Part of our windows fixes guide series

windows-fixes

WSL2 No Internet on Windows 11? 5 DNS & VPN Fixes

Praveen19 min read
Minimal flat editorial illustration of an ethernet cable plug with a severed wire and an amber indicator on an off-white background
On This Page (22 sections)
Workbench Security Audit

Auditing network telemetry or stopping background tracking? Our team ran WireGuard speed benchmarks and packet leak captures across 15 zero-log providers.

our workbench tested best free VPN services in 2026

Quick direct answer: To fix WSL2 with no internet or broken DNS on Windows 11, open PowerShell and run notepad $env:USERPROFILE\.wslconfig. Add dnsTunneling=true and autoProxy=true under [wsl2]. Then run wsl --shutdown. If on a corporate VPN where ping works but apt or curl hangs, run sudo ip link set dev eth0 mtu 1400.

After updating our workstations to Windows 11 24H2, our developers hit a familiar roadblock: Windows loaded websites fine, but inside Ubuntu, sudo apt update, docker pull, and git clone stalled on Temporary failure in name resolution or hung on TLS handshakes.

Do not overwrite /etc/resolv.conf with random public DNS servers or unregister your Linux distro yet. First, inspect how the underlying network topology works. WSL2 does not run directly on bare metal—it runs inside a lightweight Hyper-V virtual machine connected via an internal virtual switch (vEthernet (WSL)).

WSL2 Network Architecture & VPN Packet Traversal

The Technical Root Cause:

To fix WSL2 with no internet or broken DNS on Windows 11, configure DNS tunneling inside %USERPROFILE%\.wslconfig. By default, WSL2 operates behind a legacy Hyper-V NAT switch assigned to an isolated subnet gateway. Enterprise VPN clients like Cisco AnyConnect, GlobalProtect, and Zscaler enforce strict host resolver rules that bypass this virtual switch. To resolve this, add dnsTunneling=true and autoProxy=true under [wsl2] in your .wslconfig file, then run wsl --shutdown in PowerShell. This routes guest DNS queries through the Windows virtualization socket directly into host networking APIs. If pings succeed but apt update or git clone hangs during TLS handshakes, corporate VPN encapsulation is clipping packet sizes. Clamp the guest interface by running sudo ip link set dev eth0 mtu 1400 to stop silent packet drops. For multi-interface routing on Windows 11 23H2 or 24H2, enable networkingMode=mirrored to mirror host adapters directly into Linux. You can generate this configuration using our WSL Configuration Generator.

+-----------------------------------------------------------------------------------+
|                                 WINDOWS 11 HOST                                   |
|                                                                                   |
|  +--------------------+   +-----------------------+   +------------------------+  |
|  | Physical NIC (Eth) |   | Corporate VPN Adapter |   | Windows Host Resolver  |  |
|  | MTU: 1500 bytes    |   | (Cisco / GP / Zscaler)|   | (NRPT / WinINet Proxy) |  |
|  +---------^----------+   | MTU: 1350-1400 bytes  |   +-----------^------------+  |
|            |              +-----------^-----------+               |               |
|            |                          |                           |               |
|  +---------+--------------------------+---------------------------+------------+  |
|  |              Hyper-V Virtual Network Switch (vEthernet WSL)                 |  |
|  |    • Default NAT: Isolated 172.x.x.1 gateway (Drops VPN DNS & split-tunnels)|  |
|  |    • Mirrored Mode: Shares Windows Host L2/L3 stack directly                |  |
|  +------------------------------------^----------------------------------------+  |
|                                       |                                           |
|       DNS Tunneling Enabled: Resolves via Windows Host APIs directly             |
|       NAT Default: Forwards raw UDP port 53 packets (Blocked by VPN firewalls)    |
+---------------------------------------|-------------------------------------------+
                                        |
+---------------------------------------|-------------------------------------------+
|                                  WSL2 GUEST VM                                    |
|                                                                                   |
|  +------------------------------------+----------------------------------------+  |
|  | eth0 Virtual Interface                                                      |  |
|  | Default MTU: 1500 bytes ──► [BOTTLENECK: Corporate VPN drops packets >1400] |  |
|  | Fixed MTU:   1400 bytes ──► [PASS: Clean TLS handshakes & apt downloads]     |  |
|  +------------------------------------+----------------------------------------+  |
|                                       |                                           |
|  +------------------------------------+----------------------------------------+  |
|  | Resolver Stack (/run/systemd/resolve/stub-resolv.conf -> /etc/resolv.conf)   |  |
|  | • DNS Tunneling: Queries routed to Windows virtualization socket               |  |
|  | • Legacy NAT: Points to 172.x.x.1 (Fails on VPN disconnect/reconnect)          |  |
|  +-----------------------------------------------------------------------------+  |
+-----------------------------------------------------------------------------------+

