not protect against a failed client connection.

Tiefgang · JANA-01Exploded view of a laptop, access point, switch, firewall, servers, virtual machines and backup. Two uplinks connect switch and firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
VLAN 20 · client network

03 / 07 · Address (DHCP)

Four messages.
One address.

In plain words: Every device on the network needs its own address, like a house number for the post. The laptop asks, a server answers. After four short messages it has one.

The laptop asks and the DHCP server replies. An address, gateway and DNS turn an unknown device into a reachable participant.

Discover, Offer, Request, Acknowledge: the client may use the offered address only after the server confirms it.

Terms
DHCP
Hands out network addresses automatically.
DNS
The network’s phone book: it turns names into addresses.
  1. DISCOVER · Laptop → everyone

    “Is there anyone who can give me an address?”

  2. OFFER · DHCP → laptop

    “I can offer 10.20.0.42. Your gateway is 10.20.0.1.”

  3. REQUEST · Laptop → everyone

    “I would like to accept this offer from DHCP-01.”

  4. ACK · DHCP → laptop

    “Confirmed. The address is reserved for you. DNS: 10.20.0.10.”

Tiefgang · JANA-01Exploded view of a laptop, access point, switch, firewall, servers, virtual machines and backup. Two uplinks connect switch and firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
DHCP · an address

04 / 07 · Operating system (PXE)

One boot.
No USB stick.

In plain words: The laptop has no Windows yet. It fetches it over the network, without a USB stick, and gets exactly the version IT has approved.

The laptop boots into deployment over the network. PXE delivers the boot environment; the deployment solution installs the operating system and drivers.

UEFI network boot → boot environment → approved image → drivers. Keeping these steps distinct makes rollout repeatable.

Terms
PXE
Starting over the network instead of from a USB stick.
Tiefgang · JANA-01Exploded view of a laptop, access point, switch, firewall, servers, virtual machines and backup. Two uplinks connect switch and firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
PXE · operating system

05 / 07 · Sign-in (AD)

One name.
The right access.

In plain words: Jana signs in with her name and password. A central directory knows who she is and what she may do.

Jana signs in with her domain account. Active Directory verifies her identity; groups and policies manage access.

DNS locates the domain controller. Kerberos authenticates the account, Group Policy configures the workstation and groups restrict file access.

Terms
Active Directory
A central directory for accounts, groups and permissions.
DNS
The network’s phone book: it turns names into addresses.
Tiefgang · JANA-01Exploded view of a laptop, access point, switch, firewall, servers, virtual machines and backup. Two uplinks connect switch and firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
AD · an identity

06 / 07 · Software (UEM)

Everything ready.
Before work starts.

In plain words: All the programs Jana needs are installed automatically. IT can also see whether it really worked.

baramundi deploys approved software to the managed client. Assignments, installation status and inventory remain centrally traceable.

Packages are assigned by device and user. A successful job requires a verifiable result — not merely an installer that was started.

Terms
UEM (baramundi)
Management that brings programs and settings to devices. baramundi is one such product.
Tiefgang · JANA-01Exploded view of a laptop, access point, switch, firewall, servers, virtual machines and backup. Two uplinks connect switch and firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
UEM · baramundi

07 / 07 · Backup

Work begins.
Protection stays.

In plain words: Jana’s files are saved in a second place. Whether they can be brought back is tested. Only then is the workstation truly protected.

Jana’s files live on the file server and are backed up. A separate backup and a verified restore protect them when redundancy alone is no longer enough.

Redundancy keeps services available. A backup recovers lost data; this model therefore also restores a file as a test.

Terms
Backup · restore
A backup is a copy of the data in another place. A restore brings it back.
Redundancy
Important parts exist twice so operation continues when one fails.

Good morning, Jana.

Model time: 35 minutes

The time is shown compressed. It is neither measured nor compared with another approach.
Tiefgang · JANA-01Exploded view of a laptop, access point, switch, firewall, servers, virtual machines and backup. Two uplinks connect switch and firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
Backup · recoverable

Statische Lesefassung · English / Deutsch

01 / 07 · Auspacken

Ein neuer Tag.
Ein leeres Gerät.

