iqworks's Posts

Thanks RD, that was helpful as well. 
Thanks Carlton. That was great. 
Hi,   I need to use vmware tools. I have securityonion-2.3.200, I want to be able to cut and paste text from SO to my ms word on the host.   I am not sure whether I need to install from vmware tool... See more...
Hi,   I need to use vmware tools. I have securityonion-2.3.200, I want to be able to cut and paste text from SO to my ms word on the host.   I am not sure whether I need to install from vmware tools iso or the exe?   In fact, I don’t even know the difference between these two. It looks like the iso is for linux, and the exe Is the latest one to use? I download the vmware tools exe, but when I ran it, it just ask to change my machine  And I clicked ok, it just disappeared?   Thanks for any help or advice
hi, I am using VMware Workstation 17 pro 17.0.0 build-20800274. Windows 10 I am using two security onion versions.  the VM with version “securityonion-2.3.190-20221207.iso“ seems to have scroll wo... See more...
hi, I am using VMware Workstation 17 pro 17.0.0 build-20800274. Windows 10 I am using two security onion versions.  the VM with version “securityonion-2.3.190-20221207.iso“ seems to have scroll working. TVM using “securityonion-2.3.250-20230519.iso “ seems to be the one with the problem.  Both on windows 11 .It works for one VM (2.3.190-20221207 ). But not on  the other VM (2.3.250-20230519iso  ) scrolling does not work and has no scroll bar. he scroll used to work in the terminal where I use my commands. But now its not. On my windows 11, the page up /down are not over the keyboard. On my windows 10 the scroll page up/down works.  On my windows 11, the scroll page up/down are shown as the 9 and 3 number keys. it also has a page up/down arrow keys showing page up/down between the ctrl and insert keys. I use these to get the last command.  On my widows the page up/down keys are on the top of the keypad. There must be some place in VMware Workstation where I can enable it? I have other VM's show a scroll bar and scrolls. another that does not have a scroll bar, but scrolls with the mouse. where are the settings for these in VMware Workstation? Seems like it is a problem for a vm, not VMware Workstation. my other VM's dont seem to have this issue. I see posts with many suggestions, but none help.  is this a VMware, linux centos 7 or other issue maybe? thanks for any advice or suggestions.
  It seemed like a paging issue. I called my virus protection people. They finally looked at my paging. They made these changes : 1 – go to settings and enter performance in the search. 2 – select ... See more...
  It seemed like a paging issue. I called my virus protection people. They finally looked at my paging. They made these changes : 1 – go to settings and enter performance in the search. 2 – select adjust the appearance and performance of windows. 3 – select advanced and select change. 4 – now I changed my paging from initial size 12288 to intial size 6946. The Max size stays at 24576. 5 – I then loaded my usual daily windows files and ran my SO VM. it ran quicker and I left it for a while and no errors, just needed to do ctrl to get the cursor back. Looks like the problem is fixed, for now.   
   Hi, I have sent this post to security onion, but I thought I would also try it here in case this sparks interest?   For the past 2 months SO VMs have started as usual bringing everything to OK st... See more...
   Hi, I have sent this post to security onion, but I thought I would also try it here in case this sparks interest?   For the past 2 months SO VMs have started as usual bringing everything to OK status. But for the past 6 days its take a long time (5 to 10  minutes or so) to bring all services to an OK status.   Also, if i leave the VM process for a few minutes, the cursor disappears and the process just sits there or I get this type of message :    This means that I have to run  sudo so-status every 15 - 20 seconds, and sometimes I get all OK's and I can get into my SOC.   I restarted my laptop and power on my VM, it seemed to go a little faster. When the problem happened again, I restarted my laptop and it still took to long to get my OK’s.   I stopped my anti virus process, still no change.   I reinstalled VMware, still no change.   Once I changed the memory from 16 to 32 GB, this seem to help, but I don’t think this is a good idea going forward.   I created another VM with the same ISO, still no change.   Not sure what to try next?   Thanks for your advice and suggestions
16.2.3 build-19376536   16.2.3 build-19376536
VMware® Workstation 16 Pro 16.2.3 build-19376536
  Now that  my re-start seemed to solve the first problem. After repeated sudo so-status, it is taking a long time to start up everthing. its been almost half hour now. Was fine yesterday.    