WSL2 Network Triage Decision Matrix

Before applying random registry tweaks or editing Linux system files, test your failure symptoms against our team’s verified decision matrix:

Error SymptomDiagnostic ProbeFailure MechanismProven Fix
Temporary failure in name resolutionping 1.1.1.1 OK; getent hosts archive.ubuntu.com FAILSHost DNS proxy not forwarding queries from Hyper-V vSwitchAdd dnsTunneling=true in .wslconfig and run wsl --shutdown
Connection timed out on TLS / Port 443ping 1.1.1.1 OK; curl -I https://github.com HANGSCorporate VPN encapsulation drops packets larger than 1400 bytesClamp guest MTU: sudo ip link set dev eth0 mtu 1400
Network is unreachableip route empty or missing default gatewayHyper-V virtual switch corrupted or Host Network Service (HNS) deadRun wsl --shutdown and restart Windows hns service
407 Proxy Authentication Requiredcurl fails with HTTP 407 / 502 Bad GatewayStale Windows corporate proxy environment variables passed to WSLClear stale exports: unset HTTP_PROXY HTTPS_PROXY
Localhost dev server unreachableBrowser on Windows cannot open localhost:3000Port collision in Mirrored mode or broken NAT loopbackAdd hostAddressLoopback=true or bind server to 0.0.0.0
Resolv.conf keeps resetting to 172.x.x.1Manual edits in /etc/resolv.conf wiped on rebootWSL automatically regenerates resolver from virtual switch stateSet generateResolvConf=false in /etc/wsl.conf

Microsoft’s WSL troubleshooting documentation confirms that a working shell does not prove that the WSL virtual network or DNS path is healthy. According to Microsoft, DNS tunneling is especially relevant when VPN behavior differs between Windows and WSL2.

The safest way to isolate the fault is to separate three distinct layers:

  1. Does Windows itself have internet access and resolve DNS?
  2. Can WSL reach external IP addresses via raw routing?
  3. Can WSL resolve hostnames through the DNS proxy?

Do these checks in order. Do not start by deleting your Linux distribution or replacing /etc/resolv.conf with a random public DNS server.

1. Check whether Windows is the problem

Test the Windows host first; WSL cannot repair a host connection, VPN, or firewall that is already failing.

Open Settings > Network & internet in Windows and confirm the host can browse before testing the Linux side.

Open a normal PowerShell window in Windows and run:

# PowerShell: test the Windows host before opening WSL2
Test-NetConnection 1.1.1.1 -Port 443
Resolve-DnsName archive.ubuntu.com

If both commands fail, WSL is not the first thing to repair. Fix the Windows connection, captive portal, VPN, firewall, or Wi-Fi connection first.

If Windows works, open your WSL distribution and test the Linux side:

# WSL2 shell: separate IP reachability, DNS, and HTTPS
ip route
getent hosts archive.ubuntu.com
curl -I --max-time 10 https://archive.ubuntu.com

The results tell you where to focus:

ResultLikely boundaryNext step
Windows and WSL both failHost connection, VPN, or firewallRepair Windows networking first
IP traffic works but hostnames failDNS pathTry DNS tunneling and restart WSL
DNS works but HTTPS failsProxy, firewall, certificate, or VPNCheck proxy and security software
Only one distribution failsDistro configurationInspect its wsl.conf and resolver behavior

2. Restart WSL cleanly and update it

Use wsl --shutdown to reset the lightweight VM and virtual-network state without deleting the distribution.

