This will ensure that /rw/config/rc.local is called after applying default iptables rules, so it can safely modify it without the risk to be overridden later by default ones.
@@ -1,6 +1,6 @@
[Unit]
Description=Qubes misc post-boot actions
-After=qubes-dvm.service
+After=qubes-dvm.service network.target
[Service]
Type=oneshot