firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)