(In reply to Reinhard Max from comment #1) > > How can I in the meantime get the iptables hack permanently enabled? > > One way would be to add it to an appropriate place in this file: > /etc/sysconfig/scripts/SuSEfirewall2-custom > > But maybe there is a better place somewhere in the network scripts of > libvirt. AFAICT from #0, br0 managed by yast/wicked is being used, not a libvirt-managed network. So I guess /etc/sysconfig/scripts/SuSEfirewall2-custom is the place to put such a rule.