In einfachen Worten: Jana fängt heute an. Ihr neuer Laptop liegt noch im Karton. Damit sie arbeiten kann, muss die IT ihn erst erfassen, anschließen und einrichten.

Jana fängt heute an. Ihr Laptop ist ausgepackt — aber ohne Netz, Betriebssystem und Identität ist er noch kein Arbeitsplatz.

Asset erfassen, Gerät zuordnen, Strom anschließen. Automatisierung beginnt mit einem sauberen Inventar.

Begriffe
Client
Das Gerät, an dem jemand arbeitet. Hier: Janas Laptop.
Tiefgang · JANA-01Schnitt durch Laptop, Access Point, Switch, Firewall, Server, virtuelle Maschinen und Backup. Zwei Uplinks verbinden Switch und Firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
Inventar · JANA-01

02 / 07 · Das Netz

Janas Laptop
meldet sich.

In einfachen Worten: Der Laptop wird ans Firmennetz angeschlossen, wie ein Auto, das auf die richtige Straße fährt. Eine Firewall sorgt dafür, dass er nur dorthin kommt, wo er hin darf.

Das Netz ist der erste Kontakt. Im Client-VLAN bekommt Janas Gerät seinen Platz; die Firewall begrenzt den Weg zu den Diensten.

Der Laptop startet am kabelgebundenen Dock. Der Access Point versorgt WLAN-Clients; zwei unabhängige Uplinks sichern hier die Verbindung zwischen Switch und Firewall.

Begriffe
VLAN
Getrennte „Spuren“ auf derselben Verkabelung.
Firewall
Pförtner zwischen Netzen: lässt nur Erlaubtes durch.
Access Point
Sendestation für das WLAN.
Uplink
Die Leitung zwischen zwei Netzwerkgeräten, hier zwischen Switch und Firewall.
Switch
Kabelverteiler: verbindet alle Geräte im Haus miteinander.

Bei einem Ausfall des aktiven Uplinks pausiert die Übertragung kurz. Der unabhängige Ersatzpfad übernimmt; ein einzelner ausgefallener Client-Anschluss wäre damit nicht abgesichert.

Tiefgang · JANA-01Schnitt durch Laptop, Access Point, Switch, Firewall, Server, virtuelle Maschinen und Backup. Zwei Uplinks verbinden Switch und Firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
VLAN 20 · Client-Netz

03 / 07 · Adresse (DHCP)

Vier Nachrichten.
Eine Adresse.

In einfachen Worten: Jedes Gerät im Netz braucht eine eigene Adresse, wie eine Hausnummer für die Post. Der Laptop fragt, ein Server antwortet. Nach vier kurzen Nachrichten hat er seine.

Der Laptop fragt, der DHCP-Server antwortet. Adresse, Gateway und DNS machen aus einem unbekannten Gerät einen erreichbaren Teilnehmer.

Discover, Offer, Request, Acknowledge: Erst nach der Bestätigung darf der Client die angebotene Adresse verwenden.

Begriffe
DHCP
Verteilt automatisch Netzwerkadressen.
DNS
Telefonbuch des Netzes: macht aus Namen Adressen.
  1. DISCOVER · Laptop → alle

    „Ist hier jemand, der mir eine Adresse geben kann?“

  2. OFFER · DHCP → Laptop

    „Ich biete dir 10.20.0.42 an. Dein Gateway ist 10.20.0.1.“

  3. REQUEST · Laptop → alle

    „Ich möchte dieses Angebot von DHCP-01 annehmen.“

  4. ACK · DHCP → Laptop

    „Bestätigt. Die Adresse ist für dich reserviert. DNS: 10.20.0.10.“

Tiefgang · JANA-01Schnitt durch Laptop, Access Point, Switch, Firewall, Server, virtuelle Maschinen und Backup. Zwei Uplinks verbinden Switch und Firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
DHCP · eine Adresse

04 / 07 · Betriebssystem (PXE)

Ein Start.
Ohne USB-Stick.

In einfachen Worten: Auf dem Laptop ist noch kein Windows. Er holt es sich übers Netz, ohne USB-Stick, und bekommt genau den Stand, den die IT geprüft hat.