WSL keeps a lightweight virtual machine and a Windows networking layer alive between shells. A normal exit does not reset either one.

From PowerShell, run:

# PowerShell: restart the WSL2 runtime without unregistering a distro
wsl --shutdown
wsl --update
wsl --status

Start the distribution again and repeat the getent and curl tests. This clears stale virtual-network state without changing your Linux files.

3. Enable DNS Tunneling and Auto-Proxy in .wslconfig

DNS tunneling routes Linux queries through the Windows virtualization socket directly into Windows Host DNS APIs, bypassing VPN route-table overrides.

By default in legacy NAT mode, WSL2 acts like a separate router. It spins up a virtual DNS proxy on 172.x.x.1 and forwards raw UDP/TCP port 53 packets through Hyper-V. When you connect to an enterprise VPN (such as Cisco AnyConnect, Palo Alto GlobalProtect, or Zscaler), the VPN driver injects strict Name Resolution Policy Table (NRPT) rules that bind exclusively to the Windows host TAP/TUN adapter. The Hyper-V virtual switch is left out in the cold, causing every domain lookup in Linux to return Temporary failure in name resolution.

To fix this natively on Windows 11 (22H2 build 22621+ and newer), Microsoft introduced DNS Tunneling. Instead of sending raw network packets across a virtual gateway, WSL sends name resolution requests via an internal virtualization communications channel (VMBus) directly to Windows host APIs.

Create or open %UserProfile%\.wslconfig in Windows (e.g. C:\Users\<YourUsername>\.wslconfig) and add:

# %UserProfile%\.wslconfig
[wsl2]
dnsTunneling=true
autoProxy=true

Save the file, then open PowerShell in Windows and bounce the WSL runtime:

# PowerShell (Windows): reload .wslconfig settings
wsl --shutdown

Relaunch your Linux distribution and test name resolution:

# WSL2 shell: verify DNS resolution through host tunnel
cat /etc/resolv.conf
getent hosts archive.ubuntu.com
curl -I --max-time 10 https://archive.ubuntu.com

Workbench Rule: Do not touch /etc/resolv.conf or disable generateResolvConf in /etc/wsl.conf while testing DNS tunneling. WSL needs to generate its internal tunnel stub to bridge into the Windows host resolver.

Pro Tip: Does your virtual machine also hoard memory during builds? Pair these network flags with our WSL2 vmmem auto memory reclaim guide. You can also build your complete config with our interactive WSL Configuration Generator.

4. Fix Corporate VPN MTU Packet Clipping

If ping 1.1.1.1 passes but apt update, git clone, or curl hangs during TLS handshakes, clamp the Linux interface MTU to 1400.

On our workbench, this was the single most baffling failure our engineers encountered when testing developer laptops connected to Palo Alto GlobalProtect and Cisco AnyConnect. Raw ICMP pings to public IP addresses worked instantly, but running sudo apt update or cloning a GitHub repository over HTTPS stalled indefinitely at 0% [Connecting to archive.ubuntu.com] before timing out after 120 seconds.

Here is what happens under the hood:

  1. The Handshake Passes: Small TCP SYN/ACK packets (40–60 bytes) traverse the VPN tunnel without friction.
  2. The TLS Certificate Chokes: When the remote web server responds with its SSL/TLS certificate chain or package repository headers, the packet size expands to the standard Ethernet Maximum Transmission Unit (MTU 1500 bytes).
  3. The Silent Drop: Corporate VPN encapsulation headers (IPsec ESP or TLS tunneling) add 50 to 100 bytes of overhead. The physical network path can only handle an MTU of ~1350 to 1420 bytes. Because many corporate enterprise firewalls drop ICMP “Fragmentation Needed” packets (Type 3, Code 4), Path MTU Discovery (PMTUD) fails. Your packets vanish into a silent black hole.

