Do not pre-maturely optimize, and a hypervisor is not your firewall, and never should be.
When doing the firewall for all, it is easier with the bigger hosting companies that does MAC bindings - been there, got the scarrs - the firewall solved the problems all at once - than to manage it on all...