> Theses rules is to send to PVEFW-FORWARD, only firewalled vms. > ipset is really usefull, to avoid have 1 line by vm. (multiple containers with 1 > ip) (I have send a patch for demo) I see, and it is quite simple anyways ;-) Good work!