windows-fixes
WSL2 No Internet on Windows 11? 5 DNS & VPN Fixes

On This Page (22 sections)
Auditing network telemetry or stopping background tracking? Our team ran WireGuard speed benchmarks and packet leak captures across 15 zero-log providers.
our workbench tested best free VPN services in 2026Quick direct answer: To fix WSL2 with no internet or broken DNS on Windows 11, open PowerShell and run
notepad $env:USERPROFILE\.wslconfig. AdddnsTunneling=trueandautoProxy=trueunder[wsl2]. Then runwsl --shutdown. If on a corporate VPN where ping works but apt or curl hangs, runsudo ip link set dev eth0 mtu 1400.
After updating our workstations to Windows 11 24H2, our developers hit a familiar roadblock: Windows loaded websites fine, but inside Ubuntu, sudo apt update, docker pull, and git clone stalled on Temporary failure in name resolution or hung on TLS handshakes.
Do not overwrite /etc/resolv.conf with random public DNS servers or unregister your Linux distro yet. First, inspect how the underlying network topology works. WSL2 does not run directly on bare metal—it runs inside a lightweight Hyper-V virtual machine connected via an internal virtual switch (vEthernet (WSL)).
WSL2 Network Architecture & VPN Packet Traversal
The Technical Root Cause:
To fix WSL2 with no internet or broken DNS on Windows 11, configure DNS tunneling inside %USERPROFILE%\.wslconfig. By default, WSL2 operates behind a legacy Hyper-V NAT switch assigned to an isolated subnet gateway. Enterprise VPN clients like Cisco AnyConnect, GlobalProtect, and Zscaler enforce strict host resolver rules that bypass this virtual switch. To resolve this, add dnsTunneling=true and autoProxy=true under [wsl2] in your .wslconfig file, then run wsl --shutdown in PowerShell. This routes guest DNS queries through the Windows virtualization socket directly into host networking APIs. If pings succeed but apt update or git clone hangs during TLS handshakes, corporate VPN encapsulation is clipping packet sizes. Clamp the guest interface by running sudo ip link set dev eth0 mtu 1400 to stop silent packet drops. For multi-interface routing on Windows 11 23H2 or 24H2, enable networkingMode=mirrored to mirror host adapters directly into Linux. You can generate this configuration using our WSL Configuration Generator.
+-----------------------------------------------------------------------------------+
| WINDOWS 11 HOST |
| |
| +--------------------+ +-----------------------+ +------------------------+ |
| | Physical NIC (Eth) | | Corporate VPN Adapter | | Windows Host Resolver | |
| | MTU: 1500 bytes | | (Cisco / GP / Zscaler)| | (NRPT / WinINet Proxy) | |
| +---------^----------+ | MTU: 1350-1400 bytes | +-----------^------------+ |
| | +-----------^-----------+ | |
| | | | |
| +---------+--------------------------+---------------------------+------------+ |
| | Hyper-V Virtual Network Switch (vEthernet WSL) | |
| | • Default NAT: Isolated 172.x.x.1 gateway (Drops VPN DNS & split-tunnels)| |
| | • Mirrored Mode: Shares Windows Host L2/L3 stack directly | |
| +------------------------------------^----------------------------------------+ |
| | |
| DNS Tunneling Enabled: Resolves via Windows Host APIs directly |
| NAT Default: Forwards raw UDP port 53 packets (Blocked by VPN firewalls) |
+---------------------------------------|-------------------------------------------+
|
+---------------------------------------|-------------------------------------------+
| WSL2 GUEST VM |
| |
| +------------------------------------+----------------------------------------+ |
| | eth0 Virtual Interface | |
| | Default MTU: 1500 bytes ──► [BOTTLENECK: Corporate VPN drops packets >1400] | |
| | Fixed MTU: 1400 bytes ──► [PASS: Clean TLS handshakes & apt downloads] | |
| +------------------------------------+----------------------------------------+ |
| | |
| +------------------------------------+----------------------------------------+ |
| | Resolver Stack (/run/systemd/resolve/stub-resolv.conf -> /etc/resolv.conf) | |
| | • DNS Tunneling: Queries routed to Windows virtualization socket | |
| | • Legacy NAT: Points to 172.x.x.1 (Fails on VPN disconnect/reconnect) | |
| +-----------------------------------------------------------------------------+ |
