I have an Oracle Linux guest running a web server in VirtualBox on a Windows 7 Host. I need to set the networking up so that I can do 3 things:
- the host can connect to the guest through a browser and ssh
- the guest can talk to other servers on the internal network through the host's VPN
- the guest can reach the outside internet
I've read a few answers and tried a few configurations, and here's what happens:
Bridged
- host cannot reach guest
- guest cannot see through VPN
- guest can reach internet
NAT
- host cannot reach guest
- guest can see through VPN
- guest cannot reach internet
Host-Only
all 3 conditions fail.
NAT-Network
- host cannot reach guest
- guest can see through VPN
- guest cannot reach internet
I should also point out that sometimes the host is connected through a VPN while other times it is simply plugged directly into the corporate network. When it is plugged directly in, a bridged adapter satisfies all 3 conditions. Ideally, there would be a configuration that satisfies all 3 conditions regardless whether there's a VPN or a direct connection.
2 Answers
I had the exact same problem, and saw it through to resolution, so I'm happy to explain the problem and solution in detail.
Without Involving a VPN
It is important to understand the configuration that is required in order to meet your requirements without involving a VPN. Also, this information assumes that no software firewall is interfering, neither on the host nor the guest.
Without a VPN, this is normally solved by creating two network adapters in the virtual machine's configuration.
The first adapter must be set to NAT mode, which enables the guest to access network resources (including the Internet) through the host's network interface.
The second adapter must be set to Host-only, which enables bidirectional communication between the host and the guest.
This adapter is slightly more complex to setup than the first, because it requires modifying VirtualBox's global networking preferences in order to configure the host-only adapter (note: this requires Administrator privileges).
In VirtualBox, go to File -> Preferences -> Network. Click the Host-only Networks tab and click the little + icon to add a new adapter. You will be prompted to elevate VirtualBox's permissions.
Filling-out the Adapter tab is mandatory; it should look something like this (ignore the adapter labeled #2; that's used for something unrelated):
The values on the DHCP server tab are optional. If you're intending to hard-code the IP address for this adapter within the guest's networking configuration, then these values are unnecessary. If, on the other hand, you intend to use DHCP, the values might look something like this:
The last step with regard to configuring VirtualBox is to go back into the VM's network configuration and add the second adapter, which references the host-only adapter that we just created:
Now, in the guest operating system, the network must be configured to utilize these two network interfaces.
On Debian or Ubuntu GNU/Linux, the configuration is as simple as modifying /etc/network/interfaces to look like this:
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).
# The loopback network interface
auto lo
iface lo inet loopback
# The primary network interface
auto eth0
iface eth0 inet dhcp
# The secondary network interface
auto eth1
iface eth1 inet static
address 192.168.56.101
netmask 255.255.255.0
(the purist may prefer to utilize the /etc/network/interfaces.d directory instead, but that's beyond the scope of this explanation)
Restart the guest's networking services, or more simply, restart the entire guest VM, and everything should "just work".
At this point, one should be able to ping the guest VM at 192.168.56.101 and receive a reply (provided a software firewall is not interfering).
Likewise, one should be able to ping the host at 10.0.2.2. This IP address seems to be "hard-coded" into VirtualBox's NAT implementation, or at least specified via some non-obvious configuration directive, and there is little information available as to its origin. But, alas, "it just works".
Given this configuration, all three conditions outlined in your question are met.