The cool thing is that /etc/iptables/rules.v4 and /etc/iptables/rules.v6 get loaded at bootup. So if you're living dangerously, you just use /etc/iptables/test-rules.v4 or whatever. If you get locked out, just reboot the server. Or have it rebooted, if you don't have a management console.
Why do you need a wrapper at all? I looked at shorewall ten years ago and it just made everything more complicated than just doing it raw.
Term is also nice because it still uses iptables syntax.
I do agree on the iptables vs wrapper issue. I started out using Shorewall, and then ufw. But once I started learning iptables, I decided that it was simpler to just use it.
https://github.com/benkillin/linux-firewall
the ip6 section needs some further development though - I have no need for it in my scenario at the moment.