When "firewall_flush_rules_and_chains:" is false "Iptables.bash.js" template is missing "iptables -F" But in "firewall.unit.j2" there is "ExecStop = /sbin/iptables -F" And when the service restarts, all additional chains and rules are deleted