Thanks for the suggestion. That’s another weird part, with the firewall disabled iptables is empty:
# iptables --list -v
Chain INPUT (policy ACCEPT 413K packets, 1396M bytes)
pkts bytes target prot opt in out source destination
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 327K packets, 23M bytes)
pkts bytes target prot opt in out source destination