> We need to accept traffic at the end of bridge rules for outgoing packets > from tap->ethX, as we don't do ACCEPT in tap-out rules. But we should only accept packages which originates from VMs?