Der Laptop startet über das Netzwerk in die Bereitstellung. PXE liefert die Startumgebung; die Deployment-Lösung übernimmt Betriebssystem und Treiber.

UEFI-Netzwerkstart → Bootumgebung → freigegebenes Image → Treiber. Diese Trennung macht einen wiederholbaren Rollout möglich.

Begriffe
PXE
Start über das Netzwerk statt von einem USB-Stick.
Tiefgang · JANA-01Schnitt durch Laptop, Access Point, Switch, Firewall, Server, virtuelle Maschinen und Backup. Zwei Uplinks verbinden Switch und Firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
PXE · Betriebssystem

05 / 07 · Anmeldung (AD)

Ein Name.
Die richtigen Rechte.

In einfachen Worten: Jana meldet sich mit ihrem Namen und Passwort an. Ein zentrales Verzeichnis weiß, wer sie ist und was sie darf.

Jana meldet sich mit ihrem Domänenkonto an. Active Directory bestätigt ihre Identität; Gruppen und Richtlinien regeln den Zugriff.

DNS findet den Domänencontroller. Kerberos authentifiziert das Konto, Gruppenrichtlinien konfigurieren den Arbeitsplatz und Gruppen begrenzen die Dateizugriffe.

Begriffe
Active Directory
Zentrales Verzeichnis für Konten, Gruppen und Rechte.
DNS
Telefonbuch des Netzes: macht aus Namen Adressen.
Tiefgang · JANA-01Schnitt durch Laptop, Access Point, Switch, Firewall, Server, virtuelle Maschinen und Backup. Zwei Uplinks verbinden Switch und Firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
AD · eine Identität

06 / 07 · Software (UEM)

Alles da.
Bevor es losgeht.

In einfachen Worten: Alle Programme, die Jana braucht, werden automatisch installiert. Die IT sieht außerdem, ob es auch wirklich geklappt hat.

baramundi verteilt die freigegebene Software auf den verwalteten Client. Zuweisungen, Installationsstatus und Inventar bleiben zentral nachvollziehbar.

Pakete werden nach Geräte- und Benutzerzuordnung verteilt. Ein erfolgreicher Job braucht eine nachvollziehbare Rückmeldung — nicht nur einen gestarteten Installer.

Begriffe
UEM (baramundi)
Verwaltung, die Programme und Einstellungen auf Geräte bringt. baramundi ist ein solches Produkt.
Tiefgang · JANA-01Schnitt durch Laptop, Access Point, Switch, Firewall, Server, virtuelle Maschinen und Backup. Zwei Uplinks verbinden Switch und Firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
UEM · baramundi

07 / 07 · Sicherung

Arbeit beginnt.
Sicherheit bleibt.

In einfachen Worten: Janas Dateien werden an einem zweiten Ort gesichert. Ob man sie zurückholen kann, wird ausprobiert. Erst dann ist der Arbeitsplatz wirklich geschützt.

Janas Dateien liegen auf dem Dateiserver und werden gesichert. Eine getrennte Sicherung und ein geprüfter Restore schützen auch dann, wenn Redundanz allein nicht mehr hilft.

Redundanz hält Dienste verfügbar. Ein Backup stellt Daten nach Verlust wieder her; im Modell wird deshalb auch eine Datei testweise zurückgesichert.

Begriffe
Backup · Restore
Ein Backup ist die Kopie der Daten an einem anderen Ort. Restore holt sie zurück.
Redundanz
Wichtiges gibt es doppelt, damit der Betrieb bei einem Ausfall weiterläuft.

Guten Morgen, Jana.

Modellzeit: 35 Minuten

Die Zeit ist verdichtet dargestellt. Sie ist weder gemessen noch mit einem anderen Weg verglichen.
Tiefgang · JANA-01Schnitt durch Laptop, Access Point, Switch, Firewall, Server, virtuelle Maschinen und Backup. Zwei Uplinks verbinden Switch und Firewall. FIREWALL DHCP · DNS PXE / DEPLOY AD / IDENTITY UEM / PACKAGES VM 01 VM 02 VM 03 STORAGE / BACKUP AB
Backup · wiederherstellbar