When Your Hypervisor Is Too Helpful: Forcing Proxmox VM Traffic Through an Inline Network Tap

Tonight’s malware-lab adventure began with a mystery.

I have an inline Debian network tap sitting between my malware-analysis environment and OPNsense. The goal is straightforward: all VM traffic should traverse the tap so I can inspect, log, and control exactly what enters and leaves the environment.

At least, that was the goal.

I noticed traffic from one VM:

172.20.200.73

to another:

172.20.200.200

was not behaving the way the network diagram said it should.

The tap could see packets in some circumstances, my firewall rules were doing unexpected things, and OPNsense was not seeing traffic that should have been reaching it.

Naturally, I started with iptables.

My tap is aggressively filtered. INPUT, OUTPUT, and FORWARD all default to DROP, with explicit exceptions for allowed traffic. I could see TCP SYNs such as:

172.20.200.73:56530 -> 172.20.200.200:1501
172.20.200.73:56530 -> 172.20.200.200:19315
172.20.200.73:56530 -> 172.20.200.200:1840

but I wasn’t seeing the expected blacklist logs.

At first, bridge netfilter looked suspicious.

It wasn’t.

net.bridge.bridge-nf-call-iptables = 1
net.bridge.bridge-nf-call-ip6tables = 1

br_netfilter was loaded too.

Then I noticed the RELATED,ESTABLISHED rule counters going wild during an Nmap scan.

That looked promising, but it still wasn’t the root cause.

Proxmox Was Taking a Shortcut

The real answer appeared when I looked at the Proxmox bridge configuration.

All three relevant VMs were attached to the same bridge:

VM 2002 -> VMData -> 172.20.200.63
VM 3002 -> VMData -> 172.20.200.73
VM 3999 -> VMData -> 172.20.200.200

That meant Proxmox had absolutely no reason to send .73 -> .200 out onto the physical network.

They were on the same Layer-2 bridge.

Instead of:

VM .73
  ↓
Proxmox
  ↓
network tap
  ↓
OPNsense
  ↓
network tap
  ↓
VM .200

the actual path was basically:

VM .73
  ↓
VMData
  ↓
VM .200

My elaborate inspection path was being bypassed because Linux was doing exactly what an Ethernet bridge is supposed to do.

How inconsiderate.

Blocking Guest-to-Guest Switching

The first part of the solution was to stop Proxmox from directly forwarding traffic between VM-facing ports.

A guest-isolation guard now prevents VM-to-VM forwarding inside VMData while still allowing traffic to leave through the physical uplink.

Conceptually:

guest -> guest      DROP
guest -> enp7s0     ALLOW
enp7s0 -> guest     ALLOW

Problem solved?

Of course not.

Because Ethernet had another opinion.

ARP Enters the Chat

The VMs are all in:

172.20.200.0/24

So when .73 wants to communicate with .200, it does not send the packet to the gateway.

It asks:

Who has 172.20.200.200?

If guest-to-guest switching is blocked, .200 never receives that ARP request and therefore never answers it.

The host does not think:

“Well, direct Layer-2 communication failed. I guess I’ll send it to the router.”

That is not how IP works.

So I needed the VMs to believe that OPNsense itself was the Layer-2 destination for other VM addresses.

Enter Proxy ARP.

OPNsense Becomes Everyone

I configured OPNsense to Proxy ARP for the VM network.

Now when .73 asks:

Who has 172.20.200.200?

OPNsense responds:

172.20.200.200 is at <OPNsense MAC>

The same thing happens for the other VM addresses.

So the packet now goes:

VM .73
  ↓
OPNsense MAC
  ↓
network tap
  ↓
OPNsense
  ↓
network tap
  ↓
VM .200

The VMs still think they are on one flat /24, but they are effectively being routed through OPNsense.

This is gloriously weird.

Then the Tap Started Arguing With OPNsense

One address produced two ARP responses:

172.20.200.100

That address belongs to the Debian network tap itself.

The tap has:

br0 = 172.20.200.100/24

So Linux was correctly answering:

“Yes, 172.20.200.100 is me.”

Unfortunately, OPNsense was also answering on behalf of .100.

I had accidentally created an ARP custody dispute.

The fix was to make the tap continue owning .100 at Layer 3 while refusing to advertise that ownership directly at Layer 2.

The tap already had a native nftables bridge table protecting against ARP impersonation:

table bridge vmdata_l2_guard

I added an input chain:

chain input {
    type filter hook input priority filter; policy accept;

    arp operation request
    arp daddr ip 172.20.200.100
    counter
    drop
    comment "suppress local ARP reply for tap IP"
}

The important distinction is that this blocks local ARP processing while still allowing the ARP broadcast to be bridged onward to OPNsense.

So now:

VM:
Who has .100?

Debian tap:
...

OPNsense:
ME.

The tap still receives routed traffic destined for .100; it simply no longer tells neighboring machines to send Ethernet frames directly to its own MAC.

Making It Persistent

The network tap already had a dedicated native nftables configuration:

/etc/nftables.d/vmdata-l2-guard.nft

loaded by:

/usr/local/sbin/load-vmdata-l2-guard

with a systemd unit:

vmdata-l2-guard.service

So the ARP suppression rule went into the existing guard instead of adding yet another firewall-management mechanism.

That matters because this system also uses iptables-nft rules restored by netfilter-persistent.

One thing I definitely did not want to do was enable the generic /etc/nftables.conf, which currently contains:

flush ruleset

That would make for a very memorable reboot.

Where Things Stand Now

The final behavior is becoming exactly what I wanted:

VM
 ↓
cannot switch directly to another VM
 ↓
physical uplink
 ↓
Debian network tap
 ↓
OPNsense Proxy ARP / routing
 ↓
Debian network tap
 ↓
destination VM

The hypervisor can no longer quietly shortcut VM-to-VM traffic.

The tap sees the traffic.

OPNsense controls the forwarding.

And the VMs remain on the same logical /24.

Five Years Later

Five years later, nearly every physical component in the original diagram has been replaced or upgraded.

One thing has remained remarkably constant: the little Debian bridge icon.

Not the hardware—the machine behind it has changed.

But unlike almost everything else in the lab, its job really hasn’t.

In 2021, that Debian system was already intended to sit inline between the malware environment and the outside network, observing and controlling the traffic that crossed the boundary.

In 2026, that same concept remains at the center of the design.

The infrastructure surrounding it has grown dramatically more sophisticated: Proxmox, OPNsense, dedicated management networks, DMZ collectors, ELK, Logstash, WireGuard, bridge isolation, Proxy ARP, strict firewall policies, and mechanisms specifically designed to prevent the hypervisor from finding a shortcut around the inspection path.

But the fundamental idea represented by that icon has survived all of it:

If the malware wants to communicate with something outside its environment, the traffic goes through the Debian tap.

The hardware changed.

The implementation matured.

The network around it became vastly more complicated.

But apparently the architectural decision I drew in 2021 was the part I got right the first time. 😂

Home network diagram, September 2026

Five Years Later

It has been almost five years since I last posted anything here. My last post was in November 2021, and looking back now, that feels like a completely different point in my life.

At the time, I was working as an Application Analyst. In 2022, I moved into an AWS Ecosystem Team Lead role, and by 2025 I had moved into my current position as an Infrastructure as Code Technical Manager and SME. My work has changed quite a bit along the way. I went from application support, to cloud infrastructure, to spending most of my time around automation, standards, architecture, and technical leadership.

A lot changed outside of work too. My son was born in January 2020, I got my EMT certification in August of that year, and I spent some time with the local rescue squad.

In 2022, I got married, and a seven-year custody dispute finally came to an end with true 50/50 physical custody.

My daughter was born in March 2023. That same year, I was given school placement. In July, I completed the last nighttime police academy offered at the local community college, and a few months later, in October, I joined the local fire department.

I started the nighttime fire academy in January 2024. It took a little over a year to finish, and in February 2025 I became a certified firefighter.

Then February 2026 happened.

While operating at a brush fire, I had a heart attack and went into cardiac arrest. I received CPR, was shocked multiple times with an AED, and was taken to the hospital where a completely blocked LAD was opened and stented. That turned into an ICU stay, kidney failure, dialysis, and several months away from the fire department while I recovered.

That was not on the schedule.

Thankfully, I recovered well enough to eventually return to full firefighting duties.

While all of that was happening, the home lab also changed quite a bit.

This was my network in 2021:

Home network diagram from 2021
Home network, 2021

At the time, the setup centered around an EdgeRouter X, XenServer, a Debian PC acting as a network tap, a FreeBSD VM, VLANs, and a dedicated malware analysis network. It was already much more complicated than a normal home network, but compared to what it looks like now, it was fairly simple.

This is the network today:

Home network diagram from September 2026
Home network, 2026

There are now two separate Internet connections. The normal home network uses 2 Gbps fiber, while the lab has its own 1 Gbps coax connection. The lab side now includes OPNsense, Proxmox, multiple management and data VLANs, Windows Server, dedicated Logstash systems, a Debian network tap, Cisco switching, and several separate management networks.

