The documentation indicates ( via http://libvirt.org/formatnwfilter.html#nwfelemsRulesProtoMAC ) that <mac> rule types should go in the 'root' chain, however one of the example rules ( from http://libvirt.org/git/?p=libvirt.git;a=blob_plain;f=examples/xml/nwfilter/no-mac-broadcast.xml;hb=HEAD ) has the mac address match in the ipv4 chain. Which is the correct chain for these?