In fact, the network filters concept in libvirt seems to be a good way to implement this stuff, but it's only for guest interfaces right now
In fact, the network filters concept in libvirt seems to be a good way to implement this stuff, but it's only for guest interfaces right now