The Three Networking Modes
| Mode | What It Does | Use for Metasploitable 2? |
|---|---|---|
| NAT | Gives the VM outbound internet access through the host; other VMs and the host can't easily initiate connections to it. | No — blocks the attacker VM from reaching it directly. |
| Bridged | Puts the VM directly on your physical network as if it were another device on your router. | Never — exposes every vulnerable service to your real network. |
| Host-Only | Creates a private virtual network shared only by VMs on the same host, with no path to the internet. | Yes — this is the default for this entire site's tutorials. |
Why Host-Only Is the Lab Default
Host-only networking gives you exactly what a lab needs: your attacking VM and Metasploitable 2 can reach each other freely, but nothing outside your own machine can reach either of them. It requires no firewall rules to get right, because there's no path in from outside to begin with.
Configuring Host-Only in VirtualBox
- Open Tools → Network → Host-Only Networks and create one if none exists (VirtualBox usually names it
vboxnet0). - For each VM, open Settings → Network, set Adapter 1 to Host-Only Adapter, and select that network.
- Repeat for both Metasploitable 2 and your attacking VM, selecting the same network name on both.
Configuring Host-Only in VMware
- Open the Virtual Network Editor and confirm a host-only network (commonly
VMnet1) exists. - In each VM's network adapter settings, choose Host-only (or the equivalent custom network on Fusion).
- Confirm both VMs reference the same virtual network identifier.
Verifying the Configuration
ifconfig
Run on Metasploitable 2 to confirm it received an address on the host-only range (commonly 192.168.56.0/24 in VirtualBox).
ping -c 4 <metasploitable-ip>
Run from your attacking VM. Successful replies confirm the two machines share a working network path.
Security Lesson
This is a hands-on introduction to network segmentation, one of the most fundamental defensive controls in real infrastructure. Production networks isolate sensitive systems into their own segments for the same reason you're isolating Metasploitable 2: to contain what a compromise can reach.
Common Problems
- VM gets no IP address at all: confirm a host-only network actually exists before assigning it — some hypervisors don't create one automatically.
- Two VMs, two different subnets: each host-only network has its own address range; make sure both VMs are attached to the same named network, not just "a" host-only network.
- Address changes between reboots: normal behavior with DHCP-assigned host-only networks — re-verify the address each session.
FAQ
What's the difference between host-only and internal networking?
Host-only lets your VMs reach each other and the physical host machine, but not the outside network. Internal networking (VirtualBox) isolates VMs from the host too. Either works for this lab; host-only is more common because it's simpler to set up.
Can I use NAT instead of host-only?
NAT gives each VM outbound internet access individually but doesn't let VMs see each other directly without extra configuration, which defeats the point of a two-VM lab. Use host-only for the target and attacker to talk to each other.
Will host-only networking block Kali Linux from getting security updates?
Yes, host-only alone has no path to the internet. If you need Kali to update, temporarily add a second NAT-only adapter to Kali for that purpose, and leave Metasploitable 2 on host-only exclusively.