> >>That behaves quite the same. > > Maybe, without veth ? (using bridge ip directly?). > So we don't need to have physdev match. We need physdev match to filter traffic from VMs?