At least one second firewall node filters packets using a second portion of the rule set.
I doubt that any one of us understands every single rule set in the UI Act.