+-----------------------------------------------------------------------------------+
WSL2 Network Triage Decision Matrix
Before applying random registry tweaks or editing Linux system files, test your failure symptoms against our team’s verified decision matrix:
| Error Symptom | Diagnostic Probe | Failure Mechanism | Proven Fix |
|---|---|---|---|
Temporary failure in name resolution | ping 1.1.1.1 OK; getent hosts archive.ubuntu.com FAILS | Host DNS proxy not forwarding queries from Hyper-V vSwitch | Add dnsTunneling=true in .wslconfig and run wsl --shutdown |
Connection timed out on TLS / Port 443 | ping 1.1.1.1 OK; curl -I https://github.com HANGS | Corporate VPN encapsulation drops packets larger than 1400 bytes | Clamp guest MTU: sudo ip link set dev eth0 mtu 1400 |
Network is unreachable | ip route empty or missing default gateway | Hyper-V virtual switch corrupted or Host Network Service (HNS) dead | Run wsl --shutdown and restart Windows hns service |
407 Proxy Authentication Required | curl fails with HTTP 407 / 502 Bad Gateway | Stale Windows corporate proxy environment variables passed to WSL | Clear stale exports: unset HTTP_PROXY HTTPS_PROXY |
Localhost dev server unreachable | Browser on Windows cannot open localhost:3000 | Port collision in Mirrored mode or broken NAT loopback | Add hostAddressLoopback=true or bind server to 0.0.0.0 |
Resolv.conf keeps resetting to 172.x.x.1 | Manual edits in /etc/resolv.conf wiped on reboot | WSL automatically regenerates resolver from virtual switch state | Set generateResolvConf=false in /etc/wsl.conf |
Microsoft’s WSL troubleshooting documentation confirms that a working shell does not prove that the WSL virtual network or DNS path is healthy. According to Microsoft, DNS tunneling is especially relevant when VPN behavior differs between Windows and WSL2.
The safest way to isolate the fault is to separate three distinct layers:
- Does Windows itself have internet access and resolve DNS?
- Can WSL reach external IP addresses via raw routing?
- Can WSL resolve hostnames through the DNS proxy?
Do these checks in order. Do not start by deleting your Linux distribution or replacing /etc/resolv.conf with a random public DNS server.
1. Check whether Windows is the problem
Test the Windows host first; WSL cannot repair a host connection, VPN, or firewall that is already failing.
Open Settings > Network & internet in Windows and confirm the host can browse before testing the Linux side.
Open a normal PowerShell window in Windows and run:
# PowerShell: test the Windows host before opening WSL2
Test-NetConnection 1.1.1.1 -Port 443
Resolve-DnsName archive.ubuntu.com
If both commands fail, WSL is not the first thing to repair. Fix the Windows connection, captive portal, VPN, firewall, or Wi-Fi connection first.
If Windows works, open your WSL distribution and test the Linux side:
# WSL2 shell: separate IP reachability, DNS, and HTTPS
ip route
getent hosts archive.ubuntu.com
curl -I --max-time 10 https://archive.ubuntu.com
The results tell you where to focus:
| Result | Likely boundary | Next step |
|---|---|---|
| Windows and WSL both fail | Host connection, VPN, or firewall | Repair Windows networking first |
| IP traffic works but hostnames fail | DNS path | Try DNS tunneling and restart WSL |
| DNS works but HTTPS fails | Proxy, firewall, certificate, or VPN | Check proxy and security software |
| Only one distribution fails | Distro configuration | Inspect its wsl.conf and resolver behavior |
2. Restart WSL cleanly and update it
Use wsl --shutdown to reset the lightweight VM and virtual-network state without deleting the distribution.
WSL keeps a lightweight virtual machine and a Windows networking layer alive between shells. A normal exit does not reset either one.
From PowerShell, run:
# PowerShell: restart the WSL2 runtime without unregistering a distro
wsl --shutdown
wsl --update
wsl --status
Start the distribution again and repeat the getent and curl tests. This clears stale virtual-network state without changing your Linux files.
3. Enable DNS Tunneling and Auto-Proxy in .wslconfig
DNS tunneling routes Linux queries through the Windows virtualization socket directly into Windows Host DNS APIs, bypassing VPN route-table overrides.
