Chris wrote:
Sorry DNS is getting in your way. The wsl-nat-lan-unreachable label by itself doesn't establish the cause, so I don't want to guess at a fix. To narrow this down, could you tell me which WSL distribution you're using, whether Docker is Docker Desktop or Docker Engine installed inside WSL, and share the exact hostname command and error (also say whether you ran it in WSL or in a container)?
Chris wrote:
Following up on my question, because that label is more useful than I made it sound. It is something SparkBox actually measured on your box, and it explains what you're seeing. SparkBox runs inside WSL on your Windows PC. Right now WSL has put it on a small private network of its own (an address starting with 172.), and only that one PC can reach it. Apps open fine on the PC itself, but your phone, TV or another computer can't connect, and typing the PC's name instead of a number doesn't help either, because the name leads to Windows, not to SparkBox. The fix depends on your Windows version. Press Windows+R, type winver and press Enter. Windows 11, version 22H2 or newer: put SparkBox on your home network. 1. In File Explorer go to C:\Users\<your name and open the file .wslconfig (create it with Notepad if it isn't there). Make sure it contains these two lines, and leave any other lines in it alone: [wsl2] on one line and networkingMode=mirrored on the line under it. 2. Open PowerShell as administrator (right-click, Run as administrator) and run wsl --shutdown, then this line: Set-NetFirewallHyperVVMSetting -Name '{40E0AC32-46A5-438A-A0B2-2B479E8F2E90}' -DefaultInboundAction Allow 3. Open your SparkBox Linux window again and run sudo sparkbox up, then sudo sparkbox doctor. The Windows (WSL) Networking section should now say OK, and your apps will use your PC's normal home-network address. Windows 10 (or Windows 11 older than 22H2): that setting isn't available. Instead, sudo sparkbox doctor prints, in its Windows (WSL) Networking section, the exact forwarding lines for your box, one per app, to paste into an administrator PowerShell. They need redoing after a Windows restart. Could you tell me the version line winver shows, and what doctor says after you try? If your problem is something else, like an app that can't find another app by name, paste the exact name and the error it gives.
h0m3slic3 wrote:
I'm using Docker Engine installed inside WSL In settings, network, addresses it say This device cannot open media.home.arpa yet — see “My phone can’t open the names” below. I tried your reply still no t working. asked ai: My question: my phone can’t open portainer.media.home.arpa SparkBox AI replied: The box-side checks pass: [REDACTED] resolves portainer.media.home.arpa, and the proxy returns HTTP 200. But Doctor still says the WSL address only works on this PC, so your phone can’t reach it over Wi-Fi. That’s the blocker—not Portainer’s login. Since mirrored networking and the firewall change didn’t clear the WSL check, I can’t confirm the next fix from here. Use Share to demox so Tom can review the WSL networking details. What I still need help with: (describe what didn't work or what's still broken) win 25H2. If I'm still missing information let me know Thank you for ur assistance.
Chris wrote:
You're right to follow up. I'm sorry: my previous reply jumped to a fix without verifying the Windows-to-WSL path, and I shouldn't have told you to set the WSL firewall's default inbound action to Allow broadly. A check from inside SparkBox—even if the name resolves and the proxy answers there—doesn't show that your phone can reach it. I can't yet tell whether the phone is resolving portainer.media.home.arpa to an address it can reach, or whether the route from your phone through Windows to WSL is the blocker. One check, without changing anything: in your SparkBox Linux terminal, run sudo sparkbox doctor and paste only its [Windows (WSL) Networking] section, replacing any IP addresses with [redacted]. Since you're on Windows 11 25H2, please don't repeat the firewall change or make more network changes until we see that result. I've corrected my guidance here so I won't send someone else to broadly allow inbound traffic as a guessed fix.