To test and immediately resolve MTU clipping inside WSL2:

# WSL2 shell: inspect current MTU on virtual interface
ip link show eth0

# Temporarily clamp MTU from 1500 to 1400
sudo ip link set dev eth0 mtu 1400

# Test HTTPS connection immediately
curl -I --max-time 10 https://github.com

If curl immediately succeeds, you have verified MTU clipping. Because WSL2 regenerates eth0 whenever the Hyper-V micro-VM restarts, make the fix persistent by creating a lightweight systemd one-shot service:

# WSL2 shell: create persistent MTU clamping service
sudo tee /etc/systemd/system/wsl-mtu.service << 'EOF'
[Unit]
Description=Clamp WSL2 eth0 MTU for Corporate VPN Compatibility
After=network.target

[Service]
Type=oneshot
ExecStart=/sbin/ip link set dev eth0 mtu 1400
RemainAfterExit=yes

[Install]
WantedBy=multi-user.target
EOF

# Enable and start the service
sudo systemctl daemon-reload
sudo systemctl enable --now wsl-mtu.service

5. Enable Mirrored Networking on Windows 11 (23H2 / 24H2)

Mirrored mode synchronizes Windows host network interfaces directly into Linux, resolving VPN split-tunnels and multi-interface routing out of the box.

Traditional WSL2 networking creates an internal virtual NAT switch. The Linux guest lives in its own private subnet (typically 172.x.x.x) with its own virtual MAC address. While this isolates Linux, it breaks down in modern enterprise environments:

  • VPN clients that enforce zero-trust split-tunneling drop traffic originating from unknown subnets.
  • IPv6 packets fail because Hyper-V NAT lacks native IPv6 stateful routing.
  • Local Area Network (LAN) devices cannot reach web servers or APIs running inside WSL without complex netsh interface portproxy rules.

On Windows 11 23H2 and 24H2 (WSL version 2.0.0+), Microsoft introduced Mirrored Networking (networkingMode=mirrored). When enabled, Linux network interfaces mirror the Windows host physical, Wi-Fi, and VPN adapters 1-to-1. Linux gets the exact same IP addresses as Windows.

To configure production-grade Mirrored Networking, update %UserProfile%\.wslconfig:

# %UserProfile%\.wslconfig
[wsl2]
networkingMode=mirrored
dnsTunneling=true
autoProxy=true
hostAddressLoopback=true
ignoredPorts=3000,8080

Mirrored Mode Configuration Breakdown:

  1. networkingMode=mirrored: Linux shares the host network interfaces, resolving VPN split-tunneling and IPv6.
  2. dnsTunneling=true: Routes DNS through host APIs rather than raw NAT packet proxying.
  3. autoProxy=true: Translates Windows WinINet corporate HTTP proxy settings into Linux environment variables.
  4. hostAddressLoopback=true: Lets Linux containers and Windows host applications connect to 127.0.0.1 without extra port forwarding.
  5. ignoredPorts=3000,8080: Prevents port collisions. In mirrored mode, Windows and Linux share the port space. If a Node.js server runs on Windows port 3000, WSL cannot bind to port 3000 unless specified in ignoredPorts.

After editing .wslconfig, reload the runtime from PowerShell:

# PowerShell: apply mirrored networking
wsl --shutdown

6. Clear Stale Corporate Proxy Environment Variables

A stale corporate proxy variable will make WSL look completely offline even when DNS and IP routing are 100% operational.

When you connect your laptop to an office network or corporate VPN, Windows or your shell profile may export proxy variables (HTTP_PROXY, HTTPS_PROXY, ALL_PROXY). If you disconnect from the VPN or take your machine home, Linux continues attempting to route curl and package manager requests to a dead internal proxy gateway (e.g. http://proxy.corp.internal:8080), producing HTTP 407 Proxy Authentication Required or Failed to connect to proxy port.

