-cluster nodes, and the 'pve-firewall' service updates the underlying
-iptables rules automatically on changes. Any configuration can be
-done using the GUI (i.e. Datacenter -> Firewall -> Options tab (tabs
-at the bottom of the page), or on a Node -> Firewall), so the
-following configuration file snippets are just for completeness.
-
-All firewall configuration files contains sections of key-value
-pairs. Lines beginning with a '#' and blank lines are considered
+cluster nodes, and the `pve-firewall` service updates the underlying
+`iptables` rules automatically on changes.
+
+You can configure anything using the GUI (i.e. *Datacenter* -> *Firewall*,
+or on a *Node* -> *Firewall*), or you can edit the configuration files
+directly using your preferred editor.
+
+Firewall configuration files contains sections of key-value
+pairs. Lines beginning with a `#` and blank lines are considered