does netfilter-persistent reload open up the gates for half a moment?

  1. Netfilter-persistent scripts use iptables-restore tool, that makes atomic reloading of an iptables rule set.
  2. Netfilter-persistent scripts during a boot are run before interfaces will be bringing up (you can check output of systemctl cat netfilter-persistent.service).