Good morning.
I come to you because I met the same problem.
It is impossible to accommodate the packet drop on my VM and it is quite embarrassing.
For information the node happens to him though a house the packet DROP but not VM
Here is my file vz.conf iptables
IPTABLES="ipt_REDIRECT ipt_owner ipt_recent iptable_filter iptable_mangle ipt_limit ipt_multiport ipt_tos ipt_TOS ipt_REJECT ipt_TCPMSS ipt_tcpmss ipt_ttl ipt_LOG ipt_length ip_conntrack ip_conntrack_ftp ip_conntrack_irc ipt_conntrack ipt_state ipt_helper iptable_nat ip_nat_ftp ip_nat_irc"
Is there a solution to the problem?