
Here is how to use VirtualBox: download the free installer from virtualbox.org, make sure hardware virtualization (Intel VT-x or AMD-V) is enabled in your BIOS/UEFI, create a new virtual machine, attach an operating system ISO, install it, then add Guest Additions and pick a network mode that matches what the VM needs to reach.
What do you use VirtualBox for?
Oracle VirtualBox is a type-2 hypervisor: it runs as a normal application on your existing operating system (the host) and lets you boot other operating systems (guests) inside isolated virtual machines. Each guest gets its own virtual CPU, RAM, disk and network card, and has no idea it lives inside a file on your drive.
Typical uses:
- Trying Linux without touching your main system. Ubuntu, Debian, Kali or Arch installs into a VM in half an hour and disappears with one click.
- A staging server on your laptop. A copy of your website running on the same OS, PHP and database versions as production is the safest place to break an update. There is a full section on this below.
- A disposable sandbox. Opening an untrusted file or running an unfamiliar script inside a VM, then rolling back to a snapshot, keeps your host clean.
- Legacy software. Programs that refuse to run on a modern OS often work in a guest from their own era.
- A networking lab. Several VMs on an internal network make a free lab for learning DNS, firewalls, routing and SSH.
Is VirtualBox really free?
Yes, the base package is. VirtualBox itself is released under the GNU General Public License version 3, so you can use it at home and at work without paying.
The exception is the optional Extension Pack. It is covered by the VirtualBox Extension Pack Personal Use and Educational License (PUEL), which allows noncommercial use by one individual on one host computer and educational use by teachers and students as part of a curriculum. Use that benefits a business or organization is not covered. According to the user manual, the Extension Pack adds the VRDP remote desktop server, host webcam passthrough, the Intel PXE boot ROM, AES disk image encryption and Oracle Cloud Infrastructure integration. None of that is needed to run Linux, host a test server or use shared folders, so on company machines the simplest option is to skip the Extension Pack or sort out licensing with Oracle.
How to download and install VirtualBox
Get it only from the official VirtualBox downloads page. It offers installers for Windows, macOS (separate builds for Intel and Apple Silicon), packages for major Linux distributions and Solaris, plus the Extension Pack and the manual. At the time of writing the current branch is 7.2. A hypervisor installs kernel drivers, so a tampered installer from a random mirror gets deep access to your machine.
The downloads page also publishes SHA256 checksums. Verify the file before running it:
# Windows PowerShell
Get-FileHash .\VirtualBox-7.2.X-Win.exe -Algorithm SHA256
# Linux
sha256sum virtualbox-7.2_7.2.X-*.deb
# macOS
shasum -a 256 VirtualBox-7.2.X-OSX.dmg
Use the full name of the file you downloaded: the Windows and macOS installers also carry a build number after the version, for example VirtualBox-7.2.20-175154-Win.exe, and the Apple Silicon build ends in -macOSArm64.dmg; the hash must match the line for that file exactly.
Windows
Run the installer as an administrator and keep the default components. During setup you will see a network interfaces warning: VirtualBox adds virtual adapters and your connection drops for a few seconds. The command-line tool VBoxManage.exe lands in C:\Program Files\Oracle\VirtualBox\ and is not added to PATH, so call it by full path or add the folder yourself.
Linux (Debian/Ubuntu)
You can use your distribution's package (easier, sometimes older) or the .deb from virtualbox.org (current Oracle build). Kernel modules are built with DKMS, so install headers first:
sudo apt update
sudo apt install build-essential dkms linux-headers-$(uname -r)
sudo apt install ./virtualbox-7.2_7.2.X-*.deb
sudo usermod -aG vboxusers $USER
Membership in vboxusers is needed to pass USB devices to guests; log out and back in for it to apply.
macOS
Open the .dmg for your chip and run the installer. macOS will ask you to allow Oracle's system extension under Privacy & Security; VMs will not start until you do. On Apple Silicon Macs VirtualBox runs Arm (arm64) guests only, so you need the arm64 build of your Linux distribution; x86 ISOs will not boot.
Enable VT-x or AMD-V first
VirtualBox needs a 64-bit host with hardware virtualization turned on. On Windows, open Task Manager → Performance → CPU and look for "Virtualization: Enabled". If it says Disabled, reboot into BIOS/UEFI and enable Intel Virtualization Technology (VT-x) or SVM Mode (AMD-V), usually under Advanced or CPU Configuration. On Linux:
grep -Ec '(vmx|svm)' /proc/cpuinfo
lscpu | grep -i virtualization
A non-zero count means the CPU exposes virtualization; zero means it is unsupported or disabled in firmware.
