Автор Тема: P11 + VirtualBox v7.2.0 = Особенности разрешение имен для типа подключения NAT  (Прочитано 454 раз)

Оффлайн Linuxfan

  • Участник
  • *
  • Сообщений: 269
С предыдущей версией все работало по умолчанию, но теперь нет.
Шаги воспроизведения:
  • Установить пакет virtualbox
  • Создать виртуальную машину Other Linux (64-bit)
  • Проверить и установить для сетевого адаптера тип подключения NAT
  • Запустить в созданной ВМ стартеркит alt-p11-xfce-20250912-x86_64.iso
  • В терминале загруженного стартеркита выполнить команду ping ya.ru
Ожидаемый результат:
$ ping ya.ru
PING ya.ru (5.255.255.242) 56(84) bytes of data.
64 bytes from ya.ru (5.255.255.242): icmp_seq=1 ttl=240 time=12.7 ms
Полученный результат:
$ ping ya.ru
ping: ya.ru: Temporary failure in name resolution

$ ping 5.255.255.242
PING 5.255.255.242 (5.255.255.242) 56(84) bytes of data.
64 bytes from 5.255.255.242: icmp_seq=1 ttl=255 time=29.4 ms


Если в  ВМ вместо DHCP установить сервер dns вручную (8.8.8.8), то все работает
Если установить для сетевого адаптера ВМ тип подключения Сетевой мост, то все работает
« Последнее редактирование: 13.10.2025 00:06:57 от Linuxfan »

Оффлайн asy

  • alt linux team
  • ***
  • Сообщений: 8 647
А при чём тут VirtualBox и, вообще, тема с NAT? Если Вы задали DNS, он будет использоваться. Не задали - нет. У Вас DHCP-сервер кто? Он для клиента настройки DNS отдаёт? А клиент внутри виртуалки настроен как? Он эти настройки принимает?

Оффлайн Linuxfan

  • Участник
  • *
  • Сообщений: 269
А при чём тут VirtualBox и, вообще, тема с NAT?
Так Вы мои шаги воспроизвели? У Вас получился другой результат? Обязательно проверьте по возможности и поделитесь.
Если Вы задали DNS, он будет использоваться.
Конечно, если внутри ВМ в стартерките задать ДНС вместо автоматического по DHCP, то имена разрешаются без проблем.

Не задали - нет.
Так если все использовать по умолчанию, то  по DHCP почему-то не работает,

У Вас DHCP-сервер кто?
А кто может быть DHCP-сервер в только что созданной виртуалке с типом подключения NAT? Только сервис VirtualBox  :-)
https://www.virtualbox.org/manual/ch06.html#network_nat
Цитировать
Network Address Translation (NAT) is the simplest way of accessing an external network from a virtual machine. Usually, it does not require any configuration on the host network and guest system. For this reason, it is the default networking mode in Oracle VM VirtualBox.

