This is probably the same as https://bugzilla.redhat.com/show_bug.cgi?id=1451902 I'm looking to make sure that we have the patch that reduces the number of calls to iptables, but the real fix will be when the kernel change to fix https://bugzilla.redhat.com/show_bug.cgi?id=1503702 lands.
*** This bug has been marked as a duplicate of bug 1503252 ***