The home network has expanded too, with dedicated wireless networks, an isolated IoT network, a separate VR network, WireGuard connectivity, and a 10 Gbps connection to my main desktop.

Looking back at the 2021 diagram, I remember thinking that setup was pretty elaborate.

Apparently I was just getting started.

Unlocking the Secrets of Samba: Active Directory

Apparently, Linux’s favorite file sharing service can also double as an Active Directory Domain Controller. I’ve taken two Linux classes and was even a Linux Administrator for many months, and I had no idea this was possible. I stumbled upon this fact because I am looking for a centralized way to manage my user accounts across my entire home lab network.

Since I am using my free AWS Windows server for this site, I had no choice but to find an LDAP server implementation on Linux since AWS gives you a free Windows and Linux server. I spent a good bit of time looking at OpenLDAP, but that will not work since Windows cannot join an OpenLDAP domain. So back to the drawing board I go. I briefly looked at pGINA, but that looks like it hasn’t been updated in almost a decade. Finally, I stumble upon……

Samba.

What? Isn’t that just a file-sharing service???

Apparently not.

Part 1: Pre-Installation

I fire up a RHEL instance within AWS’s EC2, and I get port 389 configured from Windows <-> Linux. I then follow the pre-install instructions on Samba’s site. To set up EPEL on AWS’s RHEL, you need to run the following commands:

sudo dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm -y && sudo dnf config-manager --set-enabled codeready-builder-for-rhel-8-rhui-rpms && sudo yum repolist

Once everything finishes, you should see the EPEL repository in the output of yum repolist. If it is, you can install all the packages needed:

sudo yum install docbook-style-xsl gcc gdb gnutls-devel gpgme-devel jansson-devel keyutils-libs-devel krb5-workstation libacl-devel libaio-devel libarchive-devel libattr-devel libblkid-devel libtasn1 libtasn1-tools libxml2-devel libxslt lmdb-devel openldap-devel pam-devel perl perl-ExtUtils-MakeMaker perl-Parse-Yapp popt-devel python3-cryptography python3-dns python3-gpg python36-devel readline-devel rpcgen systemd-devel tar zlib-devel flex bison dbus-devel python3-markdown wget curl

I have added flex, Bison, dbus-devel, and python3-markdown because Samba’s configure command requires them. We will get to this in a moment.

Now we will need to set a hostname and change our /etc/hosts file. First, to change your hostname, run:

sudo hostnamectl set-hostname yourhostname

Next, get your IP address using:

ip addr show

Then add your hostname and IP address to /etc/hosts using:

sudo vi /etc/hosts

Press the “i” key to enter Insert mode, then use your arrow keys to navigate to the end of the file. Press enter, and add your IP address and new hostname like so:

Your hosts file may make the localhost lines different.

Finally, exit insert mode with Ctrl+C, then type Shift+; (to enter : ), press x, and hit enter. This will save your new hosts change. After making your change, log out and log back in.


Part 2: The Install

If you look on the Distribution-specific Package Installation page, it explicitly states that installing Samba from the repository does not support Active Directory. We can either jettison this RHEL install and move everything to Ubuntu or build from source. Building any software from source is always a challenge, and well, that’s why we’re both here!

First, grab the most up-to-date tar.gz installation files (the most up-to-date version as of this writing is 4.15.2). In my case, it will be:

wget https://download.samba.org/pub/samba/stable/samba-4.15.2.tar.gz && tar -zxf samba-4.15.2.tar.gz && cd samba-4.15.2 && ./configure

The following command with download the tar.gz file, extract its contents, change the directory to the newly extracted folder, and run the ./configure command. For our purpose, we can leave the default configuration options alone. Once the configure command completes, you should get the following:

Success!

Next, run the make command. This will take some time. Once make finishes, you will see:

Another success!

Finally, run the sudo make install command. This will also take some time. Once the install finishes, you will see:

Final success!

Next up is creating the systemd file used to start and stop the Samba Active Directory Domain Controller automatically. Enter the following:

sudo vi /etc/systemd/system/samba-ad-dc.service

Like before, press “i” to enter insert mode, copy and paste the following:

[Unit]
Description=Samba Active Directory Domain Controller
After=network.target remote-fs.target nss-lookup.target

[Service]
Type=forking
ExecStart=/usr/local/samba/sbin/samba -D
PIDFile=/usr/local/samba/var/run/samba.pid
ExecReload=/bin/kill -HUP $MAINPID

[Install]
WantedBy=multi-user.target

Ctrl+C, then type Shift+; (to enter : ), press x, and hit enter. If you try to start Samba now using systemctl start samba-ad-dc, it will fail with the following:

SELinux prevented Samba from running.

