> Is it possible with iptables on host ? drop packets if guestip/tap mac address > couple is wrong. Such things are easy when you have a firewall - like our shorewall scripts. Unfortunately, nobody is working on that topic.