That's bad. So, no way to protect network from vm's ip spoofing using macvtap? 

On Tue, Nov 19, 2013 at 2:21 PM, Laine Stump <laine@laine.org> wrote:

The kernel macvtap packet processing bypasses both iptables and
ebtables, so libvirt's filters are ineffective for guest interfaces
using a macvtap connection.