Reinstall Whonix in Qubes / One NetVM enough?

I want to reinstall my qubs os template vms (especially whonix) just to do a fresh start in case somehow it got compromised.

Is there any way I can do without losing any data?I’ve already stored anything important in keepass on an debian10 standalone vm without NetVM.

Will this be enough?

Also how would I refresh/ reinstall the netvm?

I’m only using one netvm, hope this is not a problem?

It’s always like

NETVM > sys-firewall > sys-whonix
NETVM > sys-firewall > vpn1 > sys-whonix
NET VM > sys-firewall > vpn2 > …
NETVM > sys-frewall > vpn3 > …

1 Like

I’ve had the same issue with NetVM. I tried building a new NETVM thinking that NETVM was the bottleneck I need to loosen, but unfortunately the new NetVM would not engage the Wifi router as expected. (possibly a PCI/device config issue.) So I stopped testing my hypothesis. Possibly my network connections were wrong as well.
The object of the test was to create a singular usage networks for appVMs because I thought my NETVM was corrupted.

So is one NETVM enough or was I on the right track in creating new networks?

To clarify, is it always:
AppVM>sys-whonix>sys-firewal>NETVM
or can I change some of the connections.

Ultimately, I need something that connects to the router?

Thanks for any suggestions.

NetVM -> FirewallVM -> ProxyVM -> …
sys-net-> sys-firewall -> sys-whonix ->

Assuming you have one device (i.e. ethernet) you use one NetVM. Not a Whonix issue, see documentation at Qubes OS website or the Qubes users mailing list at Google groups.

So the correct way would be

sys-net > sys-firewall > sys-whonix > whonix workstation

in exact words

whonix workstation netvm is syswhonix
sys-whonix netvm is sys-firewall
sys-firewall netvm is sys-net

This should be right if I’m correct?

whonix workstation netvm is syswhonix
sys-whonix netvm is sys-firewall
sys-firewall netvm is sys-net

This should be right if I’m correct?

Yes, where “whonix workstation” is an AppVM like anon-whonix, not the
template itself.