I've been testing out the newer nftables-based firewall, and outside of the (very annoying) syntax changes for iplists/aliases, it seems to be working well.
However, I noticed an issue when configuring a VM that has three network interfaces. Only two of the three interfaces have the firewall...