I've read some docs about "iptables physdev match" module, and managed to get simple firewall working where we can do some firewalling without knowing anything about IP addressing inside KVM guests.
Hope someone will find this info useful :-)
Traffic flow:
Incomming traffic:
--> [eth0]...