Connecting a usb nic and another laptop

90 views
Skip to first unread message

Mark Eubanks

unread,
Sep 4, 2017, 8:15:29 AM9/4/17
to qubes-users
I have created a NETVM and I have connect the usb nic to the vm and is working. It shows up in Connection manager and I can give it a static IP . So I've also connected a different physical laptop with a cross over cable to the usb nic going to the NETVM. Both nics are on the same network and I can ping from the NETVM to the physical but I don't get a reply from the NETVM. I can see both in both arp tables . Any ideas why the physical doesn't get a reply?

cez...@gmail.com

unread,
Sep 4, 2017, 8:54:39 AM9/4/17
to qubes-users
Den mandag den 4. september 2017 kl. 12.15.29 UTC skrev Mark Eubanks:
> I have created a NETVM and I have connect the usb nic to the vm and is working. It shows up in Connection manager and I can give it a static IP . So I've also connected a different physical laptop with a cross over cable to the usb nic going to the NETVM. Both nics are on the same network and I can ping from the NETVM to the physical but I don't get a reply from the NETVM. I can see both in both arp tables . Any ideas why the physical doesn't get a reply?

Sounds like its a firewall that blocks incoming connections which wasn't established first by an outgoing connection? Are there any firewalls between? It doesn't sound like you put a firewall between them, but on the other hand, the ping behaviour does on the contrary sound a lot like a firewall.

Also if moving a lot of files is your goal, perhaps you might want try www.Syncthing.net (free, open source). You will have to allow it through the firewall though, or alternatively do it on a separate connection like you're doing now.
Optionally if syncthing is running where internet is accessible, you can disable the global discovery in syncthing.

Mark Eubanks

unread,
Sep 4, 2017, 9:11:49 AM9/4/17
to qubes-users
On Monday, September 4, 2017 at 8:15:29 AM UTC-4, Mark Eubanks wrote:
> I have created a NETVM and I have connect the usb nic to the vm and is working. It shows up in Connection manager and I can give it a static IP . So I've also connected a different physical laptop with a cross over cable to the usb nic going to the NETVM. Both nics are on the same network and I can ping from the NETVM to the physical but I don't get a reply from the NETVM. I can see both in both arp tables . Any ideas why the physical doesn't get a reply?

I agree it sounds like a firewall but I see that it shows allow imcp traffic. What I'm trying to do is make Qubes a passthrough firewall.. so I need 2 nics on the laptop

Mark Eubanks

unread,
Sep 4, 2017, 11:50:16 AM9/4/17
to qubes-users
BUMP -- anyone know why the virtual can ping out but the outside can't ping in?

On Monday, September 4, 2017 at 8:15:29 AM UTC-4, Mark Eubanks wrote:

Mark Eubanks

unread,
Sep 4, 2017, 11:51:04 AM9/4/17
to qubes-users
On Monday, September 4, 2017 at 8:15:29 AM UTC-4, Mark Eubanks wrote:

cez...@gmail.com

unread,
Sep 4, 2017, 12:37:03 PM9/4/17
to qubes-users

Apologies for late reply, had a short leave for work.

I'm not the most knowledgeable on this topic, especially the Qubes firewalls. However I believe NetVM must have a default firewall too, to block unauthorized requests, otherwise it would be quite simple and too easy to attack the NetVM.
So it seems to me that the NetVM has a default firewall, (routor firewall behavior like), blocking unauthorized incoming signals.

To solve that (Assuming it is indeed the problem), I believe https://www.qubes-os.org/doc/firewall/ might be quite helpful, down in the port forwarding section. Here it seems you should be able to poke a hole for your connection in the NetVM.

You separated all this from your other networks right? As far as I know, it should be secure enough if this has no internet connection, while on a separate Qubes network.

Unman

unread,
Sep 4, 2017, 2:01:55 PM9/4/17
to Mark Eubanks, qubes-users
No need to bump - a little patience is a good thing.

run 'iptables -L -nv' on the netvm - look at the INPUT chain.
The incoming ping is dropped there.

In 3.2 each qubes has its own iptables rules in addition to those set upstream
by the firewall mechanism. You can customise these if you wish by
manipulation from /rw/config using rc.local and
qubes-firewall-user-script

unman

Mark Eubanks

unread,
Sep 4, 2017, 2:06:12 PM9/4/17
to qubes-users, cez...@gmail.com
Thanks for responding. I'm sure its a firewall issue of some sorts. it doesn't matter which nic I use, the onboard one or the usb I can ping from either to the private network outside the vmNETwork fine pinging the adaptors connected to the Dom0 doesn't get a reply. It should be a routing issue that the link you sent might fix but the funny thing is that I have Qubes plugged into my modem switch and I can see it in the arp table , which you would think I could ping it

thanks for trying

Reply all
Reply to author
Forward
0 new messages