How to filter Windows virtual machines running on your Mac.
A virtual machine runs its own copy of Windows with its own network stack, so by default it does not go through CloudVeil’s filter. This guide points the VM at your Mac’s shared network and installs CloudVeil’s filtering certificate inside Windows, so browsing in the VM is filtered just like the rest of your Mac. The whole process takes about 5 minutes.
Interactive walkthrough
Click through the steps here, or follow the written guide below.
Before you begin
- CloudVeil for Mac must already be installed and running on the host Mac.
- You need a Windows virtual machine set up in Parallels Desktop. The steps are similar in VMware Fusion and UTM — look for the same shared/NAT networking option.
- You need administrator access inside Windows to install a certificate.
Important: Both halves are required. Shared networking alone still leaves Windows showing certificate errors, and the certificate alone does nothing if the VM is on a Bridged network. If you switch the VM back to Bridged later, it will bypass the filter again.
Set the virtual machine to shared networking
Ensure your virtual machine is configured to use the shared network settings. In Parallels, click the network settings icon in the toolbar.
Parallels network settings
Click the network icon in the Parallels toolbar.
Select Shared Network
Make sure Shared Network (Recommended) is selected.
Shared Network (Recommended)
Shared Network routes the VM’s traffic through your Mac.
Export the CloudVeil root certificate
On the Mac, open CloudVeil for Mac and go to Help & Support. Click the export root certificate button.
Help & Support
This saves CloudVeil Filtering Certificate.cer to your Mac.
Move the certificate into Windows
Drag CloudVeil Filtering Certificate.cer to the Downloads folder in the Windows file explorer. (Or place it in a shared folder if you share folders between Mac and Windows.)
Drag into the Windows Downloads folder
Drop the .cer file anywhere Windows can reach it.
Open the certificate in Windows
Inside Windows, double-click CloudVeil Filtering Certificate in the Downloads folder.
Certificate in Downloads
Double-click to open the certificate.
Choose Install Certificate
In the certificate window, click Install Certificate to start the Certificate Import Wizard.
Install Certificate
Click Install Certificate.
Select Local Machine
For Store Location, select Local Machine, then click Next.
Windows asks “Do you want to allow this app to make changes to your device?” Click Yes. Note that No is the highlighted default — be sure to click Yes.
Store Location
Select Local Machine, then Next.
Click Next
Click Next to continue.
User Account Control
Click Yes to allow the change.
Place it in Trusted Root Certification Authorities
Choose Place all certificates in the following store, then click Browse.
Select Trusted Root Certification Authorities, click OK, then click Next.
Certificate store
Don’t leave the automatic option selected.
Browse
Click Browse to pick the store.
Trusted Root Certification Authorities
The certificate must land in Trusted Root, or filtering won’t work.
Confirm the store
Click OK.
Back at the wizard
Click Next.
Finish the import
Check that the summary shows Trusted Root Certification Authorities, then click Finish.
Windows confirms The import was successful. Click OK, then restart any browsers that were already open in the VM so they pick up the new certificate.
Completing the wizard
Confirm the store, then click Finish.
Import successful
Click OK.
Setup complete! That’s it — your Windows virtual machine now routes through CloudVeil and trusts the filtering certificate, so browsers in Windows are filtered. To confirm, visit a blocked site inside the VM: you should see the CloudVeil block page rather than a certificate error.
Need help?
Our support team is happy to help you get set up. If you need additional help, we’re here for you.