Inspect active proxy variables inside your Linux shell:

# WSL2 shell: audit inherited proxy variables
env | grep -iE '^(http|https|all|no)_proxy='

If stale proxy definitions appear, flush them for the current session:

# WSL2 shell: flush session proxy variables
unset HTTP_PROXY HTTPS_PROXY http_proxy https_proxy ALL_PROXY all_proxy
curl -I --max-time 10 https://github.com

If internet connectivity immediately resumes, permanently remove the stale export lines from ~/.bashrc, ~/.zshrc, ~/.profile, or /etc/environment.

Never edit /etc/resolv.conf directly without disabling automatic generation in /etc/wsl.conf; otherwise, WSL wipes your changes on every restart.

A common piece of bad advice on forums is to delete /etc/resolv.conf and replace it with nameserver 8.8.8.8 or nameserver 1.1.1.1. On modern Ubuntu (22.04 LTS and 24.04 LTS), /etc/resolv.conf is not a static flat file—it is a symbolic link pointing to /run/systemd/resolve/stub-resolv.conf managed by systemd-resolved.

Every time WSL boots, the Microsoft init process regenerates /etc/resolv.conf with the Hyper-V virtual gateway IP (nameserver 172.x.x.1). If you write over it, your changes disappear the next time you open a terminal.

If your corporate security policy strictly mandates a custom static DNS server (and DNS tunneling cannot be used), here is the supported, persistent method:

First, instruct WSL to stop overwriting the resolver by editing /etc/wsl.conf inside Linux:

# /etc/wsl.conf
[network]
generateResolvConf = false

Next, remove the stale symlink and write your static nameservers:

# WSL2 shell: unlink and configure static nameservers
sudo rm -f /etc/resolv.conf
sudo tee /etc/resolv.conf << 'EOF'
nameserver 1.1.1.1
nameserver 8.8.8.8
options timeout:2 attempts:3 rotate
EOF

# Lock file attributes against inadvertent overwrites
sudo chattr +i /etc/resolv.conf

From PowerShell, restart WSL with wsl --shutdown.

8. Reset Hyper-V Switch and Windows Filtering

When the Hyper-V virtual switch corrupts or Windows Defender Firewall blocks the virtual interface, restart the Host Network Service (HNS).

If both raw IP pings and DNS fail inside WSL2, but the Windows host browses the web normally, the Hyper-V virtual network switch (vEthernet (WSL)) or the Windows Filtering Platform (WFP) filter driver has stalled. This frequently happens after waking a laptop from sleep, docking/undocking from Thunderbolt stations, or hot-swapping Wi-Fi networks.

To cleanly reset the virtual networking stack without rebooting Windows:

Open an elevated Administrator PowerShell prompt and execute:

# Administrator PowerShell: restart virtual network switch services
wsl --shutdown
Stop-Service -Name hns -Force
Start-Service -Name hns
Get-Service -Name hns | Select-Object Name, Status

Next, verify that Windows Defender Firewall is not blocking the WSL virtual switch interface:

# Administrator PowerShell: verify WSL firewall rule
Get-NetFirewallRule -DisplayName "*WSL*" | Select-Object DisplayName, Enabled, Direction, Action

If corporate firewall policies have disabled the rule, re-enable it:

# Administrator PowerShell: re-enable WSL inbound traffic rule
Set-NetFirewallRule -DisplayName "*WSL*" -Enabled True

9. Automated WSL2 Network Diagnostic Script

Run our automated health probe in PowerShell to isolate host, virtual switch, guest routing, DNS tunneling, and MTU clipping in 5 seconds.

