Creating a Virtual Wi-Fi Network in Windows with Netsh WLAN: Complete Guide

Last update: 11/09/2025
Author Isaac
  • The hosted network enables Virtual Wi-Fi (STA/VSTA) and SoftAP with WPA2-PSK/AES.
  • To share the Internet, use ICS with the virtual adapter, not network bridges.
  • In Windows 10/11, Mobile Hotspot makes it easy to create a hotspot.
  • Netsh allows you to configure, audit and automate WLAN, IPv4, DNS and firewall.

Virtual WiFi on Windows with Netsh Wlan

Setting up a virtual Wi-Fi network in Windows with `netsh wlan` is a simple way to share your connection without installing any extraneous software. If you prefer a graphical interface, there are programs that can turn your PC into a Wi-Fi router . This guide covers everything you need to know: from hosted network technology (SoftAP), key commands , driver compatibility , and the official Windows 10/11 mode (Mobile Hotspot), to practical solutions if something goes wrong.

In addition to virtual Wi-Fi commands, we'll cover useful netsh tricks for IPv4, firewalls, and DNS, as well as alternatives like third-party apps or using your smartphone as a hotspot. The goal is to provide you with all the necessary knowledge to create and manage your Wi-Fi hotspot reliably, all in one article.

What is Windows Hosted Network (Virtual Wi-Fi and SoftAP)

Starting with Windows 7 and Windows Server 2008 R2 with the WLAN service, the system can virtualize a physical Wi-Fi adapter into multiple logical ones to enable two functions: Virtual Wi-Fi (STA/VSTA) and a SoftAP software access point . Both functions are linked: when the hosted network is activated, they are enabled simultaneously and, in Windows, cannot be activated separately.

With this feature, a single physical wireless adapter can remain connected as a client (STA) to a regular access point (AP) while simultaneously advertising its own virtual AP for other devices to connect. However, you need an adapter and driver compatible with the hosted network and the Microsoft WLAN driver model; if the driver doesn't support the feature, it won't work . If you need help with hardware and drivers, learn how to manage virtual network adapters.

Virtualization creates up to three logical adapters: a Station Adapter (STA) (client), an Access Point Adapter (AP) for SoftAP, and optionally, a Virtual Station Adapter (VSTA) that some manufacturers use to extend functionality. The STA behaves like the physical one and is always present; the AP appears when you invoke the hosted network (and disappears when you disable it); the VSTA initializes and releases the provider's service (IHV).

Windows links the logical adapters to NDIS ports: the STA connects to port 0 ; the AP and VSTA connect to the next available port and maintain the connection until virtualization ends. Valid combinations include STA, STA+AP, STA+VSTA, and STA+AP+VSTA, but the hosted network must be enabled in all cases except for the pure STA configuration.

Important: Microsoft prohibits Layer 2 bridging between the AP adapter and any other system adapter (and applies the same restriction to VSTA ). In practice, if you want to share your internet connection, you should use ICS (Internet Connection Sharing) , not a network bridge. For additional options, see how to use your PC as a router to understand other alternatives.

There are other limitations: the SoftAP does not perform DNS resolution. If there is no external DNS server accessible via ICS, fully qualified domain name (FQDN) resolution between devices connected to the SoftAP will only work if all devices mark the SoftAP network as Private (HOME or WORK). And be aware: ad hoc networks and SoftAPs are mutually exclusive on the same hardware; if you start one, the other will shut down . In case of resolution problems, you can consult guides on DNS server errors.

Hosted Network Components and SoftAP

Security, keys and WPS on the hosted network

Windows hosted networking requires WPA2-PSK with AES . The primary (system) key is a value of up to 63 characters that Windows automatically generates the first time you invoke the hosted network and that persists until you regenerate it with netsh or through the corresponding API.

To make things easier for the user, there's also a more manageable secondary (user) key. This key is defined by the user or an application, can be temporary or persistent , and is managed with netsh commands or APIs. There can be exactly one primary key and, at most, one secondary key; devices provisioned via WPS receive the primary key , while manually configured devices can use either one.

  The best way to Make Outlook Begin Routinely With Laptop

When you change a password, devices that were using the old password will stop connecting until you reconfigure them with the new one; devices using the old password, if it hasn't changed, will continue to work. Additionally, Windows allows applications to register to receive WLAN notifications specific to the hosted network, which helps them react when the SoftAP's status or properties change.

Common scenarios: Wireless PAN and ICS

The simplest use is to set up a Wi-Fi personal area network between your PC and other devices. With SoftAP enabled, any WPA2-PSK/AES compatible device can join and share data with you or with each other, just like a home access point. You can also scan connected devices to see who is connected to the hotspot.

If you're looking to share your internet connection, Internet Connection Sharing (ICS) comes into play . The public ICS interface is the one with the external connection (Ethernet, Wi-Fi, or cellular), and the private interface is the SoftAP's virtual adapter. In many setups, the STA of the same physical adapter can be the public interface if you're connected via Wi-Fi to another access point and, at the same time, advertise your SoftAP.

