* Allow reception of multicast packets.
* Ensure that link-local multicasts aren't forwarded. (Though
currently no multicasts are forwarded, this isn't necessarily always
going to be the case).
* Turn /off/ iptables filtering of bridged packets. I'm currently
taking the view that the bridges are a hack introduced because I
can't just plug all of the guests into a physical switch. If I need
to do better filtering, I'll either use ebtables or do something
more complicated later.