On our workbench, we run this non-destructive diagnostic probe across every developer machine to instantly pinpoint which layer of the network stack is broken. It runs in standard user PowerShell without requiring administrator elevation:

# ====================================================================
# PraveenTechWorld - WSL2 Complete Network Health Probe
# Script: Test-WSLNetworkStack.ps1 (Non-destructive diagnostic probe)
# ====================================================================

Clear-Host
Write-Host "========================================================" -ForegroundColor Cyan
Write-Host "     PraveenTechWorld WSL2 Network Health Diagnostic    " -ForegroundColor Cyan
Write-Host "========================================================" -ForegroundColor Cyan

# 1. Host Connectivity
Write-Host "`n[1/5] Testing Windows 11 Host Connectivity..." -ForegroundColor Yellow
$hostPing = Test-Connection -ComputerName 1.1.1.1 -Count 1 -Quiet
$hostDns  = try { [bool](Resolve-DnsName archive.ubuntu.com -QuickTimeout -ErrorAction Stop) } catch { $false }

Write-Host "  Host Internet (1.1.1.1): $(if($hostPing){'PASS'}else{'FAIL'})" -ForegroundColor (if($hostPing){'Green'}else{'Red'})
Write-Host "  Host DNS (Public FQDN):  $(if($hostDns){'PASS'}else{'FAIL'})" -ForegroundColor (if($hostDns){'Green'}else{'Red'})

if (-not $hostPing) {
    Write-Host "`n[FATAL] Windows 11 host has no internet. Fix Wi-Fi or VPN connection first." -ForegroundColor Red
    return
}

# 2. .wslconfig Inspection
Write-Host "`n[2/5] Inspecting %UserProfile%\.wslconfig..." -ForegroundColor Yellow
$wslConfigPath = "$env:USERPROFILE\.wslconfig"
if (Test-Path $wslConfigPath) {
    $content = Get-Content $wslConfigPath -Raw
    $hasDnsTunnel = $content -match "dnsTunneling\s*=\s*true"
    $hasMirrored  = $content -match "networkingMode\s*=\s*mirrored"
    Write-Host "  Configuration File:   FOUND ($wslConfigPath)" -ForegroundColor Green
    Write-Host "  dnsTunneling Enabled: $($hasDnsTunnel)" -ForegroundColor (if($hasDnsTunnel){'Green'}else{'Yellow'})
    Write-Host "  Mirrored Mode Active: $($hasMirrored)" -ForegroundColor (if($hasMirrored){'Green'}else{'Gray'})
} else {
    Write-Host "  Configuration File:   MISSING (Legacy NAT active)" -ForegroundColor Yellow
    Write-Host "  -> Recommended: Create .wslconfig with dnsTunneling=true" -ForegroundColor Yellow
}

# 3. WSL2 Guest Routing & DNS
Write-Host "`n[3/5] Probing WSL2 Guest VM Network Stack..." -ForegroundColor Yellow
try {
    $wslPing = wsl -e ping -c 1 -W 2 1.1.1.1 2>$null
    $wslPingOk = ($LASTEXITCODE -eq 0)
    Write-Host "  WSL2 Raw IP Routing:  $(if($wslPingOk){'PASS'}else{'FAIL'})" -ForegroundColor (if($wslPingOk){'Green'}else{'Red'})

    $wslDns = wsl -e getent hosts archive.ubuntu.com 2>$null
    $wslDnsOk = ($LASTEXITCODE -eq 0)
    Write-Host "  WSL2 DNS Resolution:  $(if($wslDnsOk){'PASS'}else{'FAIL'})" -ForegroundColor (if($wslDnsOk){'Green'}else{'Red'})
} catch {
    Write-Host "  [ERROR] WSL runtime could not be queried. Is WSL installed?" -ForegroundColor Red
    return
}

# 4. MTU & TLS Handshake Probe
Write-Host "`n[4/5] Probing Corporate VPN MTU & TLS Handshakes..." -ForegroundColor Yellow
$wslCurl = wsl -e curl -I --max-time 5 https://github.com 2>$null
$wslCurlOk = ($LASTEXITCODE -eq 0)
Write-Host "  WSL2 HTTPS / TLS:     $(if($wslCurlOk){'PASS'}else{'FAIL'})" -ForegroundColor (if($wslCurlOk){'Green'}else{'Red'})

