To start with, it is nice to have a network of virtual machines that can be standalone or have Internet connectivity, as needed. So, to start, I’ll with my run down of a great article from The Helpful Hacker website “A simple OpenBSD Router for your Virtual Machines” http://thehelpfulhacker.net/2011/11/15/virtual-box-openbsd-router/
You ask, “Why yet another technology?”. It’s simple. Not really, with this article, it’s really simple to get a router rolling for my purposes. I’ll be exploring router/firewalls in CentOS and Ubuntu later, but for today: OpenBSD – quick and dirty. (http://www.openbsd.org/)
And because I like to work downstairs near my beautiful wife (http://ryu.k5ryu.com/gallery/view_album.php?set_albumName=CharriesHair and http://ryu.k5ryu.com/gallery/view_album.php?set_albumName=CharriesShodanTest), most of this will be done in VirtualBox (https://www.virtualbox.org/) on a Windows notebook.
- You are familiar with VirtualBox
- You have some basic system administration skills
- You know an editor, like ‘vi’ or ‘nano’. I’ll be using ‘vi’ for all my examples.
This will be short on theory, and mostly “here’s what you need to do”. If you want more theory, for now, I’d recommend hit Google, or send me a note. Let’s get started. Download VirtualBox and install it on your favorite workstation. Next, go to OpenBSD and download the install68.iso (or the current release) from one of the mirrors.
First, let’s create our internal network. Under File>Preferences>Network, add a new Host-only network. Update the settings to have the following parameters:
- Adaptor Tab:
- Check Configure Adapter Manually
- IPv4 Address: 10.13.13.1
- IPv4 Network Mask: 255.255.255.0
- DHCP Server
- Enable Server
- Server Address: 192.168.31.2
- Server Mask: 255.255.255.0
- Lower Address Bound: 10.13.13.100
- Upper Address Bound: 10.13.13.100
From here, we’ll pretty much follow The Helpful Hacker article with some minor changes, and then wrap up with some networking in preparation for our sandbox.
Create a new machine:
- Name: fw.dining.k5ryu.com
- Type: BSD
- Version: OpenBSD (64 bit)
Couple of notes here. Unless needed, I’ll be creating all my virtual machines (VMs) as 64-bit machines. My hostnames either follow martial arts, location, or other random name, for memory purposes. For particular tasks, I’ll use canonical names (CNAMES) to assign services (WWW, MAIL, IMAP, etc) to a host. This also allows me to move a service to a different server and not have to rename the server. From my years in the field, this is particularly useful in server migrations or upgrades.
Through out this exercise, so there will be different subnets. This first one is ‘dining.k5ryu.com’. I’m working on my notebook that generally lives in the dining room. Well, in the dining room, living room, dinette, kitchen, general mobile, but I had to pick one, so ‘dining’ works. I could bridge my various VirtualBox networks in to one, but I have additional plans that we’ll eventually get to.
- Memory: 64 M
- Disk: New VDI disk, Dynamically allocated, 16G
Leave the first network adaptor as a NAT. Add a second adaptor, enable it, and attach it to the Host-only Adaptor.
Now, attach the OpenBSD ISO to the CD/DVD Drive and start the machine.
- “default” keyboard
- Hostname: torii
- Configure em0
- IPv4 Address: dhcp
- IPv6 Address: none
- Choose “done” for network configuration.
- Choose a root password
- Start sshd by default: yes
- Start ntpd by default; yes
- Use default NTP server
- No to X windows
- No additional users
- I’m in US/Central timezone, but choose the appropriate one for you.
- Choose disk wd0 for the root disk
- Use DUIDs
- Use the (W)hole disk
- (A)uto layout
- Location of sets: cd
- Install media: cd0
- Pathname: 5.4/amd64
- Deselect the Xwindows sets: -x*
- Deselect the games: -g*
- And “done”
- When the sets load, choose “done”
- Set the time
And you are done! “Halt –p” the machine, unmount the disk, restart and log in as root.
Few more things, and we’ll be done:
- echo dhcp > /etc/hostname.em0
- echo “10.113.13.3 255.255.255.0” > /etc/hostname.em1
- echo “nameserver 188.8.131.52” > /etc/resolv.conf
- sh /etc/netstart
- edit /etc/sysctl.conf, and uncomment net.inet.ip.forwarding and set to 1 (Permit forwarding of IPv4 packets)
- edit /etc/rc.conf and set pf=YES (enable pf firewall)
- edit /etc/pf.conf and add to the end: “pass out on em0 from em1:network to any nat-to (em0)”
And you’re done.
If you want more details on the last steps, read the article at: http://thehelpfulhacker.net/2011/11/15/virtual-box-openbsd-router/
For our purposes, the first step of our sandbox is done.
Next up will be the first workstation/server. It will perform double duty as my initial configuration server and workstation. Later, the services that don’t make sense to be on this host will get migrated off.