Não é uma resposta ideal se você tem muitos contêineres, mas é possível usar o arquivo repositórios shorewall com uma entrada para cada host, ou seja, com uma rede / 32 como esta:
/ etc / shorewall / interfaces:
#ZONE INTERFACE OPTIONS
...
lxc lxc-br0 ...,routeback,bridge
/ etc / shorewall / zones:
#ZONE TYPE OPTIONS IN OUT
fw firewall
lxc ipv4
lxc12:lxc ipv4
/ etc / shorewall / hosts:
#ZONE HOSTS OPTIONS
lxc12 lxc-br0:192.168.0.12/32
/ etc / shorewall / rules:
######################################################################################################################################################################################################
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK CONNLIMIT TIME HEADERS SWITCH HELPER
# PORT PORT(S) DEST LIMIT GROUP
#Allow host web server to proxy requests to the container
Web(ACCEPT) $FW lxc12