WSL-2: Which ports are automatically forwarded?

Viewed 41626

I've been tinkering around with WSL-2 for a while now and don't exactly understand how traffic is routed between the host and WSL-2 dist.

In some sources it seems like all ports used by WSL-2 automatically become available to the host machine. Such as in this tutorial by Microsoft. Similarly I managed to host a Jupyter instance which is available directly on my host machine through localhost:8888.

However, when trying other services, such as ssh (also tried on a non-standard port) the port does not automatically become available through localhost and I have to use the IP address assigned to my WSL distro (the one from wsl hostname -I)

To make the services available through localhost I found this portforwarding script, which worked. But I would like to understand why it was needed.

Why is port forwarding needed for some services, but not all?

3 Answers

My confusion came from firewall issues with WSL-2.

What I have found is:

  • Services listening on ports in WSL-2 are accesible from the host machine as localhost:<port>
  • WSL-2 ports are not accessible from outside of the host machine
  • WSL-2 ports can be made available through netstat interface portproxy or other portforward tools using the ip address of the WSL instance.

The firewall did not allow acces to the WSL ports by just listing the ports. I had to specifcally select the iphlpsv service (IP Helper service) in my firewall rules to allow traffic through to the WSL instance.

When you run WSL-2, a machine like a vitural machin run on your window device. Windows will create a local network, same your LAN, and connect WLS-2 to this network.

  • On your WSL2, you can run ip a | grep eth0, result look like:

5: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000 inet 172.27.5.124/20 brd 172.27.15.255 scope global eth0

  • And on terminal (or PowerShell) on your windows, run ipconfig, find in the result, look like:
Ethernet adapter vEthernet (WSL):

   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::1532:a8ea:6b34:8df2%73
   IPv4 Address. . . . . . . . . . . : 172.27.0.1
   Subnet Mask . . . . . . . . . . . : 255.255.240.0
   Default Gateway . . . . . . . . . :

WSL-2 and Windows device on a same network, and WSL-2 not connect to your LAN.

My solution (use port forwarding on Windows)

Open terminal with Admin on Windows, and run script:

netsh interface portproxy set v4tov4 listenport=8888 listenaddress=0.0.0.0 connectport=8888 connectaddress=$(wsl hostname -I)

Following these steps helped me connect to my ports locally on Windows:

  1. use the script in here and change the ports to the ones that you need to forward. Save this file to a path.
  2. In wsl, sudo apt install net-tools
  3. In powershell (administrator mode), type ".\script.ps1" | powershell.exe -c -. This is to run the file. Right-clicking the file to "Run with powershell" won't work.
  4. To test that it works, in powershell, type netsh interface portproxy show v4tov4
Related