The vnet needs to be attached to **not** em0.

The host can now ping the jail, and the jail can ping the host.
The problem: we can't do NAT.
tcpdump shows no traffic on em1 leaving the jail.
Is that because bridge0 members are em0, em1, vnet0 ?
Let's try vanilla jails.