the firewall checkbox on nic is enable a fwbr bridge to get iptables work, but I think it doesn't do it with nftables (because it's not needed), and maybe it's bypass nftables rules when present.
Maybe a note should be added in doc, that nftables activation need a reboot of node to be sure that...