You are on page 1of 18

SANS SEC 508/526 Laptop Installation Guide Version 6.1.

LAPTOP INSTALLATION GUIDE


SANS Courses SEC508 or SEC526
Version 6.1.5

INTRODUCTION........................................................................ 2
If your BASE OPERATING SYSTEM is Windows: ........................ 3
Step #1 WINDOWS VMWARE CONFIGURATION ........................... 3
Step #2 VMWARE WINDOWS GUEST MACHINE Configuration ........ 5
Step #3 Check GUEST VMware Configuration Settings.................. 6
If your BASE OPERATING SYSTEM is LINUX ............................. 7
Step #1 LINUX VMWARE CONFIGURATION ................................. 7
Step #2 VMWARE WINDOWS GUEST MACHINE Configuration ....... 9
Step #3 Check GUEST VMware Configuration Settings................ 11
If your BASE OPERATING SYSTEM is MAC OSX ....................... 12
Step #1 VMWARE FUSION 1.0 CONFIGURATION........................ 12
Step #2 VMWARE WINDOWS GUEST MACHINE Configuration ..... 15
Step #3 Check GUEST VMware Configuration Settings................ 16
F.A.Q. (Frequently Asked Questions)...................................... 18

Page #1
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

INTRODUCTION
BASE OPERATING SYSTEM
LINUX, MAC OSX, or WINDOWS
Your base operating system can be anything that VMWARE WORKSTATION
runs on or VMWARE FUSION for Intel Based - MAC OSX.

You can use any version of Linux you can install VMware Workstation 6.0 or
higher and it is functional.

VMWARE SERVER is not compatible with the course.

You can use any version of Windows, MAC OSX, or Linux as your core
operating system as long as VMware Workstation or VMware Fusion is
installed and functional. You have to create a Windows VMware guest
machine as a minimum. SANS will be handing out multiple VMware guest
machines that will be utilized for the course.

WARNING: Make sure you bring a hard drive with at least 30 gigabytes of FREE
SPACE.

Mandatory Laptop Hardware Requirements:

• PIII 1Ghz CPU Minimum / M Series 1.5 GHz or higher is recommended


• DVD/CD Combo Drive
• 1 Gigabyte of RAM minimum
• 40 Gigabyte Hard Drive minimum (HARD DRIVE SIZE IS CRITICAL)
• 30 Gigabytes of Free Space on your Hard Drive
• Download and install WINZIP 10 or higher on your Windows Machine
• Bring your INSTALLATION CD-ROMS or DVDs to the course

Recommended Additional Items that are good to have but not necessary for
the class:
1. Portable USB 2.0 or Firewire Hard Drive with ~40 GB or more of free
space
2. Bring one Old/Used IDE, SATA, or Laptop Hard Drive
o Examples
ƒ Hard Drive Purchased from EBAY or Craigslist
ƒ Used Hard Drive PC from home
ƒ Local computer show
ƒ Any extra hard drive lying around
• The hard drive is for an out of class exercise that is optional for
each student and is not required for class in any way. They are
utilized during an optional exercise performed in class to
practice hard drive acquisition back in the students rooms one
night.

Page #2
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

If your BASE OPERATING SYSTEM is Windows:


Step #1 WINDOWS VMWARE CONFIGURATION
Go to http://www.vmware.com and register to download the latest version of
VMware to run under Windows. You can obtain a free 30 day license if you already
do not own a copy of VMware. Download the latest VMware Workstation and
place it in your “My Documents” directory. Do not download VMware Server or any
BETA versions of VMware Workstation for this class they will be incompatible with the
course. Do not download any earlier versions of VMware as the VMware guest
machines we distribute for the course are only compatible with VMware Workstation
6.0 or higher. Use the following guide to help you perform the installation

http://www.vmware.com/support/ws55/doc/ws_install_winhost.html

You need to reset your HOST ONLY NETWORKING SUBNET. To accomplish this
follow these steps.

