My google-fu was not strong enough to find a walkthrough of how to filter the local network for a libvirt guest instance which is using a nat-ed interface while keeping the access to the internet working.
Here is what i came up with:
Define nwfilter rule
My local network is …