Он для клиента настройки DNS отдаёт? А клиент внутри виртуалки настроен как?
Как он там настроен? А он вот так:
Спойлер
$ nmcli connection show Wired\ connection\ 1
connection.id:                          Wired connection 1
connection.uuid:                        7b99745f-fa27-3a49-beeb-785d5080a0da
connection.stable-id:                   --
connection.type:                        802-3-ethernet
connection.interface-name:              enp0s3
connection.autoconnect:                 yes
connection.autoconnect-priority:        -999
connection.autoconnect-retries:         -1 (default)
connection.multi-connect:               0 (default)
connection.auth-retries:                -1
connection.timestamp:                   1760290553
connection.permissions:                 --
connection.zone:                        --
connection.controller:                  --
connection.master:                      --
connection.slave-type:                  --
connection.port-type:                   --
connection.autoconnect-slaves:          -1 (default)
connection.autoconnect-ports:           -1 (default)
connection.down-on-poweroff:            -1 (default)
connection.secondaries:                 --
connection.gateway-ping-timeout:        0
connection.ip-ping-timeout:             0
connection.ip-ping-addresses:           --
connection.ip-ping-addresses-require-all:-1 (default)
connection.metered:                     unknown
connection.lldp:                        default
connection.mdns:                        -1 (default)
connection.llmnr:                       -1 (default)
connection.dns-over-tls:                -1 (default)
connection.mptcp-flags:                 0x0 (default)
connection.wait-device-timeout:         -1
connection.wait-activation-delay:       -1
802-3-ethernet.port:                    --
802-3-ethernet.speed:                   0
802-3-ethernet.duplex:                  --
802-3-ethernet.auto-negotiate:          no
802-3-ethernet.mac-address:             --
802-3-ethernet.cloned-mac-address:      --
802-3-ethernet.generate-mac-address-mask:--
802-3-ethernet.mac-address-denylist:    --
802-3-ethernet.mtu:                     auto
802-3-ethernet.s390-subchannels:        --
802-3-ethernet.s390-nettype:            --
802-3-ethernet.s390-options:            --
802-3-ethernet.wake-on-lan:             default
802-3-ethernet.wake-on-lan-password:    --
802-3-ethernet.accept-all-mac-addresses:-1 (default)
ipv4.method:                            auto
ipv4.dns:                               --
ipv4.dns-search:                        --
ipv4.dns-options:                       --
ipv4.dns-priority:                      0
ipv4.addresses:                         --
ipv4.gateway:                           --
ipv4.routes:                            --
ipv4.route-metric:                      -1
ipv4.route-table:                       0 (unspec)
ipv4.routing-rules:                     --
ipv4.replace-local-rule:                -1 (default)
ipv4.dhcp-send-release:                 -1 (default)
ipv4.routed-dns:                        -1 (default)
ipv4.ignore-auto-routes:                no
ipv4.ignore-auto-dns:                   no
ipv4.dhcp-client-id:                    --
ipv4.dhcp-iaid:                         --
ipv4.dhcp-dscp:                         --
ipv4.dhcp-timeout:                      0 (default)
ipv4.dhcp-send-hostname-deprecated:     yes
ipv4.dhcp-send-hostname:                -1 (default)
ipv4.dhcp-hostname:                     --
ipv4.dhcp-fqdn:                         --
ipv4.dhcp-hostname-flags:               0x0 (none)
ipv4.never-default:                     no
ipv4.may-fail:                          yes
ipv4.required-timeout:                  -1 (default)
ipv4.dad-timeout:                       -1 (default)
ipv4.dhcp-vendor-class-identifier:      --
ipv4.dhcp-ipv6-only-preferred:          -1 (default)
ipv4.link-local:                        0 (default)
ipv4.dhcp-reject-servers:               --
ipv4.auto-route-ext-gw:                 -1 (default)
ipv4.shared-dhcp-range:                 --
ipv4.shared-dhcp-lease-time:            0 (default)
ipv6.method:                            auto
ipv6.dns:                               --
ipv6.dns-search:                        --
ipv6.dns-options:                       --
ipv6.dns-priority:                      0
ipv6.addresses:                         --
ipv6.gateway:                           --
ipv6.routes:                            --
ipv6.route-metric:                      -1
ipv6.route-table:                       0 (unspec)
ipv6.routing-rules:                     --
ipv6.replace-local-rule:                -1 (default)
ipv6.dhcp-send-release:                 -1 (default)
ipv6.routed-dns:                        -1 (default)
ipv6.ignore-auto-routes:                no
ipv6.ignore-auto-dns:                   no
ipv6.never-default:                     no
ipv6.may-fail:                          yes
ipv6.required-timeout:                  -1 (default)
ipv6.ip6-privacy:                       -1 (default)
ipv6.temp-valid-lifetime:               0 (default)
ipv6.temp-preferred-lifetime:           0 (default)
ipv6.addr-gen-mode:                     default
ipv6.ra-timeout:                        0 (default)
ipv6.mtu:                               auto
ipv6.dhcp-pd-hint:                      --
ipv6.dhcp-duid:                         --
ipv6.dhcp-iaid:                         --
ipv6.dhcp-timeout:                      0 (default)
ipv6.dhcp-send-hostname-deprecated:     yes
ipv6.dhcp-send-hostname:                -1 (default)
ipv6.dhcp-hostname:                     --
ipv6.dhcp-hostname-flags:               0x0 (none)
ipv6.auto-route-ext-gw:                 -1 (default)
ipv6.token:                             --
proxy.method:                           none
proxy.browser-only:                     no
proxy.pac-url:                          --
proxy.pac-script:                       --
GENERAL.NAME:                           Wired connection 1
GENERAL.UUID:                           7b99745f-fa27-3a49-beeb-785d5080a0da
GENERAL.DEVICES:                        enp0s3
GENERAL.IP-IFACE:                       enp0s3
GENERAL.STATE:                          activated
GENERAL.DEFAULT:                        yes
GENERAL.DEFAULT6:                       yes
GENERAL.SPEC-OBJECT:                    --
GENERAL.VPN:                            no
GENERAL.DBUS-PATH:                      /org/freedesktop/NetworkManager/ActiveConnection/2
GENERAL.CON-PATH:                       /org/freedesktop/NetworkManager/Settings/2
GENERAL.ZONE:                           --
GENERAL.MASTER-PATH:                    --
IP4.ADDRESS[1]:                         10.0.2.15/24
IP4.GATEWAY:                            10.0.2.2
IP4.ROUTE[1]:                           dst = 10.0.2.0/24, nh = 0.0.0.0, mt = 100
IP4.ROUTE[2]:                           dst = 0.0.0.0/0, nh = 10.0.2.2, mt = 100
DHCP4.OPTION[1]:                        dhcp_client_identifier = 01:08:00:27:43:7c:6f
DHCP4.OPTION[2]:                        dhcp_lease_time = 86400
DHCP4.OPTION[3]:                        dhcp_server_identifier = 10.0.2.2
DHCP4.OPTION[4]:                        domain_name_servers = 127.0.0.1
DHCP4.OPTION[5]:                        expiry = 1760376952
DHCP4.OPTION[6]:                        ip_address = 10.0.2.15
DHCP4.OPTION[7]:                        next_server = 10.0.2.2
DHCP4.OPTION[8]:                        requested_broadcast_address = 1
DHCP4.OPTION[9]:                        requested_domain_name = 1
DHCP4.OPTION[10]:                       requested_domain_name_servers = 1
DHCP4.OPTION[11]:                       requested_domain_search = 1
DHCP4.OPTION[12]:                       requested_host_name = 1
DHCP4.OPTION[13]:                       requested_interface_mtu = 1
DHCP4.OPTION[14]:                       requested_ms_classless_static_routes = 1
DHCP4.OPTION[15]:                       requested_nis_domain = 1
DHCP4.OPTION[16]:                       requested_nis_servers = 1
DHCP4.OPTION[17]:                       requested_ntp_servers = 1
DHCP4.OPTION[18]:                       requested_rfc3442_classless_static_routes = 1
DHCP4.OPTION[19]:                       requested_root_path = 1
DHCP4.OPTION[20]:                       requested_routers = 1
DHCP4.OPTION[21]:                       requested_static_routes = 1
DHCP4.OPTION[22]:                       requested_subnet_mask = 1
DHCP4.OPTION[23]:                       requested_time_offset = 1
DHCP4.OPTION[24]:                       requested_wpad = 1
DHCP4.OPTION[25]:                       routers = 10.0.2.2
DHCP4.OPTION[26]:                       subnet_mask = 255.255.255.0
IP6.ADDRESS[1]:                         fd17:625c:f037:2:ad33:4c30:aa58:6846/64
IP6.ADDRESS[2]:                         fe80::d142:dae3:7705:601/64
IP6.GATEWAY:                            fe80::2
IP6.ROUTE[1]:                           dst = fe80::/64, nh = ::, mt = 1024
IP6.ROUTE[2]:                           dst = fd17:625c:f037:2::/64, nh = ::, mt = 100
IP6.ROUTE[3]:                           dst = ::/0, nh = fe80::2, mt = 100
Он эти настройки принимает?
Как на мой взгляд полностью. Но не резолвит  :-(
« Последнее редактирование: 12.10.2025 21:00:52 от Linuxfan »