An interesting point: the hosted network integrates with WPS. Windows can invoke SoftAP in the background to provision a device to a physical access point that doesn't support WPS via WPS , transparently injecting the profile.

Essential netsh wlan commands for virtual Wi-Fi

With `netsh wlan` you can enable/disable the hosted network, set the SSID and user password, start it, stop it, check its status, and regenerate passwords. Make sure to run the console as administrator.

To configure the SoftAP with a name and password defined by you (user key): adjust these values ​​to your liking.

netsh wlan set hostednetwork mode=allow ssid=MiRedVirtual key=MiContraseñaSegura keyUsage=persistent

To start and stop the hosted network, use these shortcut commands :

netsh wlan start hostednetwork
netsh wlan stop hostednetwork

If you need to completely enable or disable the feature on the system, use this global setting :

netsh wlan set hostednetwork mode=allow
netsh wlan set hostednetwork mode=disallow

Check the status, security, and connected devices with these diagnostic commands :

netsh wlan show hostednetwork
netsh wlan show hostednetwork setting=security
netsh wlan show settings

To renew the system key generated by Windows, use the refresh option :

netsh wlan refresh hostednetwork data=key

Tip: First, check if your adapter supports hosted networking. In the output, look for the " Hosted network allowed " field and confirm that it is "Yes".

netsh wlan show drivers

Internet Sharing: ICS vs. Network Bridging

If your PC connects to the internet via Ethernet and you want to share Wi-Fi from the SoftAP, enable ICS by checking the Sharing box in the properties of the access interface (public) and selecting the virtual adapter as private. This is the method recommended by Windows for masking and assigning IP addresses to clients of the access point.

Some guides suggest creating a bridge between the Ethernet and wireless NICs; however, Microsoft prohibits Layer 2 bridging between the AP adapter and any other device. In my experience, ICS works best for SoftAP; bridging can fail or be blocked by the network stack itself, so avoid it when using a hosted network.

Windows 10 and 11: Mobile Hotspot

Windows 10 and Windows 11 offer a built-in and very convenient way to share your internet connection: Mobile Hotspot . It works with Wi-Fi, Ethernet, and mobile data connections, saving you from having to deal with commands if you don't need them.

In Windows 10, you can activate it from the Action Center or the network icon; then, go to Settings > Network & Internet > Mobile hotspot to view or change the SSID, password, and band (2,4 or 5 GHz if your hardware supports it). It's quick and easy.

  How to Count Text Cells in Excel: Methods and Tricks

In Windows 11, go to Settings > Network & Internet > Mobile hotspot. Choose which interface to share from, how to do it (Wi-Fi or Bluetooth, Wi-Fi is preferable), and click Edit to customize the name, password, and band. Turn on the switch and connect your devices by finding the SSID and entering the password.

Share Internet with mobile hotspot

Compatibility, drivers and troubleshooting

If you see the SSID on your mobile device when creating the network but there's no internet connection, first check ICS: in the properties of the outgoing interface, enable " Allow other users" and select the hosted network adapter as the private network. Avoid using bridges and confirm that there are no ad hoc networks on the same adapter, as SoftAP and ad hoc are incompatible . If you experience frequent disconnections, see our solutions for disconnections.

Check for hosted network support with `netsh wlan show drivers` . If "Hosted network allowed" says "No," the driver doesn't implement the feature. Some chipsets (e.g., certain older Qualcomm Atheros chipsets) can create the SSID but fail to share it . In that case, try updating drivers, using the Windows 10/11 Mobile Zone, or using a third-party application ; you may also find it helpful to review guides on Wi-Fi software.

Note that SoftAP stops if the computer goes to sleep, hibernates, or restarts, and does not automatically resume upon restart. If you need it to start with the system, you can create a .bat script with the startup commands and schedule it using Task Scheduler to run with privileges at login.

If that doesn't resolve the issue, check your firewall: open the necessary ports or create rules if required by any application, and ensure the SoftAP network profile is set to Private to facilitate local DNS resolution when no external DNS is available. Finally, reset the TCP/IP stack if you suspect parameter corruption, and if necessary, change the DNS settings in Windows 11 before trying again.

netsh int ip reset
netsh int ip reset C:\tcpipreset.txt

Netsh in depth: syntax, parameters, and useful examples

Netsh is a powerful utility for displaying and modifying network settings in Windows (2000, XP, 7, 8, 10, 11, Server, etc.). You can run it from PowerShell or the Command Prompt , using specific parameters and contexts such as wlan or interface ipv4.

Its general syntax supports aliases, contexts, remote execution, username/password, and scripts, allowing you to automate complex settings in just a couple of commands:

netsh     Usuario]  

Quick tips: ` netsh -c wlan` enters the Wi-Fi context; ` netsh /?` or the context help shows you the available options and their exact syntax. This reduces typing errors and saves you time and troubleshooting.

