VMWare Workstation Player/Pro Installation Guide: Difference between revisions

no edit summary
No edit summary
Line 1: Line 1:
This guide describes how the Allegro Network Multimeter Virtual Edition can be set up with VMWare Workstation. The Allegro Virtual Edition is designed for 2 use cases. It can analyze [[Parallel Packet processing|pcap captures]] or [[Ring Buffer Configuration Guide|packet ring buffers]] of unlimited size for forensic investigation or it can analyze live traffic from virtual machines by a virtual Mirror Port or [[ERSPAN Installation|ERSPAN]].
This Guide describes how the Allegro Network Multimeter Virtual Edition can be set up with VMWare Workstation. The Allegro Virtual Edition is designed for 2 use cases. It can analyze [[Parallel Packet processing|pcap captures]] or [[Ring Buffer Configuration Guide|packet ring buffers]] of unlimited size for forensic investigation or it can analyze live traffic from virtual machines by a virtual Mirror Port or [[ERSPAN Installation|ERSPAN]].


== General ==
== General ==
Line 9: Line 9:
=== System requirements ===
=== System requirements ===


This guide requires a VMWare Workstation Player or Pro. 15.5.2 or newer. Please note that the non-commercial version (VMWare Workstation Player) also works with Allegro Virtual Edition if you are testing it for personal use only. Please review the license restrictions of the VMWare Workstation Player.
This Guide requires a VMWare Workstation Player or Pro. 15.5.2 or newer. Note that the non-commercial version (VMWare Workstation Player) also works with Allegro Virtual Edition if you are testing it for personal use only. Please review the license restrictions of the VMWare Workstation Player.


The system requirement of the virtual machine is:
The system requirement of the virtual machine is:
Line 19: Line 19:
=== Virtual Machine image ===
=== Virtual Machine image ===


Please contact [https://allegro-packets.com/en/contact Allegro] or your reseller to download the current Allegro Virtual Edition installation zip archive.
Contact [https://allegro-packets.com/en/contact Allegro] or your reseller to download the current Allegro Virtual Edition installation zip archive.


== Installation ==
== Installation ==
Line 25: Line 25:
=== Zip file extraction ===
=== Zip file extraction ===


Please extract the zip archive. It should contain the 3 files “allegro-multimeter.ovf”, “allegro-multimeter.vmdk” and “allegro-multimeter-virtualbox.ovf”. 
Extract the zip archive. It should contain the 3 files “allegro-multimeter.ovf”, “allegro-multimeter.vmdk” and “allegro-multimeter-virtualbox.ovf”. 


=== OVF deployment to VMWare Workstation ===
=== OVF deployment to VMWare Workstation ===
Line 37: Line 37:
[[File:Workstation player import.png|600px]]
[[File:Workstation player import.png|600px]]


Now specify the location on your disk, set a name and import the VM.
Next, specify the location on your disk, set a name and import the VM.


[[File:Workstation player import 2.png|600px]]
[[File:Workstation player import 2.png|600px]]


The Allegro Virtual Edition is being imported. Once this is done, you can edit the settings of the VM. Please note that the first interface is used for the Management Access and requires a network with DHCP server. The second network port is used as data plane. The Allegro Virtual Edition analyzes all traffic on this network port. By default, both ports are bridged to your local network. You can change the first port to NAT to allow only access from your local PC. You can also change the settings later at any time.
The Allegro Virtual Edition will be imported. Once this is complete, you can edit the settings of the VM. Note that the first interface is used for the Management Access and requires a network with a DHCP server. The second network port is used as a data plane. The Allegro Virtual Edition analyzes all traffic on this network port. By default, both ports are bridged to your local network. You can change the first port to NAT to allow only access from your local PC. You can also change the settings later at any time.


[[File:Workstation player settings.png|600px]]
[[File:Workstation player settings.png|600px]]
Line 47: Line 47:
=== Install USB License dongle ===
=== Install USB License dongle ===


If the Allegro Virtual Edition is shipped with an USB License dongle, plug the dongle into an unused USB port of the VM host. The dongle must be connected to the virtual machine. When powered off, edit the settings of the VM and add the USB dongle to it. Please select a “Feitian HID Dongle” or similar.
If the Allegro Virtual Edition was shipped with an USB License dongle, plug the dongle into an unused USB port of the VM host. The dongle must be connected to the virtual machine. When powered off, edit the settings of the VM and add the USB dongle to it. Select a “Feitian HID Dongle” or similar.


