If you don't rely on the legacy iptables-package, another solution is to replace it with iptables-nft and reboot. It's a complete drop-in replacement and requires no configuration changes.
Given that the original iptables-package states it uses the "legacy interface", I think the solution with the "nft interface" is futureproof.