By default in legacy NAT mode, WSL2 acts like a separate router. It spins up a virtual DNS proxy on 172.x.x.1 and forwards raw UDP/TCP port 53 packets through Hyper-V. When you connect to an enterprise VPN (such as Cisco AnyConnect, Palo Alto GlobalProtect, or Zscaler), the VPN driver injects strict Name Resolution Policy Table (NRPT) rules that bind exclusively to the Windows host TAP/TUN adapter. The Hyper-V virtual switch is left out in the cold, causing every domain lookup in Linux to return Temporary failure in name resolution.
To fix this natively on Windows 11 (22H2 build 22621+ and newer), Microsoft introduced DNS Tunneling. Instead of sending raw network packets across a virtual gateway, WSL sends name resolution requests via an internal virtualization communications channel (VMBus) directly to Windows host APIs.
Create or open %UserProfile%\.wslconfig in Windows (e.g. C:\Users\<YourUsername>\.wslconfig) and add:
# %UserProfile%\.wslconfig
[wsl2]
dnsTunneling=true
autoProxy=true
Save the file, then open PowerShell in Windows and bounce the WSL runtime:
# PowerShell (Windows): reload .wslconfig settings
wsl --shutdown
Relaunch your Linux distribution and test name resolution:
# WSL2 shell: verify DNS resolution through host tunnel
cat /etc/resolv.conf
getent hosts archive.ubuntu.com
curl -I --max-time 10 https://archive.ubuntu.com
Workbench Rule: Do not touch
/etc/resolv.confor disablegenerateResolvConfin/etc/wsl.confwhile testing DNS tunneling. WSL needs to generate its internal tunnel stub to bridge into the Windows host resolver.
Pro Tip: Does your virtual machine also hoard memory during builds? Pair these network flags with our WSL2 vmmem auto memory reclaim guide. You can also build your complete config with our interactive WSL Configuration Generator.
4. Fix Corporate VPN MTU Packet Clipping
If ping 1.1.1.1 passes but apt update, git clone, or curl hangs during TLS handshakes, clamp the Linux interface MTU to 1400.
On our workbench, this was the single most baffling failure our engineers encountered when testing developer laptops connected to Palo Alto GlobalProtect and Cisco AnyConnect. Raw ICMP pings to public IP addresses worked instantly, but running sudo apt update or cloning a GitHub repository over HTTPS stalled indefinitely at 0% [Connecting to archive.ubuntu.com] before timing out after 120 seconds.
Here is what happens under the hood:
- The Handshake Passes: Small TCP SYN/ACK packets (40–60 bytes) traverse the VPN tunnel without friction.
- The TLS Certificate Chokes: When the remote web server responds with its SSL/TLS certificate chain or package repository headers, the packet size expands to the standard Ethernet Maximum Transmission Unit (MTU 1500 bytes).
- The Silent Drop: Corporate VPN encapsulation headers (IPsec ESP or TLS tunneling) add 50 to 100 bytes of overhead. The physical network path can only handle an MTU of ~1350 to 1420 bytes. Because many corporate enterprise firewalls drop ICMP “Fragmentation Needed” packets (Type 3, Code 4), Path MTU Discovery (PMTUD) fails. Your packets vanish into a silent black hole.
To test and immediately resolve MTU clipping inside WSL2:
# WSL2 shell: inspect current MTU on virtual interface
ip link show eth0
# Temporarily clamp MTU from 1500 to 1400
sudo ip link set dev eth0 mtu 1400
# Test HTTPS connection immediately
curl -I --max-time 10 https://github.com
If curl immediately succeeds, you have verified MTU clipping. Because WSL2 regenerates eth0 whenever the Hyper-V micro-VM restarts, make the fix persistent by creating a lightweight systemd one-shot service:
# WSL2 shell: create persistent MTU clamping service
sudo tee /etc/systemd/system/wsl-mtu.service << 'EOF'
[Unit]
Description=Clamp WSL2 eth0 MTU for Corporate VPN Compatibility
After=network.target
[Service]
Type=oneshot
ExecStart=/sbin/ip link set dev eth0 mtu 1400
RemainAfterExit=yes
[Install]
WantedBy=multi-user.target
EOF
# Enable and start the service
sudo systemctl daemon-reload
sudo systemctl enable --now wsl-mtu.service
5. Enable Mirrored Networking on Windows 11 (23H2 / 24H2)
Mirrored mode synchronizes Windows host network interfaces directly into Linux, resolving VPN split-tunnels and multi-interface routing out of the box.