  Hi, I just had to restart.    thanks
I was running so 22.04. Usually its ok. But now I am seeing this ? :   And then this ? : In task manager, the cpu goes over a hundred -  CPU#1 Thanks for any advice or suggestions      
Hi, thanks. i will look at what port i have that is for mirroring. 
   Hi, I am using ESXi 7. I uploaded an OVF of a security onion VM I created. I setup switch nd a port group. The goal is to monitor my home/host all network packets comming and going through my netw... See more...
   Hi, I am using ESXi 7. I uploaded an OVF of a security onion VM I created. I setup switch nd a port group. The goal is to monitor my home/host all network packets comming and going through my network. I am using windows 10 and VMware Workstation 16 pro. I am using the ESXi hypervisor to support security onion.   I think I am at the point where i just need to access my switch using security onion for port mirroring. How to monitor traffic with port mirroring the most efficient and latest way?    I looked at this "https://www.youtube.com/watch?v=XDHakAb91r4  14.50 ". This is were needs to use D-Link to make the connection from security onion to my host network. My question is, there must be other ways to setup this connection WITHOUT D-Link?    thanks for any advice or suggestions
bluefirestorm (Champion), thanks so much. The link " https://kb.vmware.com/s/article/2146361" worked great !! I dont get those visualization related error messages in ESXi, and, i upload a security o... See more...
bluefirestorm (Champion), thanks so much. The link " https://kb.vmware.com/s/article/2146361" worked great !! I dont get those visualization related error messages in ESXi, and, i upload a security onion VM and it powered on without the visualization messages as well.  Thanks again. My next issue is to mirror in / outgoing packets to my security onion. I saw several examples, but I will make another forum post for that to see the latest best way to do this. You were VERY helpful   
Hi Bluefire, thanks for the further information. i am looking at https://kb.vmware.com/s/article/2146361  more closely and am researching and will apply the instructions. Playing with the registry s... See more...
Hi Bluefire, thanks for the further information. i am looking at https://kb.vmware.com/s/article/2146361  more closely and am researching and will apply the instructions. Playing with the registry scares me :-). will keep you posted.
Hi Bluefire. sorry it took so long. Here is how i set things up according to what i saw in your suggestion. I think i missed something?? thanks for taking time to look at my screen shots as well.  I... See more...
Hi Bluefire. sorry it took so long. Here is how i set things up according to what i saw in your suggestion. I think i missed something?? thanks for taking time to look at my screen shots as well.  I have my windows 10 BIOS intel virtualization technology checked (should this be enabled??)  ESXi virtulization 0.png I have the "Virtualize Intel VT-x/EPT or AMD-V/RVI" box checked/enabled for my ESXi 7. ESXi virtulization 1.png I have Hyper-v for windows 10 unchecked. ESXi virtulization 2.png If the Windows 10/11 host has Hyper-V enabled, nested virtualisation will not work with Workstation Pro. That is the meaning of the "Virtualized Intel VT-x/EPT is not supported on this platform". Make sure you have Hyper-V removed from the host so that nested virtualisation will work ???. https://kb.vmware.com/s/article/2146361 Is this what you are reffering to? Process to turn off virtualization-based Security: Below steps can be followed to turn off virtualization-based Security for Windows 10 Home & Pro: For Microsoft Windows 10 Pro & above: Edit group policy (gpedit) Go to Local Computer Policy > Computer Configuration > Administrative Templates > System Double Click on Device Guard on the right hand side to open. Double Click on "Turn On Virtualization Security" to open a new window It would be "Not Configured", Select "Disable" and click "Ok" Close the Group Policy Editor. Restart