# 5. Final Automated Triage Verdict
Write-Host "`n[5/5] Automated Triage Verdict:" -ForegroundColor Yellow
if ($wslPingOk -and $wslDnsOk -and $wslCurlOk) {
    Write-Host "  [STATUS: 100% OPERATIONAL] WSL2 network stack is healthy!" -ForegroundColor Green
} elseif ($wslPingOk -and -not $wslDnsOk) {
    Write-Host "  [DIAGNOSIS] DNS proxy failure. Add 'dnsTunneling=true' to $wslConfigPath and run 'wsl --shutdown'." -ForegroundColor Yellow
} elseif ($wslPingOk -and $wslDnsOk -and -not $wslCurlOk) {
    Write-Host "  [DIAGNOSIS] Corporate VPN MTU clipping detected! Run 'sudo ip link set dev eth0 mtu 1400' in WSL." -ForegroundColor Yellow
} elseif (-not $wslPingOk) {
    Write-Host "  [DIAGNOSIS] Virtual switch routing failure. Run 'wsl --shutdown' and restart HNS service." -ForegroundColor Red
}
Write-Host "========================================================" -ForegroundColor Cyan

Save this script as Test-WSLNetworkStack.ps1 in your dev toolkit to run whenever switching between office VPN profiles and home Wi-Fi networks.

What Not To Do

  • Do not run wsl --unregister <Distro> as a network troubleshooting step. Unregistering permanently wipes your entire Linux filesystem, installed packages, and local databases.
  • Do not blindly paste Google DNS (8.8.8.8) into /etc/resolv.conf on a corporate laptop. Many enterprise VPNs block outbound port 53 traffic to non-corporate DNS servers, making your problem worse.
  • Do not disable Windows Defender Firewall globally. Modern Windows 11 updates rely on WFP rules for Hyper-V packet filtering; turning off the firewall breaks virtual switch routing.
  • Do not mix manual DNS edits with DNS tunneling. If generateResolvConf=false is set in /etc/wsl.conf, DNS tunneling cannot update the guest stub resolver.

To maintain stable WSL2 networking on Windows 11, configure dnsTunneling=true and autoProxy=true in %UserProfile%\.wslconfig. When working behind Cisco, GlobalProtect, or Zscaler, clamp your eth0 MTU to 1400. Reserve Mirrored mode for environments requiring multi-interface or local LAN discovery.

This guide is part of our Windows 11 Developer Performance & WSL2 runbook cluster. For containerized workflows and developer environments, explore our companion workbench guides:


WSL2 Networking FAQ

Why does WSL2 say temporary failure in name resolution?

The WSL virtual network is unable to reach the Windows DNS proxy (172.x.x.1). This commonly occurs when a corporate VPN (Cisco AnyConnect, GlobalProtect, Zscaler) routes host traffic through strict split-tunnel NRPT policies that Hyper-V’s NAT switch cannot access. Enabling DNS tunneling routes queries directly through the host Windows network stack.

How do corporate VPNs break WSL2 internet?

VPN clients rewrite Windows routing tables and enforce strict Name Resolution Policy Tables (NRPT) on the host virtual adapter. Because WSL2 defaults to an internal Hyper-V NAT switch, guest packets cannot traverse the VPN tunnel without DNS tunneling (dnsTunneling=true) or MTU clamping (lowering MTU from 1500 to 1400).

Should I use Mirrored Networking (networkingMode=mirrored) in WSL2?

Mirrored networking mirrors Windows network interfaces directly into Linux, resolving VPN compatibility and multi-interface routing out of the box. It requires Windows 11 23H2 or 24H2 and may cause port conflicts if Windows and WSL both try to bind to identical ports (e.g., 3000 or 8080).

Why does ping 1.1.1.1 work in WSL2, but curl and apt update fail?

If raw IP pings succeed but curl, apt, or git clone stall indefinitely, you either have a DNS resolution failure (test with getent hosts) or a VPN MTU mismatch. When the corporate VPN limits packet size, small ICMP ping packets pass, but large TLS/SSL handshake packets exceed MTU and are silently dropped.

