VMware Communities
seregg
Contributor
Contributor
Jump to solution

vm network scan

hello, how to hide network scanning? on the screen, a program is running on a virtual machine that scans networks and it shows all the VMs on the computer, and even the physical one and all of their MAC addresses. how to avoid this, how to disable vm detection?

0 Kudos
1 Solution

Accepted Solutions
continuum
Immortal
Immortal
Jump to solution

Look here https://sanbarrow.com/transparentbridge.html
I explained a procedure that prevents that one of your VMs can scan another VM while both can scan your local router (192.168.1.1 in your case.
It requires one extra VM and several additional vmnets.
I wonder whats the reason for your request - most users assume that their own VMs are friendly to other local VMs.

Do you use firewalls inside your VMs ?
Do you really assume that I can scan your 192.168.1.* IPs from here (germany) ?

Ulli

 


________________________________________________
Do you need support with a VMFS recovery problem ? - send a message via skype "sanbarrow"
I do not support Workstation 16 at this time ...

View solution in original post

19 Replies
scott28tt
VMware Employee
VMware Employee
Jump to solution

I would suggest learning more about networking in Workstation Pro: https://docs.vmware.com/en/VMware-Workstation-Pro/16.0/com.vmware.ws.using.doc/GUID-0CE1AE01-7E79-41...

Your options would depend on what you DO and DO NOT want to scan.

 


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
0 Kudos
ravipadigela
Enthusiast
Enthusiast
Jump to solution

  1. There is a way you can connect to through custom network adapter, which is no internet connection to vm, you can specify which vm's to be connect.
  2. you want internet connection NAT connection is a type, it is access your host network and all NAT Connection VM's other than all router connections.

ravipadigela_0-1651847167297.png

ravipadigela_1-1651847225487.png

 

0 Kudos
continuum
Immortal
Immortal
Jump to solution

The purpose of a network-scanner is to find all items inside the network range you specified.
A computer that does not want to be detectable by such a scan needs to operate a firewall that then lets the incoming scan-packets timeout.
Your question is similar to a man that opens his eyes inside a wood and then complains about seeing so many trees.

Can you please explain what you want to see instead ?

Ulli


________________________________________________
Do you need support with a VMFS recovery problem ? - send a message via skype "sanbarrow"
I do not support Workstation 16 at this time ...

0 Kudos
seregg
Contributor
Contributor
Jump to solution

the firewall does not help, I checked first of all, the firewall will close the ports, and there is another system, you try at the beginning, then you say.

0 Kudos
continuum
Immortal
Immortal
Jump to solution

Please try to explain what you want to see when you scan your local network.

Ulli


________________________________________________
Do you need support with a VMFS recovery problem ? - send a message via skype "sanbarrow"
I do not support Workstation 16 at this time ...

0 Kudos
seregg
Contributor
Contributor
Jump to solution

Have you seen my screenshot from the first post? all virtual machines with poppy addresses are displayed there, they were detected by a scanner running on one of these machines and they can be linked that they are all from the same host network, you need to prevent detection.

0 Kudos
continuum
Immortal
Immortal
Jump to solution

Of course I have seen your screenshot - thats why I asked those questions.
Take mspaint or whatever and show me what the same sscan should display - then I can try to offer options.

Ulli

 


________________________________________________
Do you need support with a VMFS recovery problem ? - send a message via skype "sanbarrow"
I do not support Workstation 16 at this time ...

0 Kudos
seregg
Contributor
Contributor
Jump to solution

it should not find other VM with mac addresses, complete isolation is needed with Internet access for 8 VM so that they do not see each other.

0 Kudos
seregg
Contributor
Contributor
Jump to solution

Method 1 is not suitable, I need internet.

2 way NAT also scans all machines

0 Kudos
continuum
Immortal
Immortal
Jump to solution

You want complete isolation ? - may I assume that you mean that your VMs are invisible to scans done with simple IP-scanners ?
That depends on your setup.
At the moment I assume that 192.168.1.1 is your local router and ETAXOG is your Windows-host.
All other IPs are used by VMs.
All your VMs use bridged vmnet0.
Is that correct ?

Are you paying for one internet connection ( one public IP) or are you rich and can afford paying for 8 public IPs ?
By the way - visit https://www.whatsmyip.org/
and find out that all your VMs use the same IP.
And in case you are not aware of - you use the same IPs and MAC addresses that I use here ....

Ulli

 


________________________________________________
Do you need support with a VMFS recovery problem ? - send a message via skype "sanbarrow"
I do not support Workstation 16 at this time ...

0 Kudos
seregg
Contributor
Contributor
Jump to solution

almost true, only ETAXOG is the vm with which the scan was launched, the machines use a bridge yes, that’s right, all vm have different ip through a proxy and the poppy address has been replaced, by scanning one you can determine that they all belong to me.

0 Kudos
continuum
Immortal
Immortal
Jump to solution

> by scanning one you can determine that they all belong to me.
No - they belong to me.

LOL - that was funny.
I never heard the term poppy address - do you mean public address ?

Ulli


________________________________________________
Do you need support with a VMFS recovery problem ? - send a message via skype "sanbarrow"
I do not support Workstation 16 at this time ...

0 Kudos
ravipadigela
Enthusiast
Enthusiast
Jump to solution

if you need internet connection means exposing the vm in network, so the advance scanner definitely scan  all your VM's which is available in network.

any how you don't want scan remaining which have this scanner isolate it with different ip pool, it doesn't know ip's of other machines.

0 Kudos
seregg
Contributor
Contributor
Jump to solution

mac - gogle translate((( 

0 Kudos
continuum
Immortal
Immortal
Jump to solution

Look here https://sanbarrow.com/transparentbridge.html
I explained a procedure that prevents that one of your VMs can scan another VM while both can scan your local router (192.168.1.1 in your case.
It requires one extra VM and several additional vmnets.
I wonder whats the reason for your request - most users assume that their own VMs are friendly to other local VMs.

Do you use firewalls inside your VMs ?
Do you really assume that I can scan your 192.168.1.* IPs from here (germany) ?

Ulli

 


________________________________________________
Do you need support with a VMFS recovery problem ? - send a message via skype "sanbarrow"
I do not support Workstation 16 at this time ...

seregg
Contributor
Contributor
Jump to solution

according to the link there linux, I have windows
I do not use a firewall, but I checked that if you close everything tightly, it is scanned anyway.

0 Kudos
continuum
Immortal
Immortal
Jump to solution

I used a Windows host too - only the firewall VM used Linux / OpenBSD.
I would say that your request simply makes no sense - nobody outside your local network can address IPs from the private range.
And if you have the enemy inside your local network then your case is hopeless anyway.

Ulli

 


________________________________________________
Do you need support with a VMFS recovery problem ? - send a message via skype "sanbarrow"
I do not support Workstation 16 at this time ...

0 Kudos
Slav2
Contributor
Contributor
Jump to solution

Need to create several "host-only" networks (vmnet1, vmnet2...) for each VM and connect each network to eth0 like on the screenScheme.png

I was looking for solution for some time and figured out that third party proxy (Squid) is not required for this task. Image was taken from here Registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters has a parameter  ForwardBroadcasts was set to 1. Routing and Remote Access service was switched to start automatically. But what is route add or netsh commands should be to reproduce iptables data in Windows? Internet just flooded with not relevant info, mostly for Unix based systems. Thank you for help.

0 Kudos
seregg
Contributor
Contributor
Jump to solution

thanks a lot, you've come up with a solution!

0 Kudos