There were multiple problems with reusing existing one: - need to sync with upstream changes (configuration path etc) - conflicts resolution on updates - lack of iptables --wait, which causes firewall fail to load sometimes QubesOS/qubes-issues#1067