I have setup a cluster in Proxmox to start building out a general IT and Security lab. I will be documenting the process as I go forward, and I will detain some of my experiences within the lab.
First I am running two Dell Optiplex’s as Proxmox Servers, I have two switches (Netgear, and TP-link), and a Purple Firewalla. I am in the process of building a NAS for the lab that will be added at the bottom of the lab rack.
I am using a Tec Mojo 10inch 10 U rack. I have additional shelves coming to better accommodate the equipment.
The goal with the lab rack is to get a decent enough lab setup similarly to a full scale rack setup. This will allow me to run VMs and Containers to simulate the services small to medium businesses may run, in both a vulnerable state and a secured state scenarios.
I will be setting up vulnerable services to practice my red teaming, detection & response for Incident management & incident response scenarios, secure configuration, documentation & report writing utilizing logging and SIEM or other SOC tools.
Lag Planned install and setup:
Phase 1 Core Lab (Server for VM & Containers backbone, AD, Firewall and DNS services)
- Proxmox
- OPNsense
- AD
- WireGuard
- Pi-hole
Phase 2 Identity Management, SSO, Proxy & Monitoring, and SIEM
- Wazuh
- Authentik
- Traefik
- Grafana
Phase 3 Automation and Documentation
- Gitea
- N8N
Phase 4 Security Training (vulnerable by design)
- Juice Shop
- DVWA
- Metasploitable
- WebGoat
- VulnHub
- redStack