Seems we cannot filter traffic from containers to KVM VM correctly: venet => vmbrX/tapXiY because of the known physdev match restrictions. Any idea how to handle that?