> any comments for theses patches ? AFAIK iptables support interface wildcards, so you can use 'tap100i+' to match all interfaces for VM 100. Would that help to optimize things further?