Will editing /etc/resolv.conf permanently fix WSL2 DNS?

No. WSL automatically regenerates /etc/resolv.conf on every reboot based on Hyper-V virtual switch state. To manage DNS manually, you must add [network] generateResolvConf=false to /etc/wsl.conf before creating a static resolv.conf. However, enabling dnsTunneling=true in .wslconfig is Microsoft’s supported fix.

How do I fix MTU packet drops in WSL2 under a VPN?

Run sudo ip link set dev eth0 mtu 1400 inside your WSL distribution. Corporate VPN encapsulation adds 50 to 100 bytes of overhead to IP packets; clamping eth0 MTU to 1400 prevents packet fragmentation and silent TLS connection timeouts.

Hardware & RepairSponsored Diagnostic Tools
Free PowerShell & Sysadmin Toolkit

Get Our Sysadmin & AI Runbooks Direct to Your Inbox

Join 2,500+ engineers receiving our weekly PowerShell automation scripts, root cause analyses, and hardware diagnostic playbooks.

Zero spam. Unsubscribe anytime in 1 click.

Frequently Asked Questions: WSL2 No Internet on Windows 11? 5 DNS & VPN Fixes

Why does WSL2 say temporary failure in name resolution?
The WSL virtual network is unable to reach the Windows DNS proxy (172.x.x.1). This commonly occurs when a corporate VPN (Cisco AnyConnect, GlobalProtect, Zscaler) routes host traffic through strict split-tunnel NRPT policies that Hyper-V's NAT switch cannot access. Enabling DNS tunneling routes queries directly through the host Windows network stack.
How do corporate VPNs break WSL2 internet?
VPN clients rewrite Windows routing tables and enforce strict Name Resolution Policy Tables (NRPT) on the host virtual adapter. Because WSL2 defaults to an internal Hyper-V NAT switch, guest packets cannot traverse the VPN tunnel without DNS tunneling (dnsTunneling=true) or MTU clamping (lowering MTU from 1500 to 1400).
Should I use Mirrored Networking (networkingMode=mirrored) in WSL2?
Mirrored networking mirrors Windows network interfaces directly into Linux, resolving VPN compatibility and multi-interface routing out of the box. It requires Windows 11 23H2 or 24H2 and may cause port conflicts if Windows and WSL both try to bind to identical ports (e.g., 3000 or 8080).
Why does ping 1.1.1.1 work in WSL2, but curl and apt update fail?
If raw IP pings succeed but curl, apt, or git clone stall indefinitely, you either have a DNS resolution failure (test with getent hosts) or a VPN MTU mismatch. When the corporate VPN limits packet size, small ICMP ping packets pass, but large TLS/SSL handshake packets exceed MTU and are silently dropped.
Will editing /etc/resolv.conf permanently fix WSL2 DNS?
No. WSL automatically regenerates /etc/resolv.conf on every reboot based on Hyper-V virtual switch state. To manage DNS manually, you must add [network] generateResolvConf=false to /etc/wsl.conf before creating a static resolv.conf. However, enabling dnsTunneling=true in .wslconfig is Microsoft's supported fix.
How do I fix MTU packet drops in WSL2 under a VPN?
Run 'sudo ip link set dev eth0 mtu 1400' inside your WSL distribution. Corporate VPN encapsulation adds 50 to 100 bytes of overhead to IP packets; clamping eth0 MTU to 1400 prevents packet fragmentation and silent TLS connection timeouts.

Official Technical References

  1. Troubleshooting Windows Subsystem for Linux — Microsoft Learn
  2. WSL configuration settings — MicrosoftDocs
  3. WSL localhost networking and Mirrored Mode — Microsoft WSL
Get Independent Tech Benchmarks First

Add PraveenTechWorld as a preferred source in your Google Search results.

Prefer on Google
P
Praveen

IT ops lead in India. I break Windows, Android and self-hosted AI stacks on my workbench, then write down what actually fixed them.

Explore more: Browse all windows fixes guides or check related articles below.