Prferable way to add iptables entry into sys-firewall dvm

Official guide to firewall states that if we wanna add rule to iptables that allow internet connection between VMs we should put it into /rw/config/qubes-firewall-user-script but in disposable sys-firewall it not working. What is the right solution for that?

/rw/config/qubes-firewall-user-script of a dvm-template.