Press ESC to close · Ctrl+K to open

How to build a virtual machine environment

For OT labs and safe tests without touching the plant.

How to build a virtual machine environment for OT labs and automation testing

Almost everything we publish here is tested first in a virtual machine lab: a simulated PLC, an OPC UA server, a SCADA and a traffic analyser, each one on its own machine and without touching any real installation. If something breaks, you roll it back with a snapshot.

This guide goes straight to the point: six steps to build it, with the download links, which licence you actually need for each piece, and how to keep the network isolated.

Why virtualise the lab

A virtual lab solves four very specific everyday problems in automation:

Versions that coexist

TIA Portal V17 and V19, or two FactoryTalk versions, on separate machines and without conflicts.

Instant rollback

A snapshot before the test and, if the system ends up unusable, it is restored in seconds.

A real test network

Several machines talking to each other over OPC UA, Modbus TCP or MQTT without touching the plant.

The fourth one is the most important: safety. Testing a new OPC UA client, a script that writes to a PLC or a traffic capture against a production device is unnecessary and risky. In a virtual machine with a closed network, the worst case is having to restore a snapshot.

Step 1 — Choose the hypervisor

The hypervisor is the program that creates and runs the virtual machines. For a lab on a PC or laptop there are three reasonable options, and all three work well.

Hypervisor Cost Strong at Watch out for
VirtualBox
Oracle
Free (GPLv2) Getting started fast, cross-platform, very easy isolated networks. The Extension Pack has its own separate licence. Modest graphics performance.
VMware Workstation Pro
Broadcom
Free Performance, linked clones, advanced virtual networks, stability with Windows Server. The download goes through the Broadcom portal and requires a free account.
Hyper-V
Microsoft
Included in Windows Pro/Enterprise Native Windows integration, nothing extra to install. Once enabled, VirtualBox and VMware fall back to a slower compatibility mode.

Practical recommendation: if you are starting from zero, go with VirtualBox. It installs in five minutes, asks for no account and isolated networks are two clicks away. If the lab is going to grow to four or five machines running at the same time, VMware Workstation Pro handles it better and linked clones save a lot of disk space.

What you should not do is mix them: pick one, and disable Hyper-V if you are going to use VirtualBox or VMware, because all three compete for the same virtualization engine in the processor.

Licences without surprises

This is where confusion usually appears, especially when the lab is built on a company machine. An honest summary:

  • VirtualBox (base package): free software under GPLv2. It can also be used in a professional environment at no cost.
  • VirtualBox Extension Pack: a separate component under the PUEL licence, free only for personal, educational or evaluation use. In a company it must be licensed. It adds USB 2.0/3.0, PXE boot and RDP; if you do not need to pass a USB programming cable through to the virtual machine, the lab works perfectly well without it.
  • VMware Workstation Pro: Broadcom released it as a free product and absorbed the old Workstation Player, which is no longer distributed separately. Before rolling it out across a company fleet, read the current terms on the download portal, because the licensing model has changed several times in a short period.
  • Hyper-V: included with the Windows 10/11 Pro and Enterprise licence. It is not available on Home editions.

Simple rule: the hypervisor is rarely the licensing problem. What really has to be licensed are the guest operating systems and the automation software you install inside them. That is the next step.

Step 2 — Get the legal ISOs

An ISO is the image of the operating system installation disc. Every ISO you need for a lab can be downloaded free and legally from the vendor. There is no need to look for shady sites.

System Where to download it Terms
Windows 11 microsoft.com/software-download/windows11 The ISO is a free download. Continued use requires a valid licence.
Windows 11 Enterprise (evaluation) Microsoft Evaluation Center 90-day evaluation version. The clean route for testing.
Windows Server (evaluation) Microsoft Evaluation Center 180-day evaluation. Ideal for the SCADA, the historian or the database.
Ubuntu Desktop / Server LTS ubuntu.com/download Free and open, with no time limit.
Debian debian.org/distrib Free and open. Very light as a gateway or SoftPLC.

Windows 10 reached end of support in October 2025. It is still valid for reproducing an old customer machine, but do not pick it as the base for a new lab: it gets no security updates, and more and more automation software will stop installing on it.

The same logic applies to industrial software: nearly every vendor offers trial or free versions. TIA Portal and PLCSIM Advanced have an evaluation period, CODESYS offers a free development environment with a runtime limited by run time, and tools such as UaExpert or Wireshark are free.

Step 3 — Create the virtual machine

With the hypervisor installed and the ISO downloaded, create a clean base machine first. The example below uses Windows 11 in Workstation Pro 17, but the same logic applies to any hypervisor: official ISO, reasonable resources, expandable disk, controlled networking and integration tools installed at the end.

  1. Create a new machine from the hypervisor wizard. Do not reuse an old VM just to save time: a clean base avoids inherited problems.
  2. Use an official ISO. Download it from Microsoft or the operating system vendor, keep it in a stable folder and select that ISO in the wizard.
  3. Set a clear name and location. Use names such as WIN11-ENGINEERING-BASE, and store the machines on a disk with enough free space.
  4. Enable encryption, TPM and Secure Boot for Windows 11. This is the point that breaks most installations when it is left until later.
  5. Define the virtual disk. For a Windows 11 lab machine, start with 80-120 GB. A split or expandable disk is better than a huge fixed block on day one.
  6. Tune the hardware before booting. A sensible base is 2 vCPU and 8 GB RAM for Windows 11; increase resources only if heavy engineering software will be installed.
  7. Configure networking deliberately. NAT is fine for installation; for OT tests, keep an isolated adapter and avoid bridged mode against any plant network.
  8. Install Windows as on a normal PC. When it finishes, apply updates, install the hypervisor drivers and reboot before adding industrial software.
  9. Check adapters and IPs with ipconfig. If you see one NAT IP and one lab IP, Internet access and the test network are separated.
Wizard for creating a new virtual machine

Always start from a new machine and select the official ISO for the operating system.