1. Click START-> ALL-PROGRAMS -> VMWARE -> Manage Virtual Networks

(Note: On Windows machines you might need to “right click” on the above icon
and “RUN-AS” administrator to adjust network settings)

2. Click on the third tab: “Host Virtual Network Mapping”

Page #3
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

3. Click on the VMnet1 Host Adapter Button Configuration

4. Press the “>” button and click on “SUBNET”

5. Change the Subnet IP Address to “192.168.2.0”

6. Click on the fifth tab: “DHCP”

Page #4
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

7. Click “REMOVE” in the DHCP Configuration.


8. Click “APPLY” and reboot your Windows Machine.

Step #2 VMWARE WINDOWS GUEST MACHINE Configuration

Windows 2000, XP, 2003, or Vista


In class, you will make use of a "virtual" Windows machine running within VMware.
Licensing restrictions prevent us from distributing copies of a Windows VMware
image. Therefore, you must create a Windows VMware machine before class begins.
You must use Windows 2000/2003/XP for creating the VMware machine that you will
use during class.

When you start VMWARE follow the following steps to set it up correctly.

1. Start VMWARE
2. Click FILE -> Click NEW -> Click “New Virtual Machine”
3. Choose Typical Settings (CLICK NEXT)
4. Guest OS should be “Windows 2000 Professional”, “Windows XP”,
“VISTA”, or “Windows 2003” (CLICK NEXT)
5. Virtual machine name should be “WINDOWS_VMWARE” (CLICK
NEXT)
6. Location should not be changed (CLICK NEXT)
7. Click “HOST-ONLY NETWORKING” (CLICK FINISH)
8. Disk Capacity: When allocating your VMware Disk Size a 2 GB to 4
GB is recommended. Anything larger is unnecessary. Do not
allocate all disk space now. Do not split disk into 2 GB files.

After you finish your new virtual machine is ready to be installed with the
Windows Operating System.

If you do not have a floppy drive attached to your laptop edit your configuration
settings. On the floppy drive tab, uncheck “connected” and “connect on power
on”. (See #2 Below)

When you first start your VMWARE machine, press F2 to take you into the
VMWARE BIOS Settings. Check to make sure that your first bootable device is
the CDROM so you can install your Windows VMWARE session.

1. Insert the Windows 2000/XP/2003/Vista CD in the CD-ROM drive.


2. Remove the Floppy Drive and Sound Devices from your VMWARE
Settings. (This will slow down your install if it doesn’t find them on
your system.)
3. Power on the virtual machine to start installing Windows
2000/XP/2003/Vista.
4. Follow the installation steps as you would for a physical machine.

Page #5
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

• Install your Windows 2000/XP/2003/Vista System with


the these settings:

9 Filesystem can be formatted as NTFS or FAT32


9 Hard Drive Size should be between 2-4 GB
9 IP Address of the VMWARE machine should be 192.168.2.10
9 Netmask of the machine should be 255.255.255.0
9 Workgroup should be “SANS”
9 System Name should be “WinForensics”
9 File and Print Sharing must be turned on under your network
adapter properties

Step #3 Check GUEST VMware Configuration Settings

1. Open the VMWARE Windows Image


– Press Control-D
– Ensure Network Adapter is “Host-Only”
2. Press Power On Button (looks like play button on VCR)
3. Log in as “Administrator”
4. Press “START” then “Control Panel”
– Double click “Network Connections”
– Right Click on “Local Network Connection” and click “Properties”
– Highlight Internet Protocol (TCP/IP) and click “Properties”
– Click Radio Button “Use the following IP Address”
– Input IP Address 192.168.2.10
– Input Netmask 255.255.255.0
– No Default Gateway is needed
– Do not adjust DNS server
– Press OK then Press OK a second time.
5. “Right click” on My Computer and click “Properties”
– Under the Network Identification Tab
– Ensure workgroup is “SANS”
– Ensure computer name is “winforensics”
6. Open up a command prompt (START -> RUN -> type cmd.exe)
7. Type \\192.168.2.10 and see if you are able to see the machine via
the network.

