Currently It works on application level. It's will be much more better if we block all connections on iptables level (e.g. use user id for filtering etc.) inside VM.