How to use VirtualBox to run Linux
Here is the flow for an Ubuntu Server VM, which doubles as a test server later. Download the ISO from the distribution's official site, then in VirtualBox Manager:
- Click New (Machine → New). Enter a name, a folder and the ISO image; VirtualBox detects the OS type from the image.
- For many distributions the wizard offers an unattended install where you pre-fill the username, password and hostname. For your first VM, skip it and go through the distribution's own installer so you see every step.
- Hardware: 2048 MB of RAM for a server without a desktop, 4096 MB for a desktop distribution, 2 CPUs. Never give a guest more than half of the host's cores or memory.
- Hard disk: create a new virtual disk of 20–25 GB. A dynamically allocated VDI only takes as much host space as the guest actually writes.
- Click Finish, then Start. The VM boots from the ISO and the normal installer runs.
After installation, open Settings → Storage and remove the ISO from the virtual optical drive, or the installer will start again on the next boot.
The Host key releases your mouse and keyboard from the VM window. By default it is the right Ctrl key on Windows and Linux hosts and the left Command key on macOS; for example Host+F toggles full screen.
Install Guest Additions
A fresh guest runs at a fixed resolution with no shared clipboard. Guest Additions fix that and add automatic display resizing, drag and drop, time sync and shared folders. Inside an Ubuntu or Debian guest:
sudo apt update
sudo apt install build-essential dkms linux-headers-$(uname -r)
Then choose Devices → Insert Guest Additions CD image in the VM window. On a server without a desktop, mount and run it manually:
sudo mount /dev/cdrom /mnt
sudo sh /mnt/VBoxLinuxAdditions.run
sudo reboot
Shared folders
In Settings → Shared Folders, add a host path, give the folder a name and tick Auto-mount. In a Linux guest it appears as /media/sf_name, readable only by members of the vboxsf group:
sudo usermod -aG vboxsf $USER
# or mount by hand:
sudo mkdir -p /mnt/site
sudo mount -t vboxsf site /mnt/site
Shared folders are handy for editing code on the host and running it in the guest, but they are slow for databases and huge directories such as node_modules; keep those on the guest's own disk.
For distribution-specific tips see our guides to Kali Linux and Arch Linux, both of which run well in VirtualBox.
How to run a program in VirtualBox?
A VM is a separate computer, so a program runs in VirtualBox the same way it runs on any machine: you install it inside the guest operating system. VirtualBox cannot launch a host .exe or app "inside" a VM without a guest OS. To get the installer into the guest, download it from within the guest's browser, copy it through a shared folder, or drag and drop it once Guest Additions are installed and drag and drop is enabled under Settings → General → Advanced. Then install and run it as usual in the guest.
VirtualBox network modes: which one to pick
Most "I can't ping it" and "the site won't load" problems come down to the attachment type under Settings → Network → Adapter 1 → Attached to. Up to four adapters can be configured in the GUI and modes can be combined. Reachability, per the VirtualBox networking reference:
| Mode | VM → host | Host → VM | VM ↔ VM | VM → internet/LAN | LAN → VM | Use it when |
|---|---|---|---|---|---|---|
| NAT (default) | yes | port forwarding only | no | yes | port forwarding only | The guest needs internet and you only need a couple of ports inside |
| NAT Network | yes | port forwarding only | yes | yes | port forwarding only | Several VMs must see each other and reach the internet |
| Bridged Adapter | yes | yes | yes | yes | yes | The VM should be a full device on your LAN |
| Host-only Adapter | yes | yes | yes | no | no | A test server reachable only from your own computer |
| Internal Network | no | no | yes | no | no | An isolated lab of several VMs |
- NAT: the guest gets 10.0.2.15, gateway 10.0.2.2 (which is also how the guest reaches services on the host) and DNS 10.0.2.3. Each VM has its own private NAT, so two NAT VMs cannot talk to each other.
- Bridged: the VM gets an address from your router's DHCP like any other device. Bridging over Wi-Fi does not work with every adapter, and corporate networks may block unknown MAC addresses.
- Host-only: a private network between host and guests, 192.168.56.0/24 by default with the host at 192.168.56.1. Since 6.1.28, Linux and macOS hosts only allow 192.168.56.0/21 unless you list other ranges in
/etc/vbox/networks.conf. No internet here, so add NAT as a second adapter.