Please make sure that your VMware environment is stable, and that its host-only
networking is working properly, as there will be no time to install or troubleshoot the
Windows VMware machine during class. Remember to install VMware tools on your
system. VMware support site is located on the web
http://www.vmware.com/support/pubs/ws_pubs.html.

Page #6
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

By bringing the right equipment and preparing in advance, you can maximize what
you'll see and learn, as well as have a lot of fun.

We suggest going over the following checklist before starting the class, to make sure
that your laptop is prepared for the course:

1. The laptop meets hardware requirements EXACTLY as outlined


in this guide
2. VMware Workstation 6.0 or higher is installed (VMware Server
NOT Supported)
3. The VMware license will not expire before the class (if using a
trial copy)
4. You created a Windows 2000/XP/2003/Vista VMware machine
image
5. The Windows VMware machine runs using host-only
networking mode
6. Your Base machine has 30 gigabytes of free space
7. WinZip 10 or higher is installed on your Windows Machines

If your BASE OPERATING SYSTEM is LINUX


Step #1 LINUX VMWARE CONFIGURATION

You can use any version of Linux you can install VMware Workstation 6.0 or
higher and it is functional. You have to create a Windows VMware machine
as a minimum. SANS will be handing out multiple VMware Machines that
will be utilized for the course.

Go to http://www.vmware.com and register to download the latest version of


VMware to run under Linux. You can obtain a free 30 day license if you already do
not own a copy of VMware. Download the latest VMware Workstation 6.0 or
higher rpm and place it in your /usr/local/src directory. Do not download VMware
Server or any BETA versions of VMware for this class they will be incompatible with
the course. Do not download any earlier versions of VMware as the VMware guest
machines we distribute for the course are only compatible with VMware Workstation
6.0 or higher.

From your command line run the following after your VMware rpm is downloaded to
the /usr/local/src directory.

#rpm –ivh VMware-workstation-6.0-45731.i386.rpm (or later


version)

Ensure eth0 is currently not turned on.

#ifdown eth0

Page #7
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

Wait until installation is complete and run the VMware Configuration


Tool.

#vmware-config.pl

Executed the following command and answer the following questions prompted to
you with the response in BOLD. (press return) means press the return key
without typing any value.

Do you accept? (yes/no) yes

Thank you.

Configuring fallback GTK+ 2.4 libraries.

What directory contains your desktop menu entry files? These files
have a .desktop file extension.

[/usr/share/applications] [press return]

In which directory do you want to install the mime type icons?

[/usr/share/icons] [press return]

In which directory do you want to install the application’s icon?

[/usr/share/pixmaps] [press return]

Trying to find a suitable vmmon module for your running kernel.

None of pre-built vmmon modules for VMware Workstation is suitable for


your running kernel. Do you want this program to try to build the
vmmon module for your system (you need to have a C compiler installed
on your system)? [yes] yes

Using compiler "/usr/bin/gcc". Use environment variable CC to override.

What is the location of the directory of C header files that match your
running kernel? [/lib/modules/your_kernel_version/build/include] [press
return]

Do you want networking for your virtual machines? (yes/no/help) [yes]


yes

Optional Question if you have more than one Ethernet adapter: Your
computer has multiple Ethernet network interfaces available: eth0,
eth1. Which one do you want to bridge to vmnet0 [eth0] [press return]

Optional Question if you have more than one Ethernet adapter:Do you
wish to configure another bridged network (yes/no) [press return]
Page #8
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

Configuring a bridged network for vmnet0.

Do you want to be able to use NAT networking in your virtual machine?


[yes] no

Do you want to be able to use host-only networking in your virtual


machines? [no] yes

Do you want this program to probe for an unused private subnet?


(yes/no/help) [yes] no

What will be the IP address of your host on the private network?