== Initial startup ==
== Initial startup ==


Please follow the [[VMWare ESXI Installation Guide#Initial startup]]. The Startup is identical for ESXI and Workstation.
Follow the [[VMWare ESXI Installation Guide#Initial startup]]. The Startup is identical for ESXI and Workstations.


== Mirroring virtual interface ==
== Mirroring virtual interface ==
Line 57: Line 57:
The Allegro Virtual Edition has by default 2 network interfaces. The first port is used for Management, the second is used as capture port. The Allegro Virtual Edition will analyze all traffic received by this network port.
The Allegro Virtual Edition has by default 2 network interfaces. The first port is used for Management, the second is used as capture port. The Allegro Virtual Edition will analyze all traffic received by this network port.


Please enable the promiscuous mode for the second port if you would like to analyze all incoming packets. As of now, this configuration cannot be done in the VMWare Workstation GUI and it does not work for all physical interfaces.
Enable the promiscuous mode for the second port if you would like to analyze all incoming packets. As of now, this configuration cannot be done in the VMWare Workstation GUI and it does not work for all physical interfaces.


Please navigate to your directory of the VMWare (by default: Documents\Virtual Machines) and edit the vmx file. There add the line: "ethernet1.noPromisc = "FALSE"
Navigate to your directory of the VMWare (by default: Documents\Virtual Machines) and edit the vmx file. There add the line: "ethernet1.noPromisc = "FALSE"


[[File:Workstation player promisc mode.png|600px]]
[[File:Workstation player promisc mode.png|600px]]
Line 67: Line 67:
You can add one or multiple virtual disks to the Allegro Virtual Edition.
You can add one or multiple virtual disks to the Allegro Virtual Edition.


When powered off, edit the settings of the virtual Machine and add press the "Add..." Button.
When powered off, edit the settings of the virtual machine and add click the "Add..." Button.


[[File:Workstation player add hard disk.png|600px]]
[[File:Workstation player add hard disk.png|600px]]
Line 75: Line 75:
[[File:Workstation player select scsi.png|600px]]
[[File:Workstation player select scsi.png|600px]]


Then select new disk or use an existing one.
Next, select new disk or use an existing one.


[[File:Workstation player create new disk.png|600px]]
[[File:Workstation player create new disk.png|600px]]


If you have selected a new disk, set the size in the next dialogue.  
If you selected a new disk, set the size in the next dialogue.  


[[File:Workstation player select size.png|600px]]
[[File:Workstation player select size.png|600px]]


Now review the configuration and finish it. Once it is done, please start the Allegro Virtual Edition.
Next, review the configuration and complete it. Once it is done, start the Allegro Virtual Edition.
If done, you can enable the packet ring buffer as described in [[Ring Buffer Configuration Guide]].
If done, you can enable the packet ring buffer as described in [[Ring Buffer Configuration Guide]].
Please note that a real-time capture of packets require high write rates to your storage device. Please use dedicated disks for the ring buffer to avoid performance issues on other virtual machines.
Note that a real-time capture of packets require high write rates to your storage device. We recommend you use dedicated disks for the ring buffer to avoid performance issues on other virtual machines.


== Encapsulated remote mirroring (L3) source ==
== Encapsulated remote mirroring (L3) source ==


The Allegro Virtual Edition supports the VMware '''Encapsulated remote mirroring (L3) source''' with the [[ERSPAN Installation|ERSPAN Mode]]. You can set up an IP address on the capture port and send encapsulated packets to the Allegro. Please see the Vsphere documentation center for Encapsulated remote mirroring (L3) source.
The Allegro Virtual Edition supports the VMware '''Encapsulated remote mirroring (L3) source''' with the [[ERSPAN Installation|ERSPAN Mode]]. You can set up an IP address on the capture port and send encapsulated packets to the Allegro. See the Vsphere documentation center for Encapsulated remote mirroring (L3) source.
inactive
369

edits