The way I got around this was by switching on Advanced Mode in Attended sys upgrade then removing iptables and ip6tables from the list and replacing them with:
iptables-legacy
ip6tables-legacy
Also another package has recently been swapped, xtables I believe, so you may want to add / replace
xtables-legacy
Unfortunately, I connect to my ISP with PPPoE and the last time I tried converting to firewall4 with software / hardware flow offloading it was unreliable (not sure if this has been fixed).