Оффлайн asy

  • alt linux team
  • ***
  • Сообщений: 8 647
Так Вы мои шаги воспроизвели? У Вас получился другой результат? Обязательно проверьте по возможности и поделитесь.
Зачем? Я знаю, как сеть в принципе устроена, какие там службы бывают и т.п.
Network Address Translation (NAT) is the simplest way of accessing an external network from a virtual machine. Usually, it does not require any configuration on the host network and guest system. For this reason, it is the default networking mode in Oracle VM VirtualBox.
Где здесть написано, что тут есть и DHCP? NAT - это ни разу не DHCP. Вот восем. А DHCP должен знать, какие адреса выдавать и какие DNS. И если адреса с потолка взять можно из приватных диапазонов, то вот DNS - нет. Это надо ручками добавить. Тот же Гугль, внезапно, может быть недоступен.

В общем смотрите, что настроено, как настроено и логи получения настроек у клиента. И не несите вот эту чушь: "разрешение имен для типа подключения NAT". Потому как где NAT, а где разрешение имён.

Оффлайн Linuxfan

  • Участник
  • *
  • Сообщений: 269
И не несите вот эту чушь: "разрешение имен для типа подключения NAT". Потому как где NAT, а где разрешение имён.
Очевидно при отсутствии опции DNS сервера в настройке DHCP разрешение имен не сработает...

