Oder so:
/etc/systemd/system/custom-firewall.service
[Unit]
After=pve-manager.service
[Service]
ExecStart=/usr/local/bin/custom-firewall.sh
[Install]
WantedBy=default.target
/usr/local/bin/custom-firewall.sh
#!/bin/bash
iptables -t nat -I PREROUTING -d _IP_ -p tcp --dport 443 -j DNAT...