научный тык привел к этому:
# iptables-save > /etc/sysconfig/iptables
# systemctl start iptables
# systemctl status iptables
iptables.service - IPv4 firewall with iptables
Loaded: loaded (/lib/systemd/system/iptables.service; disabled)
Active: failed (Result: exit-code) since Ср 2017-06-28 17:04:28 MSK; 26min ago
start condition failed at Ср 2017-06-28 17:31:02 MSK; 13s ago
Process: 4059 ExecStart=/etc/init.d/iptables start (code=exited, status=1/FAILURE)
июн 28 17:04:28 xx.xxxx systemd[1]: Starting IPv4 firewall with iptables...
июн 28 17:04:28 xx.xxxx iptables[4059]: iptables firewall is not configured[PASSED]
июн 28 17:04:28 xx.xxxx systemd[1]: iptables.service: main process exited, code=exited, status=1/FAILURE
июн 28 17:04:28 xx.xxxx systemd[1]: Failed to start IPv4 firewall with iptables.
июн 28 17:04:28 xx.xxxx systemd[1]: Unit iptables.service entered failed state
июн 28 17:24:55 xx.xxxx systemd[1]: Started IPv4 firewall with iptables.
июн 28 17:31:02 xx.xxxx systemd[1]: Started IPv4 firewall with iptables.
# ps aux | grep ipta
root 4125 0.0 0.0 3956 796 pts/0 S+ 17:28 0:00 grep --color=auto ipta
ошибок нету. получается работает или нет ??