Before starting Samba, SELinux will need to be adjusted to allow Samba to run. Run the following command:

chcon -R -t bin_t /usr/local/samba/sbin/

The above command will tell SELinux that Samba is permitted.


Part 3: Post-Install Configuration

Before Samba can be started, we will need to configure it. Begin by running the following commands:

sudo mv /etc/samba/smb.conf /etc/samba/smb.conf.bak ; sudo mv /etc/krb5.conf /etc/krb5.conf.bak

This will rename smb.conf and krb5.conf to a backup as we will be creating a new one soon. Run the following command:

sudo /usr/local/samba/bin/samba-tool domain provision --use-rfc2307 --interactive

This will tell samba-tool to provision a domain using the interactive tool and allow RFC-2307. Without RFC-2307, non-Windows clients would be unable to authenticate with this server. The interactive tool will ask many questions, but you only need to provide the Realm (internal.domain.com) and the administrator password. THE ADMINISTRATOR PASSWORD MUST BE SECURE. The other settings can be left as default. Once you see the following, the tool is complete:

INFO: Samba-Tool is complete.

The last thing that is needed is the following command:

sudo mv /usr/local/samba/private/krb5.conf /etc/krb5.conf && sudo systemctl start samba-ad-dc && sudo systemctl status samba-ad-dc

This command will move the Kerberos configuration file to the correct location, request systemctl to start samba-ad-dc, and output its status. If everything was completed successfully, you should see:

Perfection.

Part 4: Next Steps

Now that Samba’s Active Directory Domain Controller is running, we will need to test our configuration. If the tests are successful, we will need to deploy it to the other clients. That’s Part 2!

Bookshelf & New Homelab Addition

Last week I had to attend my grandfather’s funeral. He was 72 years old and in feeble health when he passed, so he is in a better place now. However, I had the chance to finally clean my storage unit out that I’ve had since 2018! It was a 5’x10′ unit, and the entire contents of the unit was dumped into my house. I finally got a chance to unpack, and I set up my new bookshelf and added new items to my home lab.


Introducing my new home lab!

My home lab

The two major additions are the Commodore 64 plus a disk drive and the TI-99A. I have big plans for the C64, so stay tuned! From bottom to top: HP ProLiant ML350p Gen8, Edgewave iPrism 75g, Dell Poweredge R310, Cisco Catalyst Express 500, a Debian PC used as a network tap, a Windows PC where the motherboard failed, two legacy Windows 98 PCs, a Commodore 64, a TI-99A, and three VGA/DVI monitors


Next up is my bookshelf. Some of these books I already had, but the majority of them came from my storage unit.

Full bookshelf
Full bookshelf
Zoomed to the IT books

These past few weeks have been wild. Beginning in the first week of June, I started a summer research position at North Carolina A&T’s autonomous robotics lab. I had to contribute 160 hours in the lab for the eight-week summer semester. Along with that, I worked full time while pursuing 12 credit hours at the local community college. I am SO glad that it’s over. I can finally get to my home lab projects and then begin a few others. I need to upgrade my uploader service and fully release it. After that, I will do some malware analysis within my analysis lab. Finally, I will sit down and write Part II to the mainframe series.

Running a Bootleg Mainframe from Home: Part I

The only way one can gain legitimate access to a mainframe is by either shelling out five figures or more a year or getting a job supporting a mainframe. Since mainframes are used in 71% of all Fortune 500 companies, it’s not like you have slim pickings to snag a job.

But what if you already have a job and you don’t want to leave?

If you want to be legitimate, you must pay or get a new job.

Surely there must be a way.

Of course there is! It’s 2021 of course. And now your here. You really want to run your own mainframe from the comfort of your home. Sadly, you will have to wait for Part #2.

This post is about the pre-setup for getting a bootleg mainframe running in my home. I will discuss what I’ve been up to in my lab the past couple of days.

A while back, I wrote about how my XenServer did not like installing VMs through PXE Boot. Instead, I had to install it in VMWare Workstation on my main PC, export it, then import it into XenCenter. I have finally upgraded!


I present… Puppy Linux!

