FreePBX Firewall Custom Rules loaded last

We have intermittently been seeing an issue with iptables where the Freepbx rules are loaded before our custom rules. I’ll post a screenshot below - the rules that are blurred out are our custom rules. Could this have anything to do with the permissions of /etc/firewall-4.rules? This article says that the permissions should be 644, but on a new install of Freepbx, they are 666. https://sangomakb.atlassian.net/wiki/spaces/PG/pages/26083485/PBX+GUI+-+Firewall+Custom+Rules#Setting-Permissions

I can also confirm that the rules in /etc/firewall-4.rules are -I INPUT etc etc.