I did a -A scan and got the folllowing line which might be interesting
MAC Address: 00:50:56:BC:7B:D9 (VMware)
If you dont have money to invest then better google pfsence , smoothwall , they are good all in one firewall type solutions and open source .
Thanks for your idea sir,but if possible can you tell me the possible mac address range for the vmware?
and pfsense and smoothwall supports NAT uhh?
can i use them to play my NAT enumeration on them?
Agreed, performing OS detection will determine, in my experience, a system running in a VM.
Also, Hak5 did a video on turning a mini-PC into a router/firewall. I enjoyed it u dutil they changed the firewall software they were using in another video...
I don't know how OS determination will help us in identifying the virtualization technology used on the target,besides mac address what are the other things i should look for to identify the virtualization?
Also if it is hosted using virtualization other than vmware workstation means how can we detect them?
As per wikipedia following are the features supported by Pfsence
* Firewall
* State Table
* NAT
* Redundancy
o CARP - CARP from OpenBSD allows for hardware failover. Two or more firewalls can be configured as a failover group. If one interface fails on the primary or the primary goes offline entirely, the secondary becomes active. pfSense also includes configuration synchronization capabilities where changes made to the primary firewall will automatically synchronize to the secondary firewall.
o pfsync - pfsync ensures the firewall's state table is replicated to all failover configured firewalls. This means your existing connections will be maintained in the case of failure, which is important to prevent network disruptions.
* Outbound and Inbound Load Balancing
* VPN - IPsec, OpenVPN, PPTP
* PPPoE Server
* RRD Graphs Reporting
* Real Time Information - Using AJAX
* Dynamic DNS
* Captive portal
* DHCP Server and Relay
* Live CD Version Available
* Proxy server
* Support for software extensions.
o Notable expansions are : Squid proxy server and Snort intrusion prevention/detection system.
Also if you are in LAN subnet you can issue a ping command and then check the local arp table for mac address conformation , then you can match it with nmap results .