To inventory interfaces and choose which one to configure, first list their state and type:

netsh interface show interface

Assigning a static IP address to an interface (e.g., Wi-Fi) with gateway and metric in a single line is as simple as this set :

netsh interface ipv4 set address name="Wi-Fi" static 192.168.1.40 255.255.255.0 192.168.1.1 1

Working with saved Wi-Fi profiles is also useful: view profiles, change the connection mode to manual (or back to auto), and control automatic connection to specific networks.

netsh wlan show profiles
netsh wlan set profileparameter name="NombreDeRed" connectionmode=manual
netsh wlan set profileparameter name="NombreDeRed" connectionmode=auto

Viewing IPv4/DNS parameters per interface helps diagnose slow resolutions or incorrect routing on both Wi-Fi and Ethernet:

netsh interface ipv4 show address "Wi-Fi"
netsh interface ipv4 show dns "Wi-Fi"
netsh interface ipv4 show address "Ethernet"
netsh interface ipv4 show dns "Ethernet"

For the firewall, you can open a TCP port (e.g., 80) or delete specific rules if you no longer need them. Be careful with rule names when deleting:

netsh advfirewall firewall add rule name="Open Port 80" dir=in action=allow protocol=TCP localport=80
netsh advfirewall firewall delete rule name="Open Port 80"
netsh advfirewall reset

Configuring DNS (primary and secondary) or returning the interface to DHCP is also straightforward with these commands:

netsh interface ipv4 set dnsservers name="Wi-Fi" static 8.8.8.8 validate=no
netsh interface ipv4 add dnsserver name="Wi-Fi" address=8.8.4.4 index=2 validate=no
netsh interface ipv4 set address name="Wi-Fi" dhcp
netsh interface ipv4 set dnsservers name="Wi-Fi" dhcp

Configuration backup? You can dump the configuration to text and restore it if something goes wrong after a lab test or a hasty adjustment:

netsh dump >> C:\redes\configuracion.txt
netsh -f C:\redes\configuracion.txt

It's not all advantages: netsh lacks a graphical interface, its syntax is prone to errors if you don't know it, many actions require administrator privileges, and some functions have become somewhat outdated with very modern networks (although it is still useful and powerful).

  File Explorer Freezes When Opening Large Folders: Ultimate Troubleshooting Guide

IPv4 and IPv6: Context and Considerations

To understand some of these adjustments, it's helpful to remember what IPv4 offers compared to IPv6. IPv4 has underpinned the internet for decades, with its 32-bit architecture and enormous compatibility across devices and networks. It's simple and, with NAT, allowed for the conservation of public IP addresses for years.

Its drawbacks are well-known: a limited address space of 4.300 billion, complex NAT configurations that can affect applications, and weaker native security compared to IPv6. For all these reasons, IPv6—with 128 bits, more efficient headers, and built-in security—is the natural evolution , although the transition is gradual.

Third-party applications to create a hotspot

If you prefer a graphical interface, there are some very well-established tools available. Connectify is one of the most popular and user-friendly; its free version covers the basics, and the PRO/MAX editions add advanced features, including the ability to act as a repeater . There are also compilations that can help you choose.

Other options have been available, although some are no longer officially distributed. Baidu Hotspot and Virtual Router Plus were popular but are no longer available from their original links. Even so, utilities like OSToto Hotspot (formerly 160WiFi), MyPublicWiFi , and mHotspot still offer a balance between simplicity and control (blacklists, client registration, etc.).

Create a hotspot from your mobile

If you need a quick fix without using your PC, using your smartphone as a hotspot is a fast solution . On Android , search for "Internet sharing and Wi-Fi hotspot" or something similar, set the SSID, security settings, password, and, if your phone allows it, choose the band (2,4/5 GHz).

On iPhone , go to Settings > Personal Hotspot and turn on “Allow Others to Connect.” On iOS , you can only share cellular data (not the Wi-Fi you're connected to), but this is sufficient and stable for most situations.

Advantages of sharing Internet from your PC

Setting up your own hotspot offers greater security than relying on public Wi-Fi. You control who connects, what password you use, and avoid open or suspicious networks where your credentials could be exposed without your knowledge.

You also gain privacy: you don't need to reveal your main Wi-Fi password to your guests; you can create a temporary SSID with its own password and delete it when you're finished. And if your router doesn't have a guest network, this is a quick alternative.

Stability is another advantage: many public networks are congested, with frequent outages. With your hotspot, you control how many devices you connect and the signal quality . The result is usually a much smoother experience.

And in terms of speed, there's little comparison: shared Wi-Fi in cafes or hotels often moves at a snail's pace. By creating your own access point, you reduce competition for bandwidth and make the most of your actual connection.

With all of the above in mind, setting up a virtual Wi-Fi network with netsh or Windows Mobile Hotspot is a powerful, flexible, and secure option for sharing your connection, managing WPA2-PSK/AES keys, using ICS instead of bridges, and combining it with netsh utilities for IPv4, firewall, or DNS. If you respect the limitations (compatible drivers, sleep mode, network profiles) and choose the appropriate method in Windows 10/11, you'll have a reliable and easy-to-maintain hotspot for everyday use.

How to use my Windows PC as a router
Related articles:
How to Use Your Windows PC as a Router: A How-To Guide and Advanced Options