I have worked on the options on the Firewall to edit rules and to disable/enable rules,
on this moment is edit not working and is there fore on development.
If the checkbox before the rule is checked the rule becomes red on the rules list this means the rule is disabled/suspended.
when you check or uncheck the checkbox the page is automaticly reloaded and the change is made to the rule set.
when the checkbox before the rule is not checked the rule is active again.
there are some rules on the firewall that are automatic enabled/disabled like the rules for VPN-clients,
when a client is not connected the rule is automaticly disabled when the client is active the rule became active only if the checkbox before the rule is not checked, this rules have another active/disabled administrative setting for the system only this can't be set by person.
for now i found a bug for forward in combination with nat-prerouting,
and for now 2 rules needed to be set with nat-prerouting one for nat-prerouting,
and one for INPUT or FORWARD i'm working on a fix what set those rules automaticly when nat-prerouting is selected.
when the firewall is ready there will be an wiki page for the firewall wich explain it.