Hey there, great guide. Really helped me out!
I'm attempting to achieve this setup and so far I've had partial success...
I can pass internet to a CT, but not to a VM. VM can ping host, as well as other resources (and vice-versa), but it can't get outside. Again, CT can get outside.
ip a on...