Повторно https://www.virtualbox.org/manual/ch06.html#network_nat
Цитировать
Network Address Translation (NAT) is the simplest way of accessing an external network from a virtual machine. Usually, it does not require any configuration on the host network and guest system. For this reason, it is the default networking mode in Oracle VM VirtualBox.

A virtual machine with NAT enabled acts much like a real computer that connects to the Internet through a router. The router, in this case, is the Oracle VM VirtualBox networking engine, which maps traffic from and to the virtual machine transparently. In Oracle VM VirtualBox this router is placed between each virtual machine and the host. This separation maximizes security since by default virtual machines cannot talk to each other.

The disadvantage of NAT mode is that, much like a private network behind a router, the virtual machine is invisible and unreachable from the outside internet. You cannot run a server this way unless you set up port forwarding. See Section 6.3.1, “Configuring Port Forwarding with NAT”.

The network frames sent out by the guest operating system are received by Oracle VM VirtualBox's NAT engine, which extracts the TCP/IP data and resends it using the host operating system. To an application on the host, or to another computer on the same network as the host, it looks like the data was sent by the Oracle VM VirtualBox application on the host, using an IP address belonging to the host. Oracle VM VirtualBox listens for replies to the packages sent, and repacks and resends them to the guest machine on its private network.

Note
Even though the NAT engine separates the VM from the host, the VM has access to the host's loopback interface and the network services running on it. The host's loopback interface is accessible as IP address 10.0.2.2. This access to the host's loopback interface can be extremely useful in some cases, for example when running a web application under development in the VM and the database server on the loopback interface on the host.

The virtual machine receives its network address and configuration on the private network from a DHCP server integrated into Oracle VM VirtualBox. The IP address thus assigned to the virtual machine is usually on a completely different network than the host. As more than one card of a virtual machine can be set up to use NAT, the first card is connected to the private network 10.0.2.0, the second card to the network 10.0.3.0 and so on. If you need to change the guest-assigned IP range, see Section 9.8, “Fine Tuning the Oracle VM VirtualBox NAT Engine”.

https://www.virtualbox.org/manual/ch09.html#changenat
Цитировать
9.8.5. Enabling DNS Proxy in NAT Mode
The NAT engine by default offers the same DNS servers to the guest that are configured on the host. In some scenarios, it can be desirable to hide the DNS server IPs from the guest, for example when this information can change on the host due to expiring DHCP leases. In this case, you can tell the NAT engine to act as DNS proxy using the following command:

$ VBoxManage modifyvm VM-name --natdnsproxy1 on
9.8.6. Using the Host's Resolver as a DNS Proxy in NAT Mode
For resolving network names, the DHCP server of the NAT engine offers a list of registered DNS servers of the host. If for some reason you need to hide this DNS server list and use the host's resolver settings, thereby forcing the Oracle VM VirtualBox NAT engine to intercept DNS requests and forward them to host's resolver, use the following command:

$ VBoxManage modifyvm VM-name --natdnshostresolver1 on
Note that this setting is similar to the DNS proxy mode, however whereas the proxy mode just forwards DNS requests to the appropriate servers, the resolver mode will interpret the DNS requests and use the host's DNS API to query the information and return it to the guest.
А вот это стоит посмотреть :-)

Оффлайн Linuxfan

  • Участник
  • *
  • Сообщений: 269
Отлично сработало 8-)
$ VBoxManage modifyvm VM-name --natdnshostresolver1 on
Но
Цитировать
The NAT engine by default offers the same DNS servers to the guest that are configured on the host
Такое впечатление, что разрешение имен для новых ВМ с типом подключения NAT по умолчанию выключено.
« Последнее редактирование: 13.10.2025 00:04:29 от Linuxfan »

Оффлайн Linuxfan

  • Участник
  • *
  • Сообщений: 269
https://www.virtualbox.org/wiki/Changelog-7.2#v0
Цитировать
VirtualBox 7.2.2 (released September 10 2025)
...
Network (NAT, DNS): Fixed potential issue where a nameserver in the 127/8 network could have been passed to the guest (issue ​github:gh-136)
https://github.com/VirtualBox/virtualbox/issues/136

Что мы и видим
DHCP4.OPTION[4]:                        domain_name_servers = 127.0.0.1

Всем спасибо :-)
« Последнее редактирование: 13.10.2025 00:05:24 от Linuxfan »