192.168.2.1

What will be the netmask of your private network? 255.255.255.0

Do you wish to configure another host-only network? (yes/no) [no] no

Do you want this program to automatically configure your system to


allow your virtual machines to access the host's filesystem?
(yes/no/help) [no] no

Do you want to install the Eclipse Integrated Virtual Debugger [no] no

Do you accept? (yes/no) yes

[press return] for all VMware VIX API questions

EXECUTE THE VMWARE MACHINE #ifconfig

Check to see if vmnet1 is configured to 192.168.2.1 and eth0 and/or is


anything BUT 192.168.2.1. If vmnet1 and eth0/1 are configured to the
same network, a routing loop will occur and you will not have connectivity.
Re-run vmware-config.pl until you verify that vmnet1 is set to 192.168.2.1.

# vmware &

Step #2 VMWARE WINDOWS GUEST MACHINE Configuration


Windows 2000, XP, 2003, or Vista
In class, you will make use of a "virtual" Windows machine running within VMware.
Licensing restrictions prevent us from distributing copies of a Windows VMware
image. Therefore, you must create a Windows VMware machine before class begins.
You must use Windows 2000/2003/XP for creating the VMware machine that you will
use during class.

When you start VMWARE follow the following steps to set it up correctly.

Page #9
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

1. Start VMWARE
2. Click FILE -> Click NEW -> Click “New Virtual Machine”
3. Choose Typical Settings (CLICK NEXT)
4. Guest OS should be “Windows 2000 Professional”, “Windows XP”,
“VISTA”, or “Windows 2003” (CLICK NEXT)
5. Virtual machine name should be “WINDOWS_VMWARE” (CLICK NEXT)
6. Location should not be changed (CLICK NEXT)
7. Click “HOST-ONLY NETWORKING” (CLICK FINISH)
8. Disk Capacity: Do not allocate a disk larger than 4 GB. Do not
allocate all disk space now. Do not split disk into 2 GB files.

After you finish your new virtual machine is ready to be installed with the
Windows Operating System.

If you do not have a floppy drive attached to your laptop edit your configuration
settings. On the floppy drive tab, uncheck “connected” and “connect on power
on”. (See #2 Below)

When you first start your VMware machine, press F2 to take you into the
VMWARE BIOS Settings. Check to make sure that your first bootable device is
the CDROM so you can install your Windows VMWARE session.

1. Insert the Windows 2000/XP/2003/Vista CD in the CD-ROM drive.


2. Remove the Floppy Drive and Sound Devices from your VMWARE
Settings. (This will slow down your install if it doesn’t find them on
your system.)
3. Power on the virtual machine to start installing Windows
2000/XP/2003/Vista.
4. Follow the installation steps as you would for a physical machine.
5. When allocating your VMware Disk Size a 2 GB to 4 GB is recommended.
Anything larger is unnecessary.

• Install your Windows 2000/XP/2003/Vista System with


the these settings:

9 Filesystem can be formatted as NTFS or FAT32


9 Hard Drive Size should be between 2-4 GB
9 IP Address of the VMWARE machine should be 192.168.2.10
9 Netmask of the machine should be 255.255.255.0
9 Workgroup should be “SANS”
9 System Name should be “WinForensics”
9 File and Print Sharing must be turned on under your network
adapter properties

Page #10
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

Step #3 Check GUEST VMware Configuration Settings

1. Open the VMWARE Windows Image


1. Press Control-D
2. Ensure Network Adapter is “Host-Only”
2. Press Power On Button (looks like play button on VCR)
3. Log in as “Administrator”
4. Press “START” then “Control Panel”
1. Double click “Network Connections”
2. Right Click on “Local Network Connection” and click “Properties”
3. Highlight Internet Protocol (TCP/IP) and click “Properties”
4. Click Radio Button “Use the following IP Address”
5. Input IP Address 192.168.2.10
6. Input Netmask 255.255.255.0
7. No Default Gateway is needed
8. Do not adjust DNS server
9. Press OK then Press OK a second time.
5. “Right click” on My Computer and click “Properties”
1. Under the Network Identification Tab
2. Ensure workgroup is “SANS”
3. Ensure computer name is “winforensics”
6. Open up a command prompt (START -> RUN -> type cmd.exe)
7. Type \\192.168.2.10 and see if you are able to see the machine via
the network.

