1.4. Firewall direct rules
The firewalld service provides multiple ways with which to configure rules, including regular rules and direct rules.
One difference between these is how each method interacts with the underlying backend (iptables or nftables).
The direct rules are advanced, low-level rules that allow direct interaction with iptables. However, the iptables component is unmaintained and will be eventually removed from RHEL. Therefore you might consider replacing direct rules with nftables. For more details, review the knowledgebase solution How to replace firewalld direct rules with nftables?, and policy objects related parts in Filtering forwarded traffic between zones.