Apparently even iptables-restore does not handle concurrent firewall updates. This is especially a problem in case of HVM, which have two network interfaces (one through stubom and the other direct) added at the same time.