VNET is the module that tags packets with the xid of the slice that generate them. It is implemented mainly in the xt_MARK extension of iptables. The following rule enables VNET:
To verify if VNET is active:
The reference count on the xt_MARK module should be 2 - accounting for one reference each for incoming and outgoing packets. Without this rule, all packets will be accounted to root.