If you have a single machine behand a firewall and the complexities of samba + iptables are too much to handle then turn off iptables. If you are paranoid enough to want iptables enabled on such a machine then you should be paranoid enough to not want things messing with your rules without your knowledge.

iptables-restore < /etc/iptables/rules.v4 ip6tables-restore < /etc/iptables/rules.v6 The two packages are similar, but provide slightly different functionality. If you only install iptables-persistent, you won't get the service definition file for correct handling in systemd,