MacVisor Beta

Custom networks

Named shared and host-only segments: what macOS 27 lets you pin, gateway services, DHCP reservations, network port forwards, and VLAN uplinks.

A custom network is a named private segment any number of VMs can join. VMs on it see each other directly; the mode decides whether anything routes outside.

ModeBehaviour
Shared (NAT)Private segment plus an uplink that NATs to the outside through the Mac
Host OnlyThe host and the VMs on the segment, nothing beyond

Manage them in the Networks section of the sidebar or with mvz networks. VMs made from cloud images join one by default, the Default MacVisor Network.

A custom network: VM ports on one vmnet segment, gateway services, and an optional NAT uplink.

Defining a network

A network is a definition when you create it and becomes live when the first VM on it starts; the detail view shows which. Attach a VM in VM Settings → Network or with mvz set <vm> --network <network>; a running VM picks the change up at its next start.

mvz networks                                   # list
mvz networks create lab                        # shared, automatic subnet
mvz networks create isolated --host-only       # host-only, automatic subnet
mvz set dev --network lab
mvz networks rm lab                            # refused while a VM uses it

Addressing

Leave addressing empty and vmnet picks a /24 under 192.168.0.0/16. On macOS 27 what you can pin is limited by vmnet, not MacVisor:

NetworkSubnetDHCP from macOSReservations
Shared (NAT)Chosen by vmnet each time the network is created; a fixed subnet is refusedYesHonoured while the subnet stays the same
Host Only, automatic subnetChosen by vmnetYesHonoured
Host Only, fixed subnetYours: a /24 under 192.168.0.0/16NoneIgnored; set addresses inside the guests
  • IPv4 subnet and mask: host-only only, a /24 under 192.168.0.0/16. MacVisor warns before you save anything else. Guests on a fixed subnet need static addresses.
  • IPv6 prefix and length: a specific ULA prefix instead of a random one.
  • MTU: 1500 by default.

Applying a change to a shared network recreates it, and vmnet picks the subnet afresh. Addresses therefore survive VM restarts but not edits to the network. The firewall is keyed to the subnet and follows it; reservations and anything you wrote down by hand do not.

Services

Each network runs its own gateway services, individually switchable:

ServicePurpose
DHCP serverAddresses guests from the segment's pool
DNS proxyGuests resolve through the host (shared mode)
IPv4 NAT (NAT44)Outbound IPv4 through the uplink (shared mode)
IPv6 NAT (NAT66)Outbound IPv6 through the uplink (shared mode)
Router advertisementIPv6 autoconfiguration on the segment

The service switches on a shared network: DHCP and reservations serve the segment, DNS and IPv6 RA configure guests, NAT44/NAT66 provide an uplink, and TCP/UDP rules publish selected services.

Services by mode

ControlShared (NAT)Host Only
DHCP serverConfigurableConfigurable (automatic subnet only)
DNS proxyConfigurableOff
IPv4 NAT (NAT44)ConfigurableOff
IPv6 NAT (NAT66)ConfigurableOff
IPv6 router advertisementConfigurableConfigurable

Host Only has no uplink, so switching a network to it turns DNS proxy, NAT44, and NAT66 off. In shared mode you can pin the uplink to one host interface, which is useful on a Mac with both Wi-Fi and Ethernet, or to go out through a VLAN interface.

While a network's firewall is on, NAT66 and router advertisement are off and their switches are greyed out, because the firewall filters IPv4 only and guests could otherwise go around it over IPv6. Your settings come back when the firewall is turned off. A shared network with NAT44 off is the exception: IPv6 NAT is its only way out, so its IPv6 stays on, unfiltered. VMs already running keep IPv6 until every VM on the network has stopped.

DHCP reservations

A reservation binds a MAC address to an address in the subnet, so a guest keeps its IP across reboots and reinstalls with no guest-side configuration. The MAC picker lists the NICs of VMs already on the network.

mvz ip dev --wait                          # see which subnet vmnet gave the network
mvz networks reserve lab dev 192.168.105.50

Two conditions, both vmnet's:

  • The guest must send its MAC in the DHCP request. Cloud-image VMs do. A hand-installed Ubuntu sends a DUID until you set dhcp-identifier: mac.
  • Reservations exist only where macOS serves DHCP: shared networks, and host-only networks on an automatic subnet. On a shared network they hold while the subnet stays; see Addressing.

Reservations are what make port forwards and firewall rules that name an address dependable.

Network port forwarding

Network-level forwards are vmnet NAT rules: a host TCP or UDP port maps to an address and port inside the segment.

host :8443  →  192.168.105.10:443

Seeing what is attached

The network detail view lists every VM NIC configured for the network:

  • Green: seen on the network's bridge via ARP.
  • Orange: the VM is running but nothing from that NIC has been seen, or its attachment failed. Check the VM's runner log.
  • Stopped: configured, not running.

A port group with six attached VMs and its NAT gateway.

The Networks section also browses host interfaces (physical uplinks, vmnet bridges, VLAN interfaces) with their addresses, child interfaces, and attached VM ports.

VLAN interfaces

Apple's Virtualization framework has no VLAN tagging, so MacVisor creates 802.1Q VLAN interfaces on the host. New VLAN Interface… takes a name, a tag from 1 to 4094, and a parent interface. VLAN changes go through the network helper, which makes them for an administrator account without asking again and deletes only VLAN interfaces MacVisor created. A standard account, a Mac without the helper, or deleting a VLAN interface the helper didn't create (one made in System Settings, without the helper, or by an earlier MacVisor) asks for an administrator password each time. The result is a bridged host interface for VM NICs, and an uplink choice for shared networks.

A physical Ethernet interface can carry multiple tagged host VLAN interfaces; MacVisor exposes each as a bridge target or custom-network uplink.

Firewalling a network

Each custom network can carry an inbound/outbound policy enforced by the host packet filter, set in the app or with mvz networks firewall, and applied by the background service whether or not the app is open. Rules are checked in order and the first match wins; the CLI keeps them in the order you type them and adds new ones after the existing rules unless --clear. See Network firewall.

Deleting a network

Delete removes the definition; it and mvz networks rm are refused while a VM uses the network. That includes a suspended VM whose saved session was made on it, even if you have since moved the VM to another network, because the session resumes on the network it was saved with. Resume that VM and shut it down, or start it from disk, first. VMs still pointing at a deleted network land on the Default MacVisor Network the next time they are cloned or imported, so re-point their NICs first.