kubernetes – What is the best way editing iptables rules while using Calico network plugin

We are running Calico network plugin along with K8S’s. We need to modify iptables rules for various reasons, but it seems does not always work well as we also have chains cali-XXX and KUBE-FIREWALL chains overwriting/preceding them immediately in some cases. What is the best way to modify iptables rules in our case ?