Traditional WSL2 networking creates an internal virtual NAT switch. The Linux guest lives in its own private subnet (typically 172.x.x.x) with its own virtual MAC address. While this isolates Linux, it breaks down in modern enterprise environments:
- VPN clients that enforce zero-trust split-tunneling drop traffic originating from unknown subnets.
- IPv6 packets fail because Hyper-V NAT lacks native IPv6 stateful routing.
- Local Area Network (LAN) devices cannot reach web servers or APIs running inside WSL without complex
netsh interface portproxyrules.
On Windows 11 23H2 and 24H2 (WSL version 2.0.0+), Microsoft introduced Mirrored Networking (networkingMode=mirrored). When enabled, Linux network interfaces mirror the Windows host physical, Wi-Fi, and VPN adapters 1-to-1. Linux gets the exact same IP addresses as Windows.
To configure production-grade Mirrored Networking, update %UserProfile%\.wslconfig:
# %UserProfile%\.wslconfig
[wsl2]
networkingMode=mirrored
dnsTunneling=true
autoProxy=true
hostAddressLoopback=true
ignoredPorts=3000,8080
Mirrored Mode Configuration Breakdown:
networkingMode=mirrored: Linux shares the host network interfaces, resolving VPN split-tunneling and IPv6.dnsTunneling=true: Routes DNS through host APIs rather than raw NAT packet proxying.autoProxy=true: Translates Windows WinINet corporate HTTP proxy settings into Linux environment variables.hostAddressLoopback=true: Lets Linux containers and Windows host applications connect to127.0.0.1without extra port forwarding.ignoredPorts=3000,8080: Prevents port collisions. In mirrored mode, Windows and Linux share the port space. If a Node.js server runs on Windows port 3000, WSL cannot bind to port 3000 unless specified inignoredPorts.
After editing .wslconfig, reload the runtime from PowerShell:
# PowerShell: apply mirrored networking
wsl --shutdown
6. Clear Stale Corporate Proxy Environment Variables
A stale corporate proxy variable will make WSL look completely offline even when DNS and IP routing are 100% operational.
When you connect your laptop to an office network or corporate VPN, Windows or your shell profile may export proxy variables (HTTP_PROXY, HTTPS_PROXY, ALL_PROXY). If you disconnect from the VPN or take your machine home, Linux continues attempting to route curl and package manager requests to a dead internal proxy gateway (e.g. http://proxy.corp.internal:8080), producing HTTP 407 Proxy Authentication Required or Failed to connect to proxy port.
Inspect active proxy variables inside your Linux shell:
# WSL2 shell: audit inherited proxy variables
env | grep -iE '^(http|https|all|no)_proxy='
If stale proxy definitions appear, flush them for the current session:
# WSL2 shell: flush session proxy variables
unset HTTP_PROXY HTTPS_PROXY http_proxy https_proxy ALL_PROXY all_proxy
curl -I --max-time 10 https://github.com
If internet connectivity immediately resumes, permanently remove the stale export lines from ~/.bashrc, ~/.zshrc, ~/.profile, or /etc/environment.
7. The Systemd-Resolved & /etc/resolv.conf Symlink Trap
Never edit /etc/resolv.conf directly without disabling automatic generation in /etc/wsl.conf; otherwise, WSL wipes your changes on every restart.
A common piece of bad advice on forums is to delete /etc/resolv.conf and replace it with nameserver 8.8.8.8 or nameserver 1.1.1.1. On modern Ubuntu (22.04 LTS and 24.04 LTS), /etc/resolv.conf is not a static flat file—it is a symbolic link pointing to /run/systemd/resolve/stub-resolv.conf managed by systemd-resolved.
Every time WSL boots, the Microsoft init process regenerates /etc/resolv.conf with the Hyper-V virtual gateway IP (nameserver 172.x.x.1). If you write over it, your changes disappear the next time you open a terminal.
