0

Dave here

I'm building a concept for a customer and they want to build a dev environment for their small business network. This is for pen testing, and as close as they can virtualized version of their physical infrastructure.

They have two pretty decent servers each with 6 NIC's, a Synology with plenty of disk for this project and a 24 port Cisco switch. The pen testers will plug their physical hosts into the switch and the security team want to attach a SIEM with a SPAN on one of the ports of the virtualized routers. I think I can do this with TaaS but more reading required, if not I'll have to virtualize a server for them to receive traffic on and forward it somehow.

I'm sure it will but would an Openstack run Controller+Compute on server A and Compute on server B with a Cinder store on the Synology? Any reference architecture you could point me at?

There would be the pen testers hitting a virtualized firewall in a DMZ with 2 VMs, then out from there to their server or client networks that would have say 5 Windows VMs in each using? I'm thinking there would be max 20 VMs worst case if I multi-NIC a couple of virtual routers like pfsense or similar to replicate their network fully.

I guess like a cyber range but without user/network simulation.

I'm saying do it on AWS but they insist on having it on the hardware they have left over from other projects (no ESX licensing).

Am I heading in the right direction with this? Both servers are the same spec 24 core 128g ram with 100gb spinning disk and then 4TB in Synology.

Sorry english not first language ,

Cheers Dave

berndbausch
  • 973
  • 7
  • 11
Dave
  • 1
  • In principle it works but my first thought is that OpenStack is too complex for a two-node installation and 20-30 VMs. Use something simpler like oVirt or Proxmox (disclosure: I know OpenStack a little but not the others). Are you sure, 100GB disk space? This might be a bit tight. I have no idea about the network attachment needs. Final comment: With all the quirky spellings, I was convinced you were a native English speaker :) (that 's meant to be a compliment from another non-native speaker). – berndbausch Mar 11 '21 at 11:50
  • In terms of architecture reference, the [manual installation guide](https://docs.openstack.org/install-guide/) sets up a two-node cloud with Cinder. It's more a learning tool than a serious cloud setup, but sheds light on many details. – berndbausch Mar 11 '21 at 11:54
  • Great thanks for the feedback , yes OpenStack selection is just something I would like to learn more about for any future jobs I have for customer. I will keep falling down the rabbit hole of discovery here – Dave Mar 11 '21 at 17:18

0 Answers0