@qdemouliere @feld
iptables is totally screwed up, but have you tried nftables?
I've converted all my Linux servers to nftables specifically due to its syntax similarity to BSD