Official page for downloading the Windows 11 ISO

The ISO should come from an official source; that avoids modified images or questionable installers.

Windows 11 virtual machine showing two network adapters with ipconfig

The final check is simple: one interface for NAT/Internet access and another one for the lab network.

A trick that saves hours: install one clean Windows machine first, with Guest Additions and updates applied, and keep it as a template. Every new lab machine is then created by cloning that template, not by reinstalling from scratch.

Step 4 — Choose the network mode

This is the step that turns a pile of virtual machines into a safe lab, and it is where most people get it wrong. Each machine's network adapter can work in four modes, and each one exposes the lab very differently.

Comparison of NAT, host-only, internal and bridged network modes on a virtual machine

The four adapter modes and what each one is good for in a test lab.

The setup that works in practice is this one:

  • Adapter 1 in host-only for every lab machine, with fixed IPs such as 192.168.10.11, 192.168.10.12… This is the network where the simulated PLC, the OPC UA server and the SCADA will talk.
  • Adapter 2 in NAT, enabled only when you need to download updates or an installer, and disabled the rest of the time.
  • Internal mode when you want maximum isolation: not even the host PC sees that network. Useful for analysing suspicious files or reproducing an incident.
  • Bridged mode: avoid it. The virtual machine shows up as one more device on the physical network, with its own IP. If that network is the plant network, every scan, every write test and every broadcast storm you generate reaches the real PLCs.

Golden rule: the lab is never bridged onto the plant network. If at some point you do need to talk to a physical PLC, use a dedicated network card and your own switch, outside the production network. Secure communication between PLC, HMI and PC/PG explains how to approach that separation.

One detail that confuses people at first: by default the Windows firewall blocks ping and many ports between machines on the host-only network. The right fix is not to turn the firewall off, but to mark that network as private and create an inbound rule allowing traffic from the lab range.

And if you also want to practise with managed switches, VLANs or protocols such as STP, the virtual lab pairs very well with GNS3, which emulates the network hardware side.

Step 5 — Snapshots and clones

If you take only one thing away from this article, make it this one. A snapshot is a photograph of the complete machine state: disk, memory and configuration. Restoring it returns the machine to exactly that moment.

The routine worth adopting:

  • A "clean base" snapshot right after installing the system, the Guest Additions and the updates. This one is never deleted.
  • A "software installed" snapshot once TIA Portal, the SCADA or whatever applies is in place, with its licence activated.
  • A snapshot before every risky test: a patch, a driver, a simulated firmware update, a new certificate.

A clone is a different thing: it creates a new machine from an existing one. A full clone is independent and takes up as much space as the original; a linked clone shares the base disk and takes almost nothing, which is ideal for spinning up three identical simulated PLCs in minutes.

Two warnings: a snapshot is not a backup —if the virtual disk gets corrupted, everything goes with it— and long snapshot chains piled up over months degrade performance and blow up disk usage. Consolidate and delete the ones that no longer add anything.

Step 6 — What to install on each machine

Four machines cover practically any automation test. This is how the example lab is split:

Lab architecture: four Windows and Linux virtual machines connected to an isolated virtual switch on top of the hypervisor and the host PC

The four lab machines, the protocols connecting them, and the hypervisor and host PC layers underneath.

Machine System Software Purpose
Engineering Windows 11 TIA Portal, Studio 5000, UaExpert, Wireshark Programming, configuration and traffic analysis.
Simulated PLC Windows 10/11 PLCSIM Advanced, FactoryTalk Echo Running the PLC program with its own virtual network.
SoftPLC / gateway Ubuntu Linux CODESYS, Node-RED, Mosquitto OPC UA server, MQTT broker and protocol conversion.
SCADA and historian Windows Server WinCC, FactoryTalk View, InfluxDB, SQL Server Supervision and process data logging.

From there the lab covers a lot of ground: bringing up an OPC UA server on a Siemens PLC, capturing and analysing OPC UA traffic, or connecting a process simulator to practise with a complete virtual plant without a single physical device.

Common mistakes and final checklist

The failures that waste the most time when building a first lab are almost always the same ones:

  • The machine will not boot, or only offers 32-bit systems: hardware virtualization is not enabled in the BIOS/UEFI (VT-x on Intel, AMD-V on AMD).
  • Everything is very slow: it is almost always Hyper-V still enabled and competing with VirtualBox or VMware, or over-allocated RAM across machines running at once.
  • The machines cannot see each other: Windows firewall with the wrong network profile, or adapters set to different modes.
  • Windows 11 refuses to install: the virtual TPM or EFI boot with Secure Boot is missing.
  • Strange OPC UA certificate failures after restoring a snapshot: rolling back leaves the machine clock out of sync and certificate validation fails. Sync the time before assuming anything is broken — the topic is covered in depth in OPC UA certificates.

Checklist before calling the lab finished:

  • Virtualization enabled in the BIOS and a single hypervisor in use.
  • Guest Additions or VMware Tools installed on every machine.
  • Host-only network with fixed IPs and no machine left in bridged mode.
  • A "clean base" snapshot saved on each machine.
  • A Windows template ready to clone the next machine from.
  • A copy of the lab on an external disk if the host is your work machine.


Was this article useful?

Share on LinkedIn