Please make sure that your VMware environment is stable, and that its host-only
networking is working properly, as there will be no time to install or troubleshoot the
Windows VMware machine during class. Remember to install VMware tools on your
system. One way to verify that the VMware host-only network is active is to check
whether you can see the Windows VMware machine (192.168.2.10) from your linux
machine. VMware support site is located on the web
http://www.vmware.com/support/pubs/ws_pubs.html.

By bringing the right equipment and preparing in advance, you can maximize what
you'll see and learn, as well as have a lot of fun.

We suggest going over the following checklist before starting the class, to make sure
that your laptop is prepared for the course:

1. The laptop meets hardware requirements EXACTLY as outlined in this


guide
2. VMware Workstation 6.0 or higher is installed (VMware Server NOT
Supported)
3. The VMware license will not expire before the class (if using a trial
copy)
4. You created a Windows 2000/XP/2003/Vista VMware machine image

Page #11
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

5. The Windows VMware machine runs using host-only networking


mode
6. Your Base machine has 30 gigabytes of free space
7. WinZip 10 or higher is installed on your Windows Machines

If your BASE OPERATING SYSTEM is MAC OSX


Step #1 VMWARE FUSION 1.0 CONFIGURATION

You can use any version of Intel Based MAC OSX you can install VMware
Fusion 1.0 on and it is functional. No beta versions are supported. You
have to create a Windows VMware machine as a minimum. SANS will be
handing out multiple VMware Machines that will be utilized for the course.

Go to http://www.vmware.com/products/fusion/ and register to download the latest


version of VMware Fusion to run under MACOSX. You can obtain a free 30 day
license if you already do not own a copy of VMware Fusion. Download the latest
VMware Fusion 1.0 or higher dmg. Do not download any BETA versions of VMware
Fusion for this class they will be incompatible with the course.

The following is from the site:


http://www.vmware.com/community/servlet/JiveServlet/download/371-96095-
712040-1280/VMware%20Fusion%20Network%20Settings%20-%20Part%201.pdf

The above link discusses how to manually configure your network adapters which I
have added to this guide below. It is critical that you follow the instructions below
STEP BY STEP in order to get your version of VMware FUSION compatible with the
class.

One of the areas that have been simplified in the first release of VMware
Fusion is the configuration of the virtual network settings. Similar to the
Windows and Linux hosted variants for VMware products, there are 2
network interfaces setup during the installation of Fusion, plus a bridge from
Fusion to the computer’s active NIC. The 2 virtual network cards that are
configured are the host-only network, vmnet1, and the NAT network
interface, vmnet8. To learn more about these configurations I would suggest
that the documentation for VMware Workstation 6 networking is read, as
Fusion is derived from the same codebase. See the VMware Workstation 6
online manual and specifically the section on “Configuring a Virtual Network”,
and especially the parts relating to Linux.

What Fusion doesn’t easily let you do is manually configure the IP address
ranges used by vmnet1 and vmnet8, or add additional virtual networks; e.g.
vmnet2, etc. This first article demonstrates how to change the Fusion
network settings, allowing the IP address range to be specified for the default
connections. Before we start the process we need to understand a few of the
files used to configure Fusion. In the “/Library/Application Support/VMware
Page #12
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

Fusion/” directory are several files and sub-directories important to the


Fusion application.

Part 1 – Reset Fusion Settings


The first stage is to ensure we are at a known state with the various files
used by Fusion. Before you start, please ensure you have no running guests
and that you have closed the fusion application. The simplest way to do this
is to remove the “locations” file and re-run the Perl configuration script. Start
a terminal session and then switch to the main directory for Fusion. We will
then remove the file:

$cd /Library/Application\ Support/VMware\ Fusion/


$sudo rm locations

Next is to run the Perl configuration script, which will regenerate all the relevant files:

$sudo ./vmware-config-net.pl

Page #13
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

You won’t need to answer any questions as the vmware-config-net.pl script


auto answers them for you. Next we want to restart the services with these
new values just to check that everything is working:

