Bookworm: lxc containers don't get IP addresses

I’m struggling with lxc networking on a bookworm (Debian 12) host:
The containers don’t get an IP address on their virtual eth-interface (beside the link-local IPv6 one).

This is a fresh setup using ansible/debops and a configuration that worked fine on a bullseye host. Config is unchanged from the old setup, only the host is bookworm instead of bullseye. Configfiles (generated by ansible/debops) are the same (AFAIS).

Any ideas?

This was caused be the firewall on the host :frowning: