Rutos firewall rules

HELLO,
Please allow me this message.

Hardware: Rutx10 ( fimware installer via boot loader) 7.09.3
1-
we have a firewall block all rule.
When I apply a rule via the web to authorize only 1 port ( 21 ), it authorizes full web.
when applied via custom rule it’s ok:
iptables -I FORWARD 1 -p tcp --dport 21 -j ACCEPT
iptables -I FORWARD 1 -p tcp --dport 20 -j ACCEPT

2-
on a rutx12.
do you have a solution to authorize tailcaile only on wan, refuse 4g.

thank you for your help
Antoine

Translated with DeepL.com (free version)