I'm closing this BZ as we decided not to block on any firewall and support iptables_hybrid firewall driver instead. This RFE for OSP 17 is tracked in bug 2075038