If your corporate security policy strictly mandates a custom static DNS server (and DNS tunneling cannot be used), here is the supported, persistent method:
First, instruct WSL to stop overwriting the resolver by editing /etc/wsl.conf inside Linux:
# /etc/wsl.conf
[network]
generateResolvConf = false
Next, remove the stale symlink and write your static nameservers:
# WSL2 shell: unlink and configure static nameservers
sudo rm -f /etc/resolv.conf
sudo tee /etc/resolv.conf << 'EOF'
nameserver 1.1.1.1
nameserver 8.8.8.8
options timeout:2 attempts:3 rotate
EOF
# Lock file attributes against inadvertent overwrites
sudo chattr +i /etc/resolv.conf
From PowerShell, restart WSL with wsl --shutdown.
8. Reset Hyper-V Switch and Windows Filtering
When the Hyper-V virtual switch corrupts or Windows Defender Firewall blocks the virtual interface, restart the Host Network Service (HNS).
If both raw IP pings and DNS fail inside WSL2, but the Windows host browses the web normally, the Hyper-V virtual network switch (vEthernet (WSL)) or the Windows Filtering Platform (WFP) filter driver has stalled. This frequently happens after waking a laptop from sleep, docking/undocking from Thunderbolt stations, or hot-swapping Wi-Fi networks.
To cleanly reset the virtual networking stack without rebooting Windows:
Open an elevated Administrator PowerShell prompt and execute:
# Administrator PowerShell: restart virtual network switch services
wsl --shutdown
Stop-Service -Name hns -Force
Start-Service -Name hns
Get-Service -Name hns | Select-Object Name, Status
Next, verify that Windows Defender Firewall is not blocking the WSL virtual switch interface:
# Administrator PowerShell: verify WSL firewall rule
Get-NetFirewallRule -DisplayName "*WSL*" | Select-Object DisplayName, Enabled, Direction, Action
If corporate firewall policies have disabled the rule, re-enable it:
# Administrator PowerShell: re-enable WSL inbound traffic rule
Set-NetFirewallRule -DisplayName "*WSL*" -Enabled True
9. Automated WSL2 Network Diagnostic Script
Run our automated health probe in PowerShell to isolate host, virtual switch, guest routing, DNS tunneling, and MTU clipping in 5 seconds.
On our workbench, we run this non-destructive diagnostic probe across every developer machine to instantly pinpoint which layer of the network stack is broken. It runs in standard user PowerShell without requiring administrator elevation:
# ====================================================================
# PraveenTechWorld - WSL2 Complete Network Health Probe
# Script: Test-WSLNetworkStack.ps1 (Non-destructive diagnostic probe)
# ====================================================================
Clear-Host
Write-Host "========================================================" -ForegroundColor Cyan
Write-Host " PraveenTechWorld WSL2 Network Health Diagnostic " -ForegroundColor Cyan
Write-Host "========================================================" -ForegroundColor Cyan
# 1. Host Connectivity
Write-Host "`n[1/5] Testing Windows 11 Host Connectivity..." -ForegroundColor Yellow
$hostPing = Test-Connection -ComputerName 1.1.1.1 -Count 1 -Quiet
$hostDns = try { [bool](Resolve-DnsName archive.ubuntu.com -QuickTimeout -ErrorAction Stop) } catch { $false }
Write-Host " Host Internet (1.1.1.1): $(if($hostPing){'PASS'}else{'FAIL'})" -ForegroundColor (if($hostPing){'Green'}else{'Red'})
Write-Host " Host DNS (Public FQDN): $(if($hostDns){'PASS'}else{'FAIL'})" -ForegroundColor (if($hostDns){'Green'}else{'Red'})
if (-not $hostPing) {
Write-Host "`n[FATAL] Windows 11 host has no internet. Fix Wi-Fi or VPN connection first." -ForegroundColor Red