$sudo ./boot.sh --restart

Part 2 – Modify the IP address ranges


We should now have a clean “locations” file to work from. Using an editor,
such as vi, open the file with write permissions via sudo or as root user, if
you have enabled the account. We need to change the following lines

answer VNET_1_HOSTONLY_HOSTADDR 192.168.2.1


answer VNET_1_HOSTONLY_SUBNET 192.168.2.0

Here vi is being run under sudo:

$sudo vi locations

You only need to worry about the two lines in red below.

answer LIBDIR /Library/Application Support/VMware Fusion


answer NETWORKING yes
answer VNET_8_NAT yes
answer VNET_8_HOSTONLY_HOSTADDR 172.16.8.1
answer VNET_8_HOSTONLY_NETMASK 255.255.255.0
file /Library/Application Support/VMware Fusion/vmnet8/dhcpd.conf 1185970219
file /var/db/vmware/vmnet-dhcpd-vmnet8.leases
file /var/db/vmware/vmnet-dhcpd-vmnet8.leases~
file /Library/Application Support/VMware Fusion/vmnet8/nat.conf 1185970219
answer VNET_1_HOSTONLY_HOSTADDR 192.168.2.1
answer VNET_1_HOSTONLY_NETMASK 255.255.255.0
answer VNET_1_HOSTONLY_SUBNET 192.168.2.0
answer VNET_1_DHCP yes
file /Library/Application Support/VMware Fusion/vmnet1/dhcpd.conf 1185970239
file /var/db/vmware/vmnet-dhcpd-vmnet1.leases
file /var/db/vmware/vmnet-dhcpd-vmnet1.leases~
file /Library/Application Support/VMware Fusion/config 1185970239

Part 3 – Apply modified settings

Finally, we run through the same sequence of commands as in Step 1 to


apply the settings to Fusion. First, run the Perl configuration script, which will
show slightly different output this time.

$sudo ./vmware-config-net.pl

$sudo ./boot.sh --restart

$ifconfig -a
Page #14
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

< Removed other output for simplicity >


vmnet1: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu
1500
inet 192.168.2.1 netmask 0xffffff00 broadcast 192.168.2.255
ether 00:50:56:c0:00:01

You should now be able to start Fusion and power on guests, and make use of the re-configured
virtual networking.

Step #2 VMWARE WINDOWS GUEST MACHINE Configuration

Windows 2000, XP, 2003, or Vista


In class, you will make use of a "virtual" Windows machine running within VMware.
Licensing restrictions prevent us from distributing copies of a Windows VMware
image. Therefore, you must create a Windows VMware machine before class begins.
You must use Windows 2000/2003/XP for creating the VMware machine that you will
use during class.

When you start VMWARE follow the following steps to set it up correctly.

1. Start VMWARE
2. Click FILE -> Click NEW -> Click “New Virtual Machine”
3. Choose Typical Settings (CLICK NEXT)
4. Guest OS should be “Windows 2000 Professional”, “Windows XP”,
“VISTA”, or “Windows 2003” (CLICK NEXT)
5. Virtual machine name should be “WINDOWS_VMWARE” (CLICK NEXT)
6. Location should not be changed (CLICK NEXT)
7. Click “HOST-ONLY NETWORKING” (CLICK FINISH)
8. Disk Capacity: Do not allocate a disk larger than 4 GB. Do not
allocate all disk space now. Do not split disk into 2 GB files.

After you finish your new virtual machine is ready to be installed with the
Windows Operating System.

If you do not have a floppy drive attached to your laptop edit your configuration
settings. On the floppy drive tab, uncheck “connected” and “connect on power
on”. (See #2 Below)

When you first start your VMware machine, press F2 to take you into the
VMWARE BIOS Settings. Check to make sure that your first bootable device is
the CDROM so you can install your Windows VMWARE session.

