Well, you'll need at least two machines for the DMZ to act as a sheepdip and a honeypot. preferably two firewalls, to create the DMZ; two different
brand firewalls, so they do different sets of testing packets.
What you build in the internal network, is pretty much up to you.
A third machine to run a proxy server would be nice.
Just a suggestion.
MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".
From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x