On Mon, Apr 24, 2017 at 02:43:46PM +0200, [email protected] wrote:
> When I change a running DispVM's NetWM (in the Qubes VM Manager) (e.g.
> from sys-whonix to sys-firewall) the DispVM loses its internet
> connection. Changing the NetWM of a normal AppVM based on the same
> TempVM as the DispVM does not cause any issues. How could this be?
> 
> I'm running Qubes 3.2. The TempVM in question is running debian
> unstable, but I don't see how this can matter since I have no problems
> with normal AppVMs based on it.
> 
> Imperfect workaround: Launch the DispVM with "qvm-run --dispvm $COMMAND"
> from a AppVM that uses the desired NetVM (more correctly: has the
> desired "NetVM for DispVM" setting*).
> 
> * As the UX is now, this setting is confusing and potentially
> detrimental for security in my opinion: 
> https://github.com/QubesOS/qubes-issues/issues/2379#issuecomment-296650904
> 
> -- 
> Ubestemt

I'm constantly switching NetVMs for disposableVMs - most of the time I do
this by script setting the netvm before opening the disposableVM, with
a keyboard shortcut.
On occasion I change the netVM for a running disposableVM and it just
works.
I make sure that I create the DVM Template using a netvm, and then set
it to none, using 'qvm-prefs foo.dvm -s netvm none'. That ensures that
disposableVMs are started using the value assigned to each qube using
dispvm_netvm, but seems to allow for netvm switching. (Actually I have
dispvm_netvm set to none across the board, so I rely on the ability to
change netvm.)
I don't know if that will make any difference to your experience?

unman

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20170424151848.GA23483%40thirdeyesecurity.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to