> >> -A PVEFW-FORWARD -i fwbr+ -m physdev --physdev-is-bridged -- > physdev-out tap+ -j PVEFW-FWBR-IN > >> -A PVEFW-FORWARD -I fwbr+ -m physdev --physdev-is-bridged > >> --physdev-in tap+ -j PVEFW-FWBR-OUT > >> > >>? > > Yes, but for veth interfaces ? (extra rules, and veth can be random I think ?) OK, you are right!