Sorry. I am interested in any option. Just highlighting @marmarek so he is getting e-mail notifications as Marek may not have the whole Whonix forums subscribed since its generating lots of traffic. And because I am not sure anymore we discussed this at 32c3 and what we concluded.
have updates proxy running over qrexec instead of TCP/IP, so template will not have its own netvm at all
ease integration of “qubes firewall rules” with other firewalls (like Whonix one)
So, those are two (related) things: default rules for the template, not enforced by Whonix (will be solved by “1”), and AppVM firewall rules generally when Whonix gateway is in use (“2” will ease solving it, but itself will not be enough).