Windows 10 hyper-v default switch problems when VPN turned on

%3CLINGO-SUB%20id%3D%22lingo-sub-802188%22%20slang%3D%22en-US%22%3EWindows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-802188%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20I%20have%20following%20problems%20with%20my%20guests%20VMs%3A%3C%2FP%3E%3CP%3EHost%20OS%3A%3C%2FP%3E%3CP%3EWindows%20Pro%20latest%20edition%3A%201903.%3CBR%20%2F%3EHyper-V%20on.%3CBR%20%2F%3EI%20am%20using%20Default%20Switch%20for%20my%20guest%20VMs.%3CBR%20%2F%3EIts%20configuration%20is%20default%3B%20IP%20is%20set%20to%3A%3CBR%20%2F%3EIP%3A%20192.168.224.241%3CBR%20%2F%3ENetmask%3A%20255.255.255.240%3CBR%20%2F%3EGateway%3A%20empty%3CBR%20%2F%3EDNS%3A%20empty%3CBR%20%2F%3EMy%20quest%20is%20configured%20in%20a%20following%20way%3A%3CBR%20%2F%3EIP%3A%20192.168.224.242%3CBR%20%2F%3ENetmask%3A%20255.255.255.240%3CBR%20%2F%3EGateway%3A%20192.168.224.241%3CBR%20%2F%3EDNS%3A%20192.168.224.241%3C%2FP%3E%3CP%3EThis%20configuration%20works%20OK%20on%20guest%20(%20I%20have%20the%20Internet%20access%20and%20host%20connection)%20until%20I%20turn%20on%20a%20corporate%20VPN.%3CBR%20%2F%3EWhen%20the%20host%20VPN%20is%20turned%20ON%20I%20loose%20the%20ability%20to%20connect%20to%20the%20Internet%20on%20my%20Hyper-V%20guest.%3C%2FP%3E%3CP%3EWhat's%20wrong%3F%20I%20though%20that%20the%20default%20switch%20should%20manage%20this%20kind%20of%20situation.%20How%20I%20can%20change%20the%20configuration%20to%20make%20it%20working%20properly%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBR%3C%2FP%3E%3CP%3ETomek%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-802569%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-802569%22%20slang%3D%22en-US%22%3EYou%20should%20create%20a%20new%20Virtual%20network%20adapter%20in%20Hyper-v%20virtual%20switch%20manager%2C%20make%20it%20an%20external%20one%20and%20attach%20it%20to%20your%20physical%20network%20adapter%20which%20is%20connected%20to%20your%20computer%20and%20gives%20you%20Internet%20access.%3CBR%20%2F%3Eafter%20that%20go%20to%20the%20Guest%20OS%20and%20give%20it%20an%20static%20IPv4%20address%20that%20is%20on%20the%20same%20subnet%20as%20your%20host%2C%20set%20default%20gateway%20to%20your%20physical%20router's%20IP%20address%20and%20DNS%20servers%20to%20something%20like%3A%208.8.8.8-8.8.4.4%20(Goolge's)%20or%201.1.1.1-1.0.0.1%20(CloudFlare's).%3CBR%20%2F%3Ethis%20method%20is%20guaranteed%20to%20work%2C%20let%20me%20know%20if%20you%20have%20problem%20setting%20it%20up.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-803427%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-803427%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310193%22%20target%3D%22_blank%22%3E%40HotCakeX%3C%2FA%3E%26nbsp%3BThanks%20for%20your%20reply.%20I%20had%20gave%20it%20a%20try%20but%20instead%20using%20google%20DNS%20I%20used%20the%20exact%20same%20DNS%20as%20on%20my%20host%20which%20is%20my%20router%20gateway%20address.%20All%20was%20looking%20OK%3B%20the%20guest%20had%20the%20Internet%20connection%20and%20it%20was%20able%20to%20ping%20any%20web%20address.%3C%2FP%3E%3CP%3EThen%20I%20tried%20to%20start%20the%20VPN%20(L2TP%2FIPsec%20vpn)%20but%20the%20host%20was%20not%20able%20to%20connect.%20I%20was%20receiving%20rejections.%20I%20have%20deleted%20the%20external%20VNIC%20and%20I%20was%20able%20to%20connect%20to%20the%20VPN%20again.%20Seems%20like%20this%20configuration%20is%20breaking%20my%20VPN%20connection.%3C%2FP%3E%3CP%3EThe%20other%20downside%20for%20this%20configuration%20is%20that%20I%20am%20switching%20the%20networks%20quite%20often%3B%20from%20cable%20to%20WIFI%2C%20from%20one%20WIFI%20to%20another%20and%20this%20configuration%20would%20require%20constant%20changes%20on%20my%20guest.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-803431%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-803431%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20the%20same%20config%20and%20it's%20working%20fine%20for%20me.