Hotspot dynamic firewall rules overriding static rules

I know there was a post about this back in the late RC/early 2.9 days, but I can’t seem to find it anywhere…

I’ve got a bunch of dst-nat, input, and forward firewall rules that get bumped down the list everytime I reboot my 2.9.10 hotspot router, then they stop working. How can you make them “stick” and not get put below the dynamic firewall rules generated by the Hotspot? Finally trying to migrate to 2.9 but this is killing me.

^ bump ^

Anyone? Please?