Firewall blocks network traffic for Windows Subsystem for Linux v2 and Windows Sandbox - Endpoint Protection
search cancel

Firewall blocks network traffic for Windows Subsystem for Linux v2 and Windows Sandbox - Endpoint Protection

book

Article ID: 221329

calendar_today

Updated On:

Products

Endpoint Protection Endpoint Security

Issue/Introduction

When using Windows Subsystem for Linux version 2 (WSL2) or the Windows Sandbox feature within Windows 10, network connections to external hosts fail.  The Endpoint Protection (SEP) firewall shows a remote connection block for the WSL2 or Windows Sandbox IP address.  

Cause

The SEP firewall uses multiple drivers to track running applications and network connections on Windows systems.  Both WSL2 and Windows Sandbox use Hyper-V technology to create a NAT'd connection from the host NIC to the guest NIC via virtual switches.  From a networking perspective, these are basically Hyper-V virtual machines.  The applications run within a guest VM and cannot be tracked by drivers running on the host operating system.  So for the SEP firewall running on the host operating system, this traffic will appear as unsolicited IP traffic and will be blocked.   

For Example

On WSL2, if you attempt to check for updates via apt, the outbound traffic from the host NIC will be blocked. 

8/6/2021 11:10:39AM Blocked Outgoing TCP security.ubuntu.com [91.000.00.00] 00-00-00-00-00-00 80 192.0.2.0 00-00-00-00-00-00 Block all other IP traffic and log 

Even if you allow all outbound traffic for the host IP address, the response from the repository going back to the WSL2 NIC will still be blocked.  

8/6/2021 3:55:35PM Blocked Incoming TCP 192.0.2.0 00-00-00-00-00-00 51658 91.000.00.00 00-00-00-00-00-00 80 Block all other IP traffic and log 

In addition, WSL2 and Windows Sandbox use dynamically generated network addresses each time they are launched, so any firewall rules created will need to be modified each time you use these features.  

Resolution

In order to allow traffic to your WSL2 and Sandbox instances, create a firewall rule to allow both the host MAC address and the WSL2 / Windows Sandbox MAC address as a source.  Put this rule above the "Block all other IP traffic" rule. 

  1. Open the Firewall policy on the SEPM.
  2. Click on Rules under the Windows Settings section
  3. In the Firewall rules window select Add Rule...
  4. Name the rule, click Next then select Allow connections, then Next and select All Applications.
  5. On the Select the Hosts screen, select Only the computers and sites listed below:, then click on Add... (see screenshot)
  6. In the Add Host screen use the drop down selector and select MAC address as the Address Type: (see screenshot)
  7. Enter the MAC address for the host, then click OK, then do the same for adding the MAC address of the WSL2 / Windows Sandbox. 
  8. Click Next through the remaining pages and make changes if needed. 
  9. Once this rule is completed, verify it is listed above the Block all other traffic rule in the list of Firewall rules.

Note:  This rule will need to be updated each time you start WSL2 or Windows Sandbox.  

Alternatively, you can disable the firewall policy or uninstall the firewall feature from the product. 

NOTE: If the above doesn't resolve the issue, double check the firewall rules and make sure they're properly applied to addresses, network interfaces, etc.