Puppy Linux

Puppy Linux is one of the most lightweight Linux distros there is. XenServer can pull ISOs from an NFS or Samba share, so I shared a folder from my Windows PC and set XenServer to boot from the ISO image there. After I installed Puppy Linux, I can freely install VMs from the server.

My current ISO library

As you can see in the picture, my first VM installed this way is Lubuntu. It’s another lightweight Linux distro that will run the z/OS (mainframe) emulator. I have *ahem* acquired a copy of z/OS 1.10 that is floating around the internet. I will then run the mainframe emulator called z/OS Hercules. That will be covered in part 2!

New Malware Analysis Lab

After several weeks and a trip to Goodwill, I have successfully implemented my malware analysis lab as envisioned!


Part I: The Setup

My network is as follows:

Network Diagram

I have the Edgerouter X serving several VLANs, but there are two in particular that I will discuss today. The two ethernet ports on the XenServer serve two purposes: one ethernet port connects to the VLAN aware switch and provides management functions, and the other is used by the VMs for a network connection. This network connection is connected to a Debian PC with two ethernet ports bridged together. That way I can snoop on any network activity silently to the VM. I can also break

Along with this upgraded network, I have revamped all of my firewall settings:

Firewall settings

In this, let’s look at VLAN400 (my PC and its VMs), VLAN325 (XenServer MGMT), and ETH1 (both IN and LOCAL). ETH1 has the largest group of firewall policies (11 in total) than any other network. For IN, it can not communicate with any of the VLANs except for the FreeBSD VM located at 192.168.40.100, but only if it originates on the Debian PC. This way, I can have a full two full virtual layers of protection between this network and the rest of the network. If malware were to escape to my main PC, its chain of infection would be either:

Infected VM -> XenServer itself -> FreeBSD VM -> PC

Or

Infected VM -> Debian PC -> FreeBSD VM -> PC

ETH1-IN Firewall Rules

For ETH1 LOCAL, it has two simple rules: Allow port 53 to the router, and deny everything else. This way, any VMs are unable to attack the switch itself through any of the VLAN IPs.

ETH1-LOCAL firewall rules

VLAN325 (the XenServer MGMT VLAN) has a similar firewall policy. It can only communicate with the FreeBSD VM:

All of this configuration is well and good, but does it work? All the configuration in the world does you no good if it simply doesn’t work in the first place!


Part II: Testing the configuration

Can my PC ping the Debian PC or the XenServer IP in the 10 network?

No.

Can my PC ping the XenServer MGMT IP?

Also nope.

Can the XenVM ping the PC?

Again, nope

Can it ping the 10 network’s switch IP?

Nope!

With our simple ping test, we can conclude that the firewall rules are working as expected. To confirm, I did do an NMAP scan of 192.168.40.* with the following commands:
nmap -T4 -d -v -F -Pn 192.168.40.1 192.168.40.2 192.168.40.10 192.168.40.100

Sure enough, not a single packet returned!

NMAP scan from XenVM

However, the 10 network isn’t so lucky. The switch gateway has DNS open; the Debian PC has ports 7, 9, 13, 21, 22, 25, 37, 53, 79, 80, 110, 113, 990, 995, and 3389 open; and the XenServer has ports 22, 80, and 443 open. I’m sure the iptables firewall could close the XenServer ports, but the open ports on the Debian PC are due to two programs I’ve installed.


Part III: PolarProxy and INetSim

By using this guide, we can capture, intercept, and blackhole any communication between the VM and the outside world. INetSim INetSim is an Internet Services Simulator Suite, and it provides simulation for popular protocols, such as HTTP/S, FTP/S, SMTP/S, and others. PolarProxy is a transparent SSL/TLS proxy created specifically for incident responders. These two programs plus Wireshark will form the backbone of the network analysis for malware, and since this is done off of the victim VM, it is practically undetectable.

PolarProxy and INetSim in action

One thing I do have to investigate is whether or not those SSL errors are fixable. However, that is not a show-stopper in any sort of the imagination! Here is the guide to install both PolarProxy and INetSim.


Part IV: What’s Next?

My first foray into serious malware analysis was in 2019. I was running a Windows VM within VMWare with an active internet connection and shared folders enabled. Fast forward a year and four months later, I have dedicated equipment and a very mature network and firewall setup. I think it has come time to do actual research on my setup and see just how well it can perform. As far as any upgrades to the existing setup, I would like to move the FreeBSD VM to its own PC altogether. After that, I would like to fully physically segment my lab network from everything else. Even up to the point of having its own router!

Tor !

