Qubes sys-whonix does not do its job as Qubes FirewallVM

Since port to nftables as a replacement for iptables was completed, this ticket can now make progress. I plan to work on this one and will post updates here.