the system Also make sure that Memory Integrity is OFF Windows Security -> Device Security -> Core Isolation details “Memory Integrity is a feature inside a broader set of protections called Core Isolation. It uses hardware virtualisation to protect sensitive processes from infection. These features are a subset of virtualisation-based security features that Microsoft has offered to enterprise users since Windows 10 shipped.Mar 9, 2020” https://nakedsecurity.sophos.com/2020/03/09/microsoft-turn-off-memory-integrity-if-its-causing-problems/ Also make sure that Memory Integrity is OFF Windows Security -> Device Security -> Core Isolation details This is the current state of my Memory Intefrity ESXi virtulization 3.png  If your Windows host is a member of an AD domain, items such as Memory Integrity/VBS can also be enforced via domain policy. If that is the case you need to contact your domain admin. When Hyper-V is detected, you will see these lines in the vmware.log <timestamp> In(05) vmx IOPL_Init: Hyper-V detected by CPUID <timestamp> In(05) vmx Monitor Mode: ULM Once Hyper-V is no longer detected, vmware.log Monitor Mode should show as CPL0, and nested virtualisation should work (with the Virtualize Intel VT-x in the VM processor settings enabled). With the above settings, I get this when I power on my ESXi. ESXi virtulization 5.png When Hyper-V is detected, you will see these lines in the vmware.log <timestamp> In(05) vmx IOPL_Init: Hyper-V detected by CPUID <timestamp> In(05) vmx Monitor Mode: ULM In my ESXi log, I see 2022-01-18T16:34:11.659Z In(05) vmx IOPL_Init: Hyper-V detected by CPUID 2022-01-18T16:34:11.777Z In(05) vmx Monitor Mode: ULM   Once Hyper-V is no longer detected, vmware.log Monitor Mode should show as CPL0, and nested virtualisation should work (with the Virtualize Intel VT-x in the VM processor settings enabled) ??? thanks for your suggestions and advice
Bluefire, Thanks for your detailed information, it helps a lot. i will be trying the link you sent as well as other information you mentioned. i will keep you posted.
   Hi, I am using windows 10, version 21H2 (OS Build 19044.1415). I have installed VMware Workstation 16 Pro.       I have installed ESXi 7 inside my VMware workstation. I am trying to install s... See more...
   Hi, I am using windows 10, version 21H2 (OS Build 19044.1415). I have installed VMware Workstation 16 Pro.       I have installed ESXi 7 inside my VMware workstation. I am trying to install security onion on this ESXi 7 so I can monitor my home network.    My shell esxcfg-info | grep "HV Support"   says 0. BEFORE I test with the following:     When I uncheck the Hyper-V option in my “Turn windows feature on or off” and power on my ESXi with the “Virtualize Intel VT-x/EPT or AMD-V/RVI” box checked, I get “Virtualized Intel VT-x/EPT is not supported on this platform. Continue without virtualized Intel VT-x/EPT”.   When I uncheck the Hyper-V option in my “Turn windows feature on or off” and power on my ESXi with the “Virtualize Intel VT-x/EPT or AMD-V/RVI” box UNchecked, I get “Virtualized Intel VT-x/EPT is disabled for this ESX virtual machine. You will only be able to run 32-bit nested virtual machines”. Then, when I get into my ESXi and  try to power on my security onion VM, I get: Failed to power on virtual machine “iq SO 2.3.62-MSEARCH OVF”. This host does not support intel VT-x. Power On VM Key haTask-5-vim.VirtualMachine.powerOn-3141252040 Description Power On this virtual machine Virtual machine iq SO 2.3.62-MEARCH 11 OVF State Failed - This host does not support Intel VT-x. Errors ·   This host does not support Intel VT-x. ·   This host does not support "Intel EPT" hardware assisted MMU virtualization. ·   This host appears to be running in a virtual machine with VHV disabled. Ensure that VHV is enabled in the virtual machine configuration file. ·   VMware ESX does not support the user level monitor on this host. ·   Module 'MonitorMode' power on failed. ·   Failed to start the virtual machine.      Thanks for any help or advice