Port forwarding in NAT mode
Set it up under Adapter 1 → Advanced → Port Forwarding, or from the command line while the VM is powered off:
VBoxManage modifyvm "web-test" --natpf1 "ssh,tcp,127.0.0.1,2222,,22"
VBoxManage modifyvm "web-test" --natpf1 "http,tcp,127.0.0.1,8080,,80"
The fields are name, protocol, host IP, host port, guest IP, guest port. For a running VM use VBoxManage controlvm "web-test" natpf1 "..."; remove a rule with --natpf1 delete ssh. Binding to 127.0.0.1 keeps the port private to your machine; leaving the host IP empty opens it on every host interface, including your LAN. Now ssh -p 2222 user@127.0.0.1 reaches the guest.
A staging copy of your website in VirtualBox
For anyone who runs a website, the most valuable thing VirtualBox offers is a place to test updates before production. Upgrading PHP, a CMS, plugins or OS packages directly on the live server is a gamble; on a VM copy it is a rehearsal you can undo in seconds.
- Match production. Run
cat /etc/os-releaseon the server and install the same distribution and release in the VM, then the same web server, PHP or Node.js and database versions. Our first-30-minutes VPS checklist applies to the test machine as well. - Set up networking. NAT with 2222→22 and 8080→80 is enough for one stand. To reach the site at a fixed address, add a Host-only adapter and give the guest a static IP via netplan (check the interface name with
ip a):
Apply it withnetwork: version: 2 ethernets: enp0s8: addresses: [192.168.56.10/24]sudo netplan apply. - Copy files and the database.
Key-based login makes this painless; see setting up SSH keys.# on production mysqldump --single-transaction dbname > dump.sql # inside the VM rsync -avz user@prod.example.com:/var/www/site/ /var/www/site/ scp user@prod.example.com:dump.sql . mysql dbname < dump.sql - Defuse the copy. Disable cron jobs, outgoing email and payment webhooks on the staging copy, or it may email real customers or reprocess orders. Customer data in the copy is still personal data: protect the VM like production or anonymize the database.
- Take a snapshot of the clean copy (next section).
- Update and test. Run
sudo apt update && sudo apt upgrade, update the CMS or dependencies, click through key pages and forms, and read the web server and application logs.
Many CMSs redirect to the domain stored in their settings, sending you off to the live site. Either send the right Host header yourself:
curl -I -H "Host: example.com" http://127.0.0.1:8080/
or point the domain at the VM temporarily in the host's hosts file (C:\Windows\System32\drivers\etc\hosts on Windows, /etc/hosts on Linux and macOS):
192.168.56.10 example.com www.example.com
A hosts file cannot specify a port, which is why this uses the Host-only address rather than the 8080 forward. Remove the line after testing, or you will soon be staring at the staging copy wondering why "production" never changes.
Why can't I reach the site in my VM?
- NAT without a forward. In NAT mode the host cannot reach the guest at all until you add a port forwarding rule.
- The service listens on 127.0.0.1 inside the guest. Check with
ss -tlnp. A web server or Node.js dev server bound to 127.0.0.1 ignores connections from other interfaces; bind it to 0.0.0.0. The difference is explained in our article on 0.0.0.0. - The guest firewall. On Ubuntu with ufw enabled:
sudo ufw allow 80/tcp. - The forward is bound to the host's 127.0.0.1. Correct for a personal stand, but other devices cannot connect.
- The internet is not your LAN. Even bridged, the VM has a private address behind your router and is unreachable from the internet without router port forwarding; many ISPs do not even give you a public IP. A staging copy usually should not be public anyway.
Test from the host with curl -I http://127.0.0.1:8080/ or, in PowerShell, Test-NetConnection 127.0.0.1 -Port 8080.
Snapshots: roll back in seconds
A snapshot records the VM's disk, settings and, if it is running, its memory. After a failed update you restore the snapshot and the system is back where it was:
VBoxManage snapshot "web-test" take "clean-copy" --description "before PHP upgrade"
VBoxManage snapshot "web-test" list
VBoxManage controlvm "web-test" poweroff
VBoxManage snapshot "web-test" restore "clean-copy"
A snapshot can only be restored on a powered-off or saved VM, hence the poweroff. Snapshots are not backups: they are differencing disks that depend on the base VDI, and long chains slow the disk down. For a real copy, export or clone the VM:
VBoxManage export "web-test" -o web-test.ova
VBoxManage clonevm "web-test" --name "web-test-2" --register
The OVA file is also how you move a VM to another computer: File → Import Appliance, or VBoxManage import web-test.ova.
