I wanted to test the efficiency of Ipfilter-net for container.  
Inside the container, after running the following command ( from https://sandilands.info/sgordon/address-spoofing-with-iptables-in-linux), spoofing the ip, all output network activity is blocked ( ping etc).
iptables -t nat -A...