просто жопа, когда несколько программных модулей пытаются влезть в одну сущность. Тот же айписек, например, тоже корежит правила файрволла
One issue with firewalld’s use of iptables and family is that firewalld assumes complete control of the hosts firewalling. With the nftables backend this is no longer true. Since nftables allows multiple namespaces (tables in nftables vernacular), firewalld will scope all of its rules, sets, and chains to the firewalldtable. This will avoid much of the contention with other pieces of software that don’t interact directly with firewalld.