A couple of weeks ago I wrote a one-page paper for a college class that I am about the Clop ransomware. Tonight, I decided to install Tor and try to locate Clop’s leaking site. That was actually very simple as a kind Redditor published a list of the well-known ransomware operators and their PR page. Sadly, since these are onion sites, you need the Tor browser to get to the page. I have never used Tor or installed it in my 27 years of existence.

Until today! And what’s the first onion site I go to?

Clop’s operators PR site

Building an Upload Service

In my last post, I wrote about how I wanted to be a webpage that will allow me to upload files to my server so I can store them for later analysis. Well, Microsoft has graciously written an ASP.NET Core program that does just that! That way, I don’t have to build the entire thing from scratch!

After working on it for about 20 or so minutes, here’s what I have:

Puter Services Malware Upload Center

My idea for this is twofold:

  1. A central storage for malware I find while away from home
  2. The ability to submit the uploaded files automatically to VirusTotal, Hybrid-Analysis, and AppAnyRun so that I don’t have to manually.

After it submits, it will then automatically download the completed report so I can view it later. Finally, it will also send me an email with the results. This way I don’t have to manually upload, keep malicious files on my phone/computer, or keep refreshing a page until I get the results.

This should be completed by the end of this weekend. I plan on livestreaming next time I work on this!

Home Network Upgrade

During the last post, I got to adding a separate network for the malware analysis server to sit on. When I clicked on save and update, the router refused to work correctly. Sadly, I could not get it to stop boot looping or keep the router powered on. After that, I reverted my changes, bought a new router, and prayed that it stayed healthy long enough to switch to the new router.

My new router

I decided on a Ubiquiti EdgeRouter X. Small form factor, able to deliver gigabit speeds, and packed with all the settings I am accustomed to having. I got it plugged in, configured, and tried to change my wireless router to a switch. It totally failed at that point. I then had to buy a new wireless access point.

My new Wireless Access Point

I ended up deciding on a Ubuquiti Unifi AP-AC Lite for my access point needs. It too has the features I am accustomed to having. It made for a simple setup that was painless and user friendly.

Finally, my last goal was to enable VLAN tagging on the AP and the router. After 15 factory resets, I now have VLANs enabled on the router. Woo!

VLAN Setup

It definitely took a while to get everything configured, and I probably should have recorded the steps I took, but the information is out on the internet. Perhaps its a topic for a different day.

What’s Next?

The next pressing matter I have is I want to create a program where I can upload malicious files for later analysis. After that, then I can finish setting up the analysis lab and do the analysis on the Clop sample I located.

Finalizing Malware Analysis Environment

So earlier this week, I went over the creation of my malware analysis lab. Today I will finish setting it up

Part VI: Installing Openvm-tools

Following these directions, I was able to successfully install OpenVM Tools within my FreeBSD environment. It took a couple reboots, but everything worked as expected. It was nice to finally have something work on the first couple tries!

Part VII: Installing Xen Orchestra

This one was pretty easy. Xen Orchestra requires 4GBs of RAM, and a few dependencies specific to FreeBSD. These are:

• gmake
• redis
• python
• git
• npm
• node
• autoconf
• gifsicle
• jpeg-turbo
• optipng
• yarn
• npm
• node

Easily enough, all of these packages can be installed with:

pkg install gmake redis python git npm node autoconf jpeg-turbo optipng gifsicle npm node

After everything is installed, you can then follow the official documentation. Once built, configured, logged in, and attached to your XenServer, it will look like this:

FreeBSD running Xen Orchestra

Part VIII: Implement Firewall Rules

Out of everything in the lab, this is the absolute most important. Without adequate firewall rules, the Windows 7 VM can interact with anything on the network. This is… not good. Especially considering most malware nowadays can spread at the speed of light. So, we will need to implement rules in order to protect everything on the network. Currently, my router acts as my firewall, so we will configure it from there.

The first part is to connect the XenServer to an open port, and assign a new VLAN to it. For my setup, the server is connected to port 3 and I have assigned it VLAN 12:

Buffalo DD-WRT VLAN Page

This will reboot the router, and once the router comes back up, port 3 no longer has access to the network. We can identify this from our previously connected XenCenter reports the XenServer offline:

RIP to XenCenter. It was good while it lasted

Now its time to configure our VLAN. I labeled it “To MAL”, enabled NAT masquerade, net isolation, and assigned an IP address of 10.10.220.1. The DHCP server is set to start at .35 and have a maximum of 5 IPs:

Finally, I have to write the firewall rules, which will have to come later. Until next time!