Yes.  The virtdomain support in 2.2 can use either fully qualified useridz (as
you show above) or it can do a reverse lookup of the interface that the
connection comes in on (for those who have IPs to burn).

Yes.  It must be created and have the correct ACL (posting allowed for anyone).