%20not%20sure%20if%20it's%20relevant%20but%20I'm%20on%20Windows%2010%20insider%2018956.%3CBR%20%2F%3Ei'm%20using%20custom%20DNS%20(cloudflare's)%20on%20my%20host%20and%203%20VMs%20that%20i%20have%20(Windows%20server%202019%20and%20Windows%2010%20pro).%20they%20all%20use%20the%20Same%20external%20virtual%20network%20adapter%20and%20they're%20all%20on%20the%20same%20subnet%20as%20my%20host%2C%20have%20static%20IP%20too%20which%20is%20mandatory%20for%20my%20servers.%3CBR%20%2F%3Emy%20network%20adapter%20is%20a%20USB%20WIFI%20adapter.%20my%20VMs%20all%20have%20direct%20connection%20to%20the%20internet%2C%20whether%20or%20not%20my%20host%20is%20using%20VPN.%3C%2FP%3E%3CP%3Ewhen%20you%20switch%20from%20WIFI%20to%20cable%20you%20just%20have%20to%20go%20to%20virtual%20switch%20manger%20in%20Hyper-v%20and%20attach%20your%20other%20network%20adapter%20to%20the%20external%20vNIC.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-803458%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-803458%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310193%22%20target%3D%22_blank%22%3E%40HotCakeX%3C%2FA%3E%26nbsp%3BThanks%20for%20your%20fast%20reply.%20What%20kind%20of%20VPN%20do%20you%20use%3F%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20other%20thing%20about%20following%3A%3C%2FP%3E%3CP%3E%22%3CSPAN%3Ewhen%20you%20switch%20from%20WIFI%20to%20cable%20you%20just%20have%20to%20go%20to%20virtual%20switch%20manger%20in%20Hyper-v%20and%20attach%20your%20other%20network%20adapter%20to%20the%20external%20vNIC.%3C%2FSPAN%3E%22%20and%20what%20about%20guest%20network%20configuration%3F%20I%20would%20need%20to%20change%20it%20as%20well.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-804059%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-804059%22%20slang%3D%22en-US%22%3EYou're%20welcome%2C%3CBR%20%2F%3EI%20use%20IKEv2%20and%20PPTP%2C%3CBR%20%2F%3Eguest%20VM%20networks%20don't%20need%20any%20changes%20because%20they%20all%20see%20the%20same%20virtual%20adapter%20on%20their%20ends%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-804122%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-804122%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310193%22%20target%3D%22_blank%22%3E%40HotCakeX%3C%2FA%3E%26nbsp%3BThanks%2C%20I%20did%20the%20configuration%20one%20more%20time%20and%20it%20started%20to%20work....more%20or%20less%3A)%20As%20this%20time%20VMs%20have%20access%20to%20the%20Internet%20when%20the%20host%20VPN%20is%20turned%20on%20but%20they%20do%20not%20have%20access%20to%20resources%20provided%20by%20the%20VPN.%20Seems%20like%20the%20VM%20traffic%20bypasses%20the%20VPN.%3C%2FP%3E%3CP%3EWhole%20point%20of%20this%20configuration%20is%20to%20get%20both%20for%20the%20VMs%3B%20resources%20behind%20the%20VPN%20and%20access%20to%20the%20Internet.%3C%2FP%3E%3CP%3EI%20haven't%20explained%20this%20well%20at%20the%20first%20place.%3C%2FP%3E%3CP%3EI%20can%20confirm%20that%20your%20configuration%20is%20fine%20when%20VMs%20do%20not%20need%20access%20to%20host%20VPN.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-804245%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-804245%22%20slang%3D%22en-US%22%3E%3CP%3EOh%20I%20thought%20the%20problem%20was%20that%20you%20couldn't%20get%20Internet%20in%20VMs%20with%20host%20VPN%20on.%20okay%20so%20I%20just%20tried%20it%20on%20my%20PC.%3CBR%20%2F%3Efirst%20restarted%20Windows%2C%20connected%20to%20my%20VPN%2C%20set%20Windows%2010%20enterprise%20VM%20to%20use%20the%20default%20switch%2C%20started%20the%20VM%2C%20then%20checked%20and%20I%20had%20both%20Internet%20and%20VPN%20access%20on%20the%20VM.%20I%20use%20VPN%20to%20access%20a%20specific%20website%20that%20only%20lets%20users%20from%20a%20specific%20country%20to%20access%20it%20so%20that's%20how%20I%20know%20my%20VM%20can%20use%20VPN%20resources.