Building a Cyber Range: How to Create Network Security Labs with GNS3 and Containerlab on a Powerful VPS
Introduction: The Modern Cyber Range
In today's rapidly evolving threat landscape, security professionals need realistic, isolated environments to test defenses, practice incident response, and develop new skills. Traditional physical labs are expensive, inflexible, and difficult to scale. Enter the cyber range—a virtualized environment that simulates real-world networks for security training, research, and testing. By deploying these ranges on powerful Virtual Private Servers (VPS), organizations and individuals gain access to enterprise-grade simulation capabilities without the capital expenditure of physical hardware.
A VPS-based cyber range offers unprecedented flexibility. You can spin up complex network topologies with routers, switches, firewalls, and vulnerable targets, conduct penetration tests, analyze malware, and then tear everything down when finished. This article explores how to build such environments using two powerful tools: GNS3 for traditional network device emulation and Containerlab for modern, container-based network topologies.
Why a VPS is Ideal for Cyber Ranges
Building a cyber range on a local machine has significant limitations: resource contention, performance bottlenecks, and lack of accessibility. A high-performance VPS solves these problems.
- Dedicated Resources: A VPS provides guaranteed CPU, RAM, and storage, ensuring consistent performance for resource-intensive emulation.
- Always-On Accessibility: Your lab is accessible from anywhere, allowing for collaborative training sessions or remote work.
- Isolation and Safety: Running potentially malicious code or disruptive tests is contained within the VPS, protecting your local network and primary systems.
- Scalability: Need more power for a larger simulation? Most VPS providers allow you to upgrade your plan with minimal downtime.
For serious cyber range work, we recommend a VPS with at least 4-8 CPU cores, 16-32 GB of RAM, and 100+ GB of SSD storage. This provides ample headroom for running multiple virtual machines and network nodes simultaneously.
Core Tool 1: GNS3 for Comprehensive Network Emulation
GNS3 (Graphical Network Simulator) is an open-source platform for designing, configuring, and testing complex network topologies. It excels at emulating real network operating systems from vendors like Cisco, Juniper, and Palo Alto.
Setting Up GNS3 on a VPS
The traditional GNS3 setup involves a local GUI client connected to a remote server. The VPS will host the GNS3 server, which does the heavy lifting of running virtual machines and network devices.
- Provision Your VPS: Choose a Linux distribution like Ubuntu 22.04 LTS. Ensure your VPS provider allows nested virtualization (KVM/Intel VT-x or AMD-V), which is crucial for running virtual machines inside the VPS.
- Install the GNS3 Server: Use the official install script or package manager. The server runs as a daemon, managing all emulation tasks.
- Configure Remote Access: Secure the GNS3 server by binding it to a local interface and setting up SSH tunneling. Never expose the GNS3 server port directly to the public internet.
- Prepare Device Images: Import your network device images (e.g., Cisco IOS, CSR1000v, VyOS) and virtual machine templates (Kali Linux, Metasploitable, Windows targets) onto the VPS storage.
Building a Pentest Lab with GNS3
A typical penetration testing lab in GNS3 might include:
- Attacker Machine: A Kali Linux VM with tools like Nmap, Metasploit, and Burp Suite.
- Target Network: A simulated corporate network with routers, a firewall (pfSense or OPNsense), and internal switches.
- Vulnerable Targets: VMs like Metasploitable, DVWA (Damn Vulnerable Web Application), or custom-built machines with specific vulnerabilities.
- Traffic Capture: Integration with tools like Wireshark on the GNS3 server for full packet analysis.
This setup allows you to practice the full cyber kill chain—from reconnaissance and weaponization to exploitation and post-exploitation—in a controlled, repeatable environment.
Core Tool 2: Containerlab for Agile, Lightweight Topologies
While GNS3 is excellent for traditional network emulation, Containerlab represents the next generation. It uses Docker containers to create network topologies defined in a simple YAML file. It's incredibly fast, lightweight, and perfect for testing modern network configurations, cloud-native security, and CI/CD pipeline integration.
Advantages of Containerlab for Security Labs
- Rapid Provisioning: Topologies with dozens of nodes can start in seconds, not minutes.
- Declarative Configuration: Your entire lab is defined in a YAML file, making it version-controllable and easily shareable.
- Resource Efficiency: Containers share the host kernel, using far less RAM and CPU than full VMs.
- Rich Ecosystem: A wide variety of containerized network topologies are available, including routers (FRRouting, Arista cEOS), switches (SONiC), and security appliances.
Creating a Containerlab Cyber Range
Installation is straightforward: install Docker and then Containerlab via its package manager. A basic lab definition for a security exercise might look like this:
name: security-lab
topology:
nodes:
attacker:
kind: linux
image: kalilinux/kali-rolling
firewall:
kind: linux
image: opnsense/opnsense
vulnerable-web:
kind: linux
image: vulnerables/web-dvwa
links:
- endpoints: ["attacker:eth1", "firewall:eth0"]
- endpoints: ["firewall:eth1", "vulnerable-web:eth0"]
With a single command (containerlab deploy -t lab.yaml), the entire environment is created. You can then SSH into the "attacker" container and begin testing the web application through the firewall.
Architecting a Hybrid Cyber Range
The most powerful approach combines both tools. Use GNS3 to emulate the core enterprise network infrastructure (legacy routers, ASA firewalls) and use Containerlab to simulate modern, agile segments like a DevOps microservices network or a cloud gateway. The two environments can be connected via virtual Ethernet bridges on the VPS, creating a seamless, multi-technology cyber range.
This hybrid model mirrors real-world IT environments, where legacy systems coexist with modern cloud-native applications, providing the most realistic training ground for security professionals.
Security and Operational Best Practices
Running a cyber range on a VPS requires careful security consideration.
- Network Isolation: Use the VPS host firewall to ensure lab traffic cannot egress to the public internet unless explicitly allowed. This prevents accidental leakage of scan traffic or malware.
- Snapshot and Rollback: Before a destructive exercise, take a snapshot of your VPS or key VM disks. This allows for instant recovery to a known good state.
- Access Control: Use SSH keys, not passwords, for VPS access. For multi-user training, consider setting up individual user accounts and leveraging GNS3 projects or separate Containerlab instances.
- Monitoring: Monitor VPS resource usage (CPU, RAM, disk I/O) to understand the impact of your simulations and avoid over-provisioning.
Conclusion: The Future of Security Training is Virtual
The combination of high-performance, affordable VPS hosting and advanced emulation software like GNS3 and Containerlab has democratized access to sophisticated cyber ranges. Whether you are an individual security researcher honing your skills, a team preparing for a red team engagement, or an educator training the next generation of defenders, a virtual cyber range provides a safe, scalable, and cost-effective platform.
By investing time in building these environments, you create a perpetual learning and testing machine. You can replicate the latest attack techniques, validate security tool configurations, and develop muscle memory for incident response—all within the confines of a virtual server. In the relentless arms race of cybersecurity, such a capability is not just an advantage; it is a necessity.
