Not ideal, we don't want to do anything within the VM itself. Previous software set these rules on the host node.
No, they are not. As noted, the only way to do this in the GUI would be for admin to create a rule in and out but users could then alter their own specific VM rules. There is no way...