1. Insert the Windows 2000/XP/2003/Vista CD in the CD-ROM drive.

Page #15
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

2. Remove the Floppy Drive and Sound Devices from your VMWARE
Settings. (This will slow down your install if it doesn’t find them on
your system.)
3. Power on the virtual machine to start installing Windows
2000/XP/2003/Vista.
4. Follow the installation steps as you would for a physical machine.
5. When allocating your VMware Disk Size a 2 GB to 4 GB is recommended.
Anything larger is unnecessary.

• Install your Windows 2000/XP/2003/Vista System with


the these settings:

9 Filesystem can be formatted as NTFS or FAT32


9 Hard Drive Size should be between 2-4 GB
9 IP Address of the VMWARE machine should be 192.168.2.10
9 Netmask of the machine should be 255.255.255.0
9 Workgroup should be “SANS”
9 System Name should be “WinForensics”
9 File and Print Sharing must be turned on under your network
adapter properties

Step #3 Check GUEST VMware Configuration Settings

1. Open the VMWARE Windows Image


1. Press Control-D
2. Ensure Network Adapter is “Host-Only”
2. Press Power On Button (looks like play button on VCR)
3. Log in as “Administrator”
4. Press “START” then “Control Panel”
1. Double click “Network Connections”
2. Right Click on “Local Network Connection” and click “Properties”
3. Highlight Internet Protocol (TCP/IP) and click “Properties”
4. Click Radio Button “Use the following IP Address”
5. Input IP Address 192.168.2.10
6. Input Netmask 255.255.255.0
7. No Default Gateway is needed
8. Do not adjust DNS server
9. Press OK then Press OK a second time.
5. “Right click” on My Computer and click “Properties”
1. Under the Network Identification Tab
2. Ensure workgroup is “SANS”
3. Ensure computer name is “winforensics”
6. Open up a command prompt (START -> RUN -> type cmd.exe)
7. Type \\192.168.2.10 and see if you are able to see the machine via
the network.

Page #16
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

Please make sure that your VMware environment is stable, and that its host-only
networking is working properly, as there will be no time to install or troubleshoot the
Windows VMware machine during class. Remember to install VMware tools on your
system. One way to verify that the VMware host-only network is active is to check
whether you can see the Windows VMware machine (192.168.2.10) from your MAC
machine. VMware support site is located on the web
http://www.vmware.com/support/fusion/doc/releasenotes_fusion.html

By bringing the right equipment and preparing in advance, you can maximize what
you'll see and learn, as well as have a lot of fun.

We suggest going over the following checklist before starting the class, to make sure
that your laptop is prepared for the course:

1. The laptop meets hardware requirements EXACTLY as outlined in this


guide
2. VMware Fusion 1.0 or higher is installed (VMware Fusion Beta is NOT
Supported)
3. The VMware license will not expire before the class (if using a trial
copy)
4. You created a Windows 2000/XP/2003/Vista VMware machine image
5. The Windows VMware machine runs using host-only networking
mode
6. Your Base machine has over 30 gigabytes of free space
7. WinZip 10 or higher is installed on your Windows Machine

Page #17
SANS SEC 508/526 Laptop Installation Guide Version 6.1.5

F.A.Q. (Frequently Asked Questions)


1. Is it legal to download the demos of VMWARE for this use? VMware
has a 30 day demo license that you can obtain specifically for this course.

2. Can I use an earlier version of VMware, such as 3, 4, or 4.5?


VMware does not grandfather previous versions of their tools virtual machine
in many cases. It is essential to require the specific version of VMware to
ensure compatibility with the course.

3. Can I use VMWARE SERVER? VMWARE SERVER does not work with the
course as it does not support reverting from snapshots.

4. I have VISTA and I cannot input my license key? When you install
Workstation on a Windows Vista host, be sure to enter the serial number at
installation time. This is necessary so that when you enter the serial number,
you will have the required permission settings. If you enter the serial number
later, as a different user, you might not have the correct permissions.

6. Can I use VMWARE FUSION for MACOS? VMWARE FUSION now


supports host-only networking. The product was just released supported by
the class. However, since it is new, it is bound to have bugs. Students who
bring VMWARE FUSION to class will potentially have more problems than
those with Linux or Window.

Page #18

You might also like