Andrew Mercer
on this page

KVM networking

Part of the KVM overview. The default NAT network, bridged networking, finding guest IP addresses, and adding or removing NICs.

Default NAT network

Guests get addresses from virbr0 (usually 192.168.122.0/24). If the default network is missing (Network not found: no network with matching name 'default'), the network config package was not installed:

sudo dnf install libvirt-daemon-config-network      # or: dnf group install "Virtualization Host"
virsh net-define /usr/share/libvirt/networks/default.xml
virsh net-autostart default
virsh net-start default
virsh net-list --all
ip addr show virbr0

Bridged networking

Use a bridge when guests need to be on the physical LAN.

Ubuntu (netplan)

# /etc/netplan/50-cloud-init.yaml
network:
  version: 2
  ethernets:
    enp3s0:
      dhcp4: false
      dhcp6: false
  bridges:
    br0:
      interfaces: [enp3s0]
      dhcp4: false
      addresses: [192.0.2.11/24]
      nameservers:
        addresses: [192.0.2.1]
      routes:
        - to: default
          via: 192.0.2.1
sudo netplan try        # reverts automatically if you lose connectivity

RHEL family (NetworkManager)

Run this from the console, not over SSH on the interface being bridged; the switchover can take a minute or two.

nmcli connection add type bridge autoconnect yes con-name br0 ifname br0
nmcli connection modify br0 ipv4.addresses 192.0.2.11/24 ipv4.method manual
nmcli connection modify br0 ipv4.gateway 192.0.2.1
nmcli connection modify br0 ipv4.dns 192.0.2.1
nmcli connection delete "Wired connection 1"          # or the existing profile for the NIC
nmcli connection add type bridge-slave autoconnect yes con-name eno1 ifname eno1 master br0
nmcli connection up br0
nmcli connection show

Host settings. Enable forwarding, and stop bridged traffic from being filtered by the host firewall:

# /etc/sysctl.d/99-kvm-bridge.conf
net.ipv4.ip_forward = 1
net.bridge.bridge-nf-call-ip6tables = 0
net.bridge.bridge-nf-call-iptables = 0
net.bridge.bridge-nf-call-arptables = 0

sudo sysctl --system applies them (the net.bridge.* keys only exist once the br_netfilter module is loaded).

Find a VM's IP address

virsh domifaddr vm01                          # default source: DHCP lease
virsh domifaddr vm01 --source agent           # needs qemu-guest-agent in the guest (best for bridged guests)
virsh domifaddr vm01 --source arp
virsh net-dhcp-leases default
watch -n 1 'virsh net-dhcp-leases default'    # useful while an installer is starting
virsh domiflist vm01                          # MAC addresses and attachment points

Add or remove a NIC

virsh domiflist vm01
virsh attach-interface --domain vm01 --type bridge --source br0 --model virtio --config --live
virsh attach-interface --domain vm01 --type network --source default --model virtio --config --live
virsh detach-interface --domain vm01 --type bridge --mac [ mac ] --config --live

Drop --live if the VM is shut off. The guest sees a new ethN; configure it like any other interface.