%3CBR%20%2F%3Enow%20i%20understand%20you've%20tried%20the%20default%20switch%20already%20and%20it%20wasn't%20successful%20but%20try%20it%20again%20like%20i%20did%20and%20see%20what%20happens.%20by%20the%20way%20on%20my%20host%20i%20didn't%20make%20any%20changes%20to%20the%20default%20virtual%20switch%2C%20all%20i%20did%20was%20to%20set%201.1.1.1%20as%20my%20DNS%20in%20the%20VM%2C%20no%20static%20IP%20or%20anything.%3CBR%20%2F%3E%3CBR%20%2F%3Eif%20you%20try%20all%20of%20them%20and%20it%20Still%20fail%20to%20work%20for%20you%20then%20i%20think%20it's%20related%20to%20the%20new%20networking%20system%20in%20the%20Windows%2010%20insider%20that%20I'm%20using%2C%20apparently%20it%20doesn't%20have%20the%20previous%20problems.%3CBR%20%2F%3E%3CBR%20%2F%3Eso%20I%20hope%20the%20default%20switch%20work%20out%20for%20you%20but%20if%20not%20then%20you%20have%202%20options.%201%20is%20to%20use%20Windows%2010%20insider%20(you%20can%20dual%20boot%20it%20if%20you%20want)%20OR%20you're%20gonna%20need%20to%20ask%20your%20VPN%20provider%20to%20let%20you%20login%20with%20multiple%20sessions%20so%20then%20you'll%20be%20able%20to%20connect%20directly%20to%20your%20VPN%20host%20from%20each%20of%20your%20VMs%20as%20well%20as%20your%20host%20OS%2C%20all%20at%20the%20same%20time.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-804323%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-804323%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310193%22%20target%3D%22_blank%22%3E%40HotCakeX%3C%2FA%3E%26nbsp%3BThanks%20for%20your%20help!%20I%20have%20already%20tried%20the%20approach%20with%20installing%20the%20VPN%20on%20VMs%20but%20it%20was%20not%20working%20for%20me%20because%20of%20lack%20of%20proper%20packages%20for%20this%20kind%20of%20VPN.%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20followed%20your%20walk-through%20and%20unfortunately%20VMs%20looses%20the%20connection%20upon%20the%20host%20VPN%20turn%20on.%20Could%20you%20please%20check%20your%20default-switch%20configuration%20on%20host%20and%20post%20it%20here%3F%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20first%20of%20all%20seems%20like%20it%20constantly%20changes%20it's%20IP%20after%20host%20restart...weird.%3C%2FP%3E%3CP%3EIn%20the%20configuration%20I%20see%20that%20only%20IP%20and%20mask%20are%20filled%20in%20(no%20gateway%2C%20no%20dns).%20I%20set%20dhcp%20on%20my%20VMs.%3C%2FP%3E%3CP%3EThe%20problem%20seems%20like%20there%20is%20no%20routing%20from%20default%20switch%20to%20VPN.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1614670%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1614670%22%20slang%3D%22en-US%22%3EI%20have%20this%20same%20problem.%20It%20seems%20my%20guest%20OS%20shares%20the%20VPN%20connection.%20I%20want%20an%20independent%20connection%20from%20the%20Guest%20OS.%20When%20I%20try%20to%20create%20the%20External%20Switch%2C%20it%20breaks%20my%20wi-fi%20connection%20(Killer%20WiFi%20AX1650).%20Frustrating.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1618504%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20hyper-v%20default%20switch%20problems%20when%20VPN%20turned%20on%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1618504%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F391392%22%20target%3D%22_blank%22%3E%40kapalkat%3C%2FA%3EHi%20I%20had%20the%20same%20problem%20and%20solved%20it%20by%20reducing%20the%20MTU%20of%20NIC%20in%20the%20guest%20vm.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20the%20guest%20vm%3A%3C%2FP%3E%3CP%3Erun%20cmd%20with%20admin%20privileges%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CSTRONG%3Enetsh%20interface%20ipv4%20show%20interfaces%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CSTRONG%3Enetsh%20interface%20ipv4%20set%26nbsp%3B%20interface%20%3CSPAN%20class%3D%22ms-rteBackColor-4%22%3E%22Ethernet%22%3C%2FSPAN%3E%20mtu%3D%3CSPAN%20class%3D%22ms-rteBackColor-4%22%3E1300%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hey I have following problems with my guests VMs:

Host OS:

Windows Pro latest edition: 1903.
Hyper-V on.
I am using Default Switch for my guest VMs.
Its configuration is default; IP is set to:
IP: 192.168.224.241
Netmask: 255.255.255.240
Gateway: empty
DNS: empty
My quest is configured in a following way:
IP: 192.168.224.242
Netmask: 255.255.255.240
Gateway: 192.168.224.241
DNS: 192.168.224.241

This configuration works OK on guest ( I have the Internet access and host connection) until I turn on a corporate VPN.
When the host VPN is turned ON I loose the ability to connect to the Internet on my Hyper-V guest.

What's wrong? I though that the default switch should manage this kind of situation. How I can change the configuration to make it working properly?

 

BR

Tomek

10 Replies
Highlighted
You should create a new Virtual network adapter in Hyper-v virtual switch manager, make it an external one and attach it to your physical network adapter which is connected to your computer and gives you Internet access.
after that go to the Guest OS and give it an static IPv4 address that is on the same subnet as your host, set default gateway to your physical router's IP address and DNS servers to something like: 8.8.8.8-8.8.4.4 (Goolge's) or 1.1.1.1-1.0.0.1 (CloudFlare's).
this method is guaranteed to work, let me know if you have problem setting it up.
Highlighted

@HotCakeX Thanks for your reply. I had gave it a try but instead using google DNS I used the exact same DNS as on my host which is my router gateway address. All was looking OK; the guest had the Internet connection and it was able to ping any web address.

Then I tried to start the VPN (L2TP/IPsec vpn) but the host was not able to connect. I was receiving rejections. I have deleted the external VNIC and I was able to connect to the VPN again. Seems like this configuration is breaking my VPN connection.

The other downside for this configuration is that I am switching the networks quite often; from cable to WIFI, from one WIFI to another and this configuration would require constant changes on my guest. 

Highlighted

I have the same config and it's working fine for me. not sure if it's relevant but I'm on Windows 10 insider 18956.
i'm using custom DNS (cloudflare's) on my host and 3 VMs that i have (Windows server 2019 and Windows 10 pro). they all use the Same external virtual network adapter and they're all on the same subnet as my host, have static IP too which is mandatory for my servers.
my network adapter is a USB WIFI adapter. my VMs all have direct connection to the internet, whether or not my host is using VPN.

when you switch from WIFI to cable you just have to go to virtual switch manger in Hyper-v and attach your other network adapter to the external vNIC.

Highlighted

@HotCakeX Thanks for your fast reply. What kind of VPN do you use? 

The other thing about following:

"when you switch from WIFI to cable you just have to go to virtual switch manger in Hyper-v and attach your other network adapter to the external vNIC." and what about guest network configuration? I would need to change it as well.

Highlighted
You're welcome,
I use IKEv2 and PPTP,
guest VM networks don't need any changes because they all see the same virtual adapter on their ends
Highlighted

@HotCakeX Thanks, I did the configuration one more time and it started to work....more or less:) As this time VMs have access to the Internet when the host VPN is turned on but they do not have access to resources provided by the VPN. Seems like the VM traffic bypasses the VPN.

Whole point of this configuration is to get both for the VMs; resources behind the VPN and access to the Internet.

I haven't explained this well at the first place.

I can confirm that your configuration is fine when VMs do not need access to host VPN.

 

Highlighted

Oh I thought the problem was that you couldn't get Internet in VMs with host VPN on. okay so I just tried it on my PC.
first restarted Windows, connected to my VPN, set Windows 10 enterprise VM to use the default switch, started the VM, then checked and I had both Internet and VPN access on the VM. I use VPN to access a specific website that only lets users from a specific country to access it so that's how I know my VM can use VPN resources.
now i understand you've tried the default switch already and it wasn't successful but try it again like i did and see what happens. by the way on my host i didn't make any changes to the default virtual switch, all i did was to set 1.1.1.1 as my DNS in the VM, no static IP or anything.

if you try all of them and it Still fail to work for you then i think it's related to the new networking system in the Windows 10 insider that I'm using, apparently it doesn't have the previous problems.

so I hope the default switch work out for you but if not then you have 2 options. 1 is to use Windows 10 insider (you can dual boot it if you want) OR you're gonna need to ask your VPN provider to let you login with multiple sessions so then you'll be able to connect directly to your VPN host from each of your VMs as well as your host OS, all at the same time.

Highlighted

@HotCakeX Thanks for your help! I have already tried the approach with installing the VPN on VMs but it was not working for me because of lack of proper packages for this kind of VPN. 

I have followed your walk-through and unfortunately VMs looses the connection upon the host VPN turn on. Could you please check your default-switch configuration on host and post it here? 

So first of all seems like it constantly changes it's IP after host restart...weird.

In the configuration I see that only IP and mask are filled in (no gateway, no dns). I set dhcp on my VMs.

The problem seems like there is no routing from default switch to VPN.

 

Highlighted
I have this same problem. It seems my guest OS shares the VPN connection. I want an independent connection from the Guest OS. When I try to create the External Switch, it breaks my wi-fi connection (Killer WiFi AX1650). Frustrating.
Highlighted

@kapalkatHi I had the same problem and solved it by reducing the MTU of NIC in the guest vm.

 

In the guest vm:

run cmd with admin privileges

netsh interface ipv4 show interfaces

netsh interface ipv4 set  interface "Ethernet" mtu=1300