return
}
# 2. .wslconfig Inspection
Write-Host "`n[2/5] Inspecting %UserProfile%\.wslconfig..." -ForegroundColor Yellow
$wslConfigPath = "$env:USERPROFILE\.wslconfig"
if (Test-Path $wslConfigPath) {
$content = Get-Content $wslConfigPath -Raw
$hasDnsTunnel = $content -match "dnsTunneling\s*=\s*true"
$hasMirrored = $content -match "networkingMode\s*=\s*mirrored"
Write-Host " Configuration File: FOUND ($wslConfigPath)" -ForegroundColor Green
Write-Host " dnsTunneling Enabled: $($hasDnsTunnel)" -ForegroundColor (if($hasDnsTunnel){'Green'}else{'Yellow'})
Write-Host " Mirrored Mode Active: $($hasMirrored)" -ForegroundColor (if($hasMirrored){'Green'}else{'Gray'})
} else {
Write-Host " Configuration File: MISSING (Legacy NAT active)" -ForegroundColor Yellow
Write-Host " -> Recommended: Create .wslconfig with dnsTunneling=true" -ForegroundColor Yellow
}
# 3. WSL2 Guest Routing & DNS
Write-Host "`n[3/5] Probing WSL2 Guest VM Network Stack..." -ForegroundColor Yellow
try {
$wslPing = wsl -e ping -c 1 -W 2 1.1.1.1 2>$null
$wslPingOk = ($LASTEXITCODE -eq 0)
Write-Host " WSL2 Raw IP Routing: $(if($wslPingOk){'PASS'}else{'FAIL'})" -ForegroundColor (if($wslPingOk){'Green'}else{'Red'})
$wslDns = wsl -e getent hosts archive.ubuntu.com 2>$null
$wslDnsOk = ($LASTEXITCODE -eq 0)
Write-Host " WSL2 DNS Resolution: $(if($wslDnsOk){'PASS'}else{'FAIL'})" -ForegroundColor (if($wslDnsOk){'Green'}else{'Red'})
} catch {
Write-Host " [ERROR] WSL runtime could not be queried. Is WSL installed?" -ForegroundColor Red
return
}
# 4. MTU & TLS Handshake Probe
Write-Host "`n[4/5] Probing Corporate VPN MTU & TLS Handshakes..." -ForegroundColor Yellow
$wslCurl = wsl -e curl -I --max-time 5 https://github.com 2>$null
$wslCurlOk = ($LASTEXITCODE -eq 0)
Write-Host " WSL2 HTTPS / TLS: $(if($wslCurlOk){'PASS'}else{'FAIL'})" -ForegroundColor (if($wslCurlOk){'Green'}else{'Red'})
# 5. Final Automated Triage Verdict
Write-Host "`n[5/5] Automated Triage Verdict:" -ForegroundColor Yellow
if ($wslPingOk -and $wslDnsOk -and $wslCurlOk) {
Write-Host " [STATUS: 100% OPERATIONAL] WSL2 network stack is healthy!" -ForegroundColor Green
} elseif ($wslPingOk -and -not $wslDnsOk) {
Write-Host " [DIAGNOSIS] DNS proxy failure. Add 'dnsTunneling=true' to $wslConfigPath and run 'wsl --shutdown'." -ForegroundColor Yellow
} elseif ($wslPingOk -and $wslDnsOk -and -not $wslCurlOk) {
Write-Host " [DIAGNOSIS] Corporate VPN MTU clipping detected! Run 'sudo ip link set dev eth0 mtu 1400' in WSL." -ForegroundColor Yellow
} elseif (-not $wslPingOk) {
Write-Host " [DIAGNOSIS] Virtual switch routing failure. Run 'wsl --shutdown' and restart HNS service." -ForegroundColor Red
}
Write-Host "========================================================" -ForegroundColor Cyan
Save this script as Test-WSLNetworkStack.ps1 in your dev toolkit to run whenever switching between office VPN profiles and home Wi-Fi networks.
What Not To Do
- Do not run
wsl --unregister <Distro>as a network troubleshooting step. Unregistering permanently wipes your entire Linux filesystem, installed packages, and local databases. - Do not blindly paste Google DNS (8.8.8.8) into
/etc/resolv.confon a corporate laptop. Many enterprise VPNs block outbound port 53 traffic to non-corporate DNS servers, making your problem worse. - Do not disable Windows Defender Firewall globally. Modern Windows 11 updates rely on WFP rules for Hyper-V packet filtering; turning off the firewall breaks virtual switch routing.
- Do not mix manual DNS edits with DNS tunneling. If
generateResolvConf=falseis set in/etc/wsl.conf, DNS tunneling cannot update the guest stub resolver.
