utmapp / utmapp/UTM

No route/nat to (split) VPN tunnel on host

Open
#7,207 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
Swift
Stars
35.5k
Forks
1.8k
Avg merge
5d 5h
Merged PRs (30d)
7

Description

I run Tunnelblick (OpenVPN) on host which split tunnels a subnet 100.100/24 to corporate. When using UTM guest using Apple Virtualisation in either NAT or bridged mode, I cannot seem to route over the tunnel. I have a colleague with a very similar setup and he is able to. The underlying problem is that NAT is not happening from the UTM guest subnet over the utun interface created by OpenVPN. I added an explicit rule to pf.conf: `nat on utun6 from 192.168.65.0/24 to any -> (utun6)` and that appeared to work, but this has two issues (1) I have to hardcode the interface name and that may not be the same for every run of Tunnelblick and (2) this breaks iCloud Private Relay.

Weird thing is, Colima which is used for docker, creates an Apple Virtualised VM (though I'm not sure what network mode - I think NAT), and I'm able to ssh onto the guest VM and then connect to corp VPN tunnel services just fine.

Any assistance would be appreciated.

**Configuration**
* UTM Version: 4.6.5 (108)
* macOS Version: 15.5 (24F74)
* Mac Chip (Intel, M1, ...): M3 Max

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.