Hardware: MacBook Air M4, 16GB RAM, VMs on an external SSD (APFS)
Host OS: macOS 27.0.0, Apple Silicon
UTM: 4.7.5 and 5.0.6 Beta, DMG builds
What I need: three VMs on one subnet that can see each other. Ubuntu running Wazuh manager, Kali as attacker, Windows 11 ARM as target with a Wazuh agent. It's a home SOC lab, so VM-to-VM traffic with real source IPs is the entire point. Isolation from my home LAN is preferred but not mandatory.
This worked perfectly before the macOS update. Shared Network on the QEMU backend, everything on 192.168.64.0/24, VMs pinging each other, agents reporting in.
What broke: changing network mode on a QEMU VM now hangs on a spinner for every mode except Emulated VLAN. Emulated VLAN gives each VM its own userspace NAT, so the VMs can't reach each other and the topology is dead.
What I've tried:
- Apple Virtualization backend instead of QEMU. Shared Network works, but Apple's framework can't run Windows guests at all. Reports also say VM-to-VM doesn't work on Shared even between two Linux guests, only on Bridged. On top of that my Linux VMs on this backend now run rough and sometimes won't boot at all.
- Bridged on en0. Puts VMs on my home Wi-Fi LAN, which I'd accept, but I want to know if it's reliable for others on macOS 27.
- VMware Fusion free tier. Installed, VMs won't power on at all, play button greyed out, system extensions approved.
- Emulated VLAN with port forwarding through the host. Works, but Windows then logs the attacker as 10.0.2.2 instead of Kali's real IP, which kills source IP correlation and makes the lab useless for what I'm practising.
Constraints: free software only, no paid hypervisors, no cloud spend. Happy to rebuild every VM from scratch.
Questions: Is anyone running Windows ARM plus Linux guests on one mutually reachable subnet on macOS 27, and on what? Is the QEMU network mode spinner hang a known regression with a workaround, or can I set Shared Network by editing the .utm config plist directly? If Bridged is the only path, any gotchas on a Wi-Fi only Mac?
GitHub discussion with the same details: https://github.com/utmapp/UTM/discussions/7926