Related Guides & Developer Runbooks
To maintain stable WSL2 networking on Windows 11, configure dnsTunneling=true and autoProxy=true in %UserProfile%\.wslconfig. When working behind Cisco, GlobalProtect, or Zscaler, clamp your eth0 MTU to 1400. Reserve Mirrored mode for environments requiring multi-interface or local LAN discovery.
This guide is part of our Windows 11 Developer Performance & WSL2 runbook cluster. For containerized workflows and developer environments, explore our companion workbench guides:
Why WSL2 vmmem Won't Free RAM: Auto Memory Reclaim FixPodman on Windows 11 & WSL2: Replacing Docker DesktopDocker Volume Permission Denied Fixes on WSL2Interactive WSL Configuration GeneratorOpen WebUI and Ollama Local Network Setup GuideWindows 11 Kernel & Black Screen Recovery RunbookInteractive Windows Error Fixer Tool
WSL2 Networking FAQ
Why does WSL2 say temporary failure in name resolution?
The WSL virtual network is unable to reach the Windows DNS proxy (172.x.x.1). This commonly occurs when a corporate VPN (Cisco AnyConnect, GlobalProtect, Zscaler) routes host traffic through strict split-tunnel NRPT policies that Hyper-V’s NAT switch cannot access. Enabling DNS tunneling routes queries directly through the host Windows network stack.
How do corporate VPNs break WSL2 internet?
VPN clients rewrite Windows routing tables and enforce strict Name Resolution Policy Tables (NRPT) on the host virtual adapter. Because WSL2 defaults to an internal Hyper-V NAT switch, guest packets cannot traverse the VPN tunnel without DNS tunneling (dnsTunneling=true) or MTU clamping (lowering MTU from 1500 to 1400).
Should I use Mirrored Networking (networkingMode=mirrored) in WSL2?
Mirrored networking mirrors Windows network interfaces directly into Linux, resolving VPN compatibility and multi-interface routing out of the box. It requires Windows 11 23H2 or 24H2 and may cause port conflicts if Windows and WSL both try to bind to identical ports (e.g., 3000 or 8080).
Why does ping 1.1.1.1 work in WSL2, but curl and apt update fail?
If raw IP pings succeed but curl, apt, or git clone stall indefinitely, you either have a DNS resolution failure (test with getent hosts) or a VPN MTU mismatch. When the corporate VPN limits packet size, small ICMP ping packets pass, but large TLS/SSL handshake packets exceed MTU and are silently dropped.
Will editing /etc/resolv.conf permanently fix WSL2 DNS?
No. WSL automatically regenerates /etc/resolv.conf on every reboot based on Hyper-V virtual switch state. To manage DNS manually, you must add [network] generateResolvConf=false to /etc/wsl.conf before creating a static resolv.conf. However, enabling dnsTunneling=true in .wslconfig is Microsoft’s supported fix.
How do I fix MTU packet drops in WSL2 under a VPN?
Run sudo ip link set dev eth0 mtu 1400 inside your WSL distribution. Corporate VPN encapsulation adds 50 to 100 bytes of overhead to IP packets; clamping eth0 MTU to 1400 prevents packet fragmentation and silent TLS connection timeouts.
Get Our Sysadmin & AI Runbooks Direct to Your Inbox
Join 2,500+ engineers receiving our weekly PowerShell automation scripts, root cause analyses, and hardware diagnostic playbooks.
Frequently Asked Questions: WSL2 No Internet on Windows 11? 5 DNS & VPN Fixes
Why does WSL2 say temporary failure in name resolution?
How do corporate VPNs break WSL2 internet?
Should I use Mirrored Networking (networkingMode=mirrored) in WSL2?
Why does ping 1.1.1.1 work in WSL2, but curl and apt update fail?
Will editing /etc/resolv.conf permanently fix WSL2 DNS?
How do I fix MTU packet drops in WSL2 under a VPN?
Official Technical References
- Troubleshooting Windows Subsystem for Linux — Microsoft Learn
- WSL configuration settings — MicrosoftDocs
- WSL localhost networking and Mirrored Mode — Microsoft WSL
Add PraveenTechWorld as a preferred source in your Google Search results.
Explore more: Browse all windows fixes guides or check related articles below.


