it looks like iptables is updated incorrectly when a firewall rule is created that crosses a date boundary when translated from local timzeone to utc. how to reproduce: 1) create a firewall rule and turn on "Use time constraints". 2) select a time in (your local timezone, of course) that is before midnight, and when converted to UTC is past midnight. i.e. 10 pm PT Monday for local time, converted to UTC is 5 am UTC Tuesday. 3) save the rule and apply the changes. 4) list the iptables rules that were created. you will see a rule for monday at 5 am UTC in this case, which should be tuesday at 5 am UTC.