Unable to update templates

66 views
Skip to first unread message

jkitt

unread,
Jul 19, 2016, 9:34:40 AM7/19/16
to qubes-users
I am unable to update either of my templates. Debian tries to connect to 10.137.255.254; none of my VMs have that IP. Why is it trying to connect to that - is it an update proxy? Fedora tries to do the same.

I can ping google.com on both systems and I can also run an update in appvms.

Andrew David Wong

unread,
Jul 19, 2016, 1:56:48 PM7/19/16
to jkitt, qubes-users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Just to check, is the "Allow connections to Updates Proxy" box checked
on the "Firewall rules" tab?

Also, what is the NetVM of your TemplateVM?

Have you made any modifications to the base installation that might be
relevant?

- --
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJXjmnWAAoJENtN07w5UDAwhzIQAIKNNfzZ0mruLaFDHVis6G28
zXaUR1uS7TjUqV+4qnVt0Gcd498NJ36zwO3BBm6KnyHDLaGiBmhKvj9rJaOn8Io6
PzUQUXkH9jZh9cBhCCot/at0kr7EgZOwUNypI0HvBOaZfDMiDbWTh+GJ1lo2hkgZ
Voti2zfHgM3KqvjkcWOvmoOfHG8FWpy9yMREsdGnQlb8mq7NZoHIGMMEv4OWLcg+
oYbxa4l6tgMIo87YzIpXo07xTkSCsktRBRHPR1sCCA3SSpgVrbZZKVthv8fRc4s+
P6uaXhlbFcAEfZ7Lh4bjW9hBQR9LTeu4gTvGW+UV2ZTSW+Ppt79no79t0LSZH8Ox
42Di1Ri9fzNb9v9tnsvrcyUqnCGwpzf4fM6FPuMs+52zDBxHis5tcTFj1MNYZaIK
0Fci0WmkzuR/boldJ2IY4c+GliiARRUCXy/dfB7qwkFO/y9fDtnOPxSby1JEZCSn
C2Mj1zVhlynMCOvfeEeWKGcrOC4pXFs4jC9+kUlsCxh8/A5Ax10H37h2isgNBy97
oK1ZW6BsCOlS8hhYvVaHPw/FiIsGKoiRv2/tCT4hTyMQ9b5o5ofajVwVmWyi1jmP
Xxpw2zsoOrmHDo37ZmQdB3Y6gn5xyWlyU1xxkBmlXIOO6lA1wdOD2GfoW/WYh3N2
pFwpAqDj92FCos4NNxwr
=+tHX
-----END PGP SIGNATURE-----

jkitt

unread,
Jul 20, 2016, 1:20:01 PM7/20/16
to qubes-users, jazzki...@gmail.com
My netvm is a proxyvm that I've set up. I've just found out about the global in which the updatevm can be changed. However, i've set this to my VPN VM yet nothing - it's still trying to connect to the same IP. IRRC that IP is a non-existent node but it's filtered by a proxy. How do i get that proxy running on my VPN VM?

Chris Laprise

unread,
Jul 20, 2016, 3:44:03 PM7/20/16
to qubes...@googlegroups.com
Its typical for a VPN to block template updates. This is because the
update proxy normally runs in sys-net, which can no longer see the
attempt to connect to the update proxy port number (sys-net only sees
encrypted stream from VPN).

Quick workaround is to set your connection so it looks like: Template ->
sys-firewall -> sys-net.


Chris
Reply all
Reply to author
Forward
0 new messages