Did you try to apply the iptable rules by hand for a test?
This turned out to be the exact hint I needed. I turned off firewalld, and applied the rules I'd quoted exactly, to see a different result.
Eventually, it turned out that iptables does not expose zones, and found that applying the rules within the "libvirt" zone resolved the issue.
Thanks