Using VBoxManage from the command line
VBoxManage --version
VBoxManage list vms
VBoxManage list runningvms
VBoxManage startvm "web-test" --type headless
VBoxManage controlvm "web-test" acpipowerbutton
VBoxManage showvminfo "web-test"
Creating a VM entirely from a Linux or macOS shell (list valid OS IDs with VBoxManage list ostypes):
VBoxManage createvm --name "web-test" --ostype Ubuntu_64 --register
VBoxManage modifyvm "web-test" --memory 2048 --cpus 2 --nic1 nat
VBoxManage createmedium disk --filename "$HOME/VirtualBox VMs/web-test/web-test.vdi" --size 20480
VBoxManage storagectl "web-test" --name SATA --add sata --controller IntelAhci
VBoxManage storageattach "web-test" --storagectl SATA --port 0 --device 0 --type hdd --medium "$HOME/VirtualBox VMs/web-test/web-test.vdi"
VBoxManage storageattach "web-test" --storagectl SATA --port 1 --device 0 --type dvddrive --medium ~/Downloads/ubuntu-server.iso
Disk size in createmedium is in megabytes. --type headless starts the VM without a window; connect over SSH through the forwarded port.
Common VirtualBox errors and fixes
VT-x is disabled in the BIOS for all CPU modes (VERR_VMX_MSR_ALL_VMX_DISABLED)
Hardware virtualization is off in firmware. The AMD equivalent is AMD-V is disabled in the BIOS (or by the host OS) (VERR_SVM_DISABLED). Enable VT-x or SVM Mode in BIOS/UEFI.
VirtualBox and Hyper-V on Windows
When Hyper-V, WSL 2, Windows Sandbox or Memory Integrity is active, Microsoft's hypervisor owns the CPU's virtualization extensions. VirtualBox then either runs through the Windows Hypervisor Platform noticeably slower (a turtle icon appears in the VM's status bar) or fails to start VMs. The VirtualBox manual recommends disabling Hyper-V when running VirtualBox. Check whether a hypervisor is active:
(Get-CimInstance Win32_ComputerSystem).HypervisorPresent
Disable it from an elevated PowerShell, then reboot:
Disable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V-All
Disable-WindowsOptionalFeature -Online -FeatureName VirtualMachinePlatform
Disable-WindowsOptionalFeature -Online -FeatureName HypervisorPlatform
bcdedit /set hypervisorlaunchtype off
Memory Integrity is under Windows Security → Device security → Core isolation. The trade-off: WSL 2, Docker Desktop's WSL 2 backend and Windows Sandbox stop working. Undo with bcdedit /set hypervisorlaunchtype auto.
Kernel driver not installed (rc=-1908) on Linux
The VirtualBox kernel module is not built or not loaded, usually after a kernel update or with Secure Boot on. Install headers for the running kernel and rebuild:
sudo apt install dkms linux-headers-$(uname -r)
sudo /sbin/vboxconfig
With Secure Boot enabled the kernel refuses unsigned modules: sign them with your own key enrolled through MOK, or use your distribution's package, which handles signing.
VT-x is being used by another hypervisor (VERR_VMX_IN_VMX_ROOT_MODE)
KVM holds the virtualization extensions on a Linux host. Unload it while you use VirtualBox: sudo modprobe -r kvm_intel kvm (on AMD: kvm_amd kvm).
FATAL: No bootable medium found!
The VM has an empty disk and no ISO attached. Open Settings → Storage, select the optical drive and choose the image file.
How to check the site after it ships
enterno.io checks run from the internet, so they cannot see a VM behind NAT on your laptop, and that is expected. They are useful for the next step, once the update you rehearsed goes to the production server:
- HTTP header and availability check — compare production's status code and headers with what the staging copy returned.
- SSL certificate check — staging uses a self-signed certificate; after a web server upgrade, confirm production still serves the right chain.
- Port scanner — see which server ports are visible from the internet so staging shortcuts such as an open database port do not leak into production.
FAQ
Can I use VirtualBox at work for free?
The base package, yes: it is GPLv3. The Extension Pack is licensed under the PUEL, which covers personal and educational use but not use that benefits a business.
Does VirtualBox work on Apple Silicon Macs?
Yes, there is a dedicated macOS build for Apple Silicon, but it runs Arm (arm64) guests only. Use the arm64 image of your Linux distribution.
Where does VirtualBox store virtual machines?
In a "VirtualBox VMs" folder in your home directory by default. Change it under File → Preferences → General → Default Machine Folder.
How much RAM should I give a VM?
1–2 GB for a Linux server without a desktop, around 4 GB for a desktop distribution. Keep at least half of the host's memory for the host, or both systems will start swapping.
How do I move a VirtualBox VM to another computer?
Export it to an OVA file (File → Export Appliance or VBoxManage export) and import it on the other machine. Make sure the target CPU architecture matches: an x86 guest will not run on an Apple Silicon host.