This PowerShell script configures firewall and port forwarding rules to allow WSL2 to access services running on the Windows host's 127.0.0.1 (localhost), such as LmStudio, MySQL, or other services.
Problem: By default, WSL2 cannot access services bound to 127.0.0.1 on the Windows host. This script creates the necessary port forwarding rules to enable this access.
Important: The port forwarding rules created by netsh interface portproxy are not persistent across Windows restarts. This script provides solutions to make them permanent.
Run the script as Administrator to configure rules immediately:
# From Windows PowerShell (as Administrator):
Set-ExecutionPolicy Bypass -Scope Process -Force
.\AllowLmStudio.ps1This will:
- Detect your WSL2 gateway IP automatically
- Create port forwarding rules for ports 1234 (LmStudio) and 3306 (MySQL)
- Add firewall rules to allow traffic from WSL2
- Restart the IP Helper Service to apply changes
Note: These rules will be lost when you restart Windows.
To make the rules persist across Windows restarts, use the built-in install:
# From Windows PowerShell (as Administrator):
.\AllowLmStudio.ps1 -InstallThis creates a scheduled task named "WSL2 PortProxy Setup" that:
- Runs at user logon (with 1-minute delay for network readiness)
- Runs when the WSL service starts (with 30-second delay for WSL VM initialization)
- Executes with SYSTEM privileges (highest level)
- Runs silently (with
-Silentflag, but still logs to file) - Automatically reconfigures all rules
To verify the scheduled task was created:
schtasks /query /tn "WSL2 PortProxy Setup"The recommended -Install flag creates a scheduled task with dual triggers (logon + WSL service start) using PowerShell's ScheduledTask module. However, if you're working from WSL, you can create a basic scheduled task directly:
# From WSL (as your user):
schtasks.exe /create /tn "WSL2 PortProxy Setup" \
/tr "powershell.exe -ExecutionPolicy Bypass -File 'C:\Users\<your-user>\path\to\AllowLmStudio.ps1' -Silent" \
/sc onstart /ru SYSTEM /rl HIGHEST /f
# Verify it was created:
schtasks.exe /query /tn "WSL2 PortProxy Setup"Note: This creates a single trigger (Windows startup). The built-in -Install flag provides better reliability with dual triggers.
Note: Adjust the path to match your actual Windows path to the script.
For additional reliability, configure WSL2 to also run the script when it starts:
# From WSL:
sudo bash -c 'cat > /etc/wsl.conf << "EOF"
[boot]
command = "powershell.exe -ExecutionPolicy Bypass -File /mnt/c/Users/<your-user>/path/to/AllowLmStudio.ps1 -Silent"
EOF'
# Restart WSL2 for changes to take effect:
wsl.exe --shutdownNote: This only runs when WSL2 starts, not when Windows starts. Use this in combination with the scheduled task for maximum reliability.
| Parameter | Description |
|---|---|
-Install |
Create a scheduled task to run this script automatically (logon + WSL service start triggers) |
-Uninstall |
Remove the scheduled task and clean up all rules |
-Test |
Display current configuration without making changes |
-Silent |
Run with minimal output (still logs to file; useful for scheduled tasks) |
-Port <ports> |
Specify custom ports instead of defaults (1234, 3306) |
# Configure rules now with default ports
.\AllowLmStudio.ps1
# Configure rules for custom ports
.\AllowLmStudio.ps1 -Port 1234,8080,5432
# Install as scheduled task (persistent)
.\AllowLmStudio.ps1 -Install
# Check current configuration
.\AllowLmStudio.ps1 -Test
# Remove scheduled task and all rules
.\AllowLmStudio.ps1 -Uninstall
# Run silently (for scheduled tasks)
.\AllowLmStudio.ps1 -SilentThe script automatically detects the WSL2 gateway IP address (the Windows-side IP of the virtual network interface). This is typically in the 172.x.x.x range.
The detection now works in two ways:
- Primary (reliable under SYSTEM account): Reads the WSL virtual adapter directly from Windows (
Get-NetAdapterlooking forvEthernet (WSL*) - Fallback: Queries inside WSL using
ip route
This ensures detection works even when running as a scheduled task under the SYSTEM account.
For each configured port, the script creates a rule that forwards traffic from the WSL2 gateway IP to 127.0.0.1:
WSL2_Gateway_IP:1234 -> 127.0.0.1:1234
WSL2_Gateway_IP:3306 -> 127.0.0.1:3306
The script adds Windows Firewall rules to allow incoming traffic from the WSL2 subnet to the specified ports.
The IP Helper Service (iphlpsvc) is restarted to ensure the port forwarding rules take effect immediately.
- 1234 - LmStudio default port
- 3306 - MySQL default port
Customize using the -Port parameter:
.\AllowLmStudio.ps1 -Port 8000,8080,3000netsh interface portproxy show allnetsh advfirewall firewall show rule name=all | findstr "WSL2"# For a service on port 1234:
curl http://127.0.0.1:1234
# For MySQL:
mysql -h 127.0.0.1 -P 3306 -u username -p# Remove scheduled task and all rules
.\AllowLmStudio.ps1 -UninstallThis will:
- Delete the scheduled task (if it exists)
- Remove all port forwarding rules for default ports
- Remove all firewall rules for WSL2
WSL2 uses a virtualized network with a lightweight VM. The WSL2 gateway IP is the Windows-side IP address assigned to the virtual adapter (typically 172.x.x.x range) and remains constant across reboots.
Windows netsh interface portproxy rules are stored in memory by the IP Helper Service (iphlpsvc). They are not written to disk, so they are lost on Windows restart. This is a Windows limitation.
The script now maintains a log file (AllowLmStudio.log in the same directory) that captures all operations, including:
- Startup and configuration attempts
- WSL2 gateway detection attempts and results
- Port forwarding and firewall rule creation status
- Error messages with context
The log file is automatically rotated (renamed to .old) when it exceeds ~200 KB to prevent unbounded growth.
The script includes retry logic to handle cases where WSL2 is still initializing:
- Windows-side detection: 20 attempts, 3 seconds between each
- WSL-side fallback: 10 attempts, 3 seconds between each
- Only the first 3 attempts are logged to avoid noise
wsl2 port-forwarding powershell windows lmsudio firewall netsh localhost networking docker-alternative
This project is licensed under the MIT License.
Copyright (c) 2026 mdeweerd
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
- v2.1 - Enhanced scheduled task with dual triggers (logon + WSL service start), added file-based logging with rotation, improved vEthernet adapter detection for WSL, better error handling for portproxy and firewall commands
- v2.0 - Added persistence support via scheduled task, retry logic, multiple installation options
- v1.0 - Initial version with basic port forwarding setup