Firewall rule on/off switch is set where in the uci settings?

Being aware of the /etc/config/firewall and editing (disabling) rules through luci I am wondering where the swtich is being set.

Simple minded logic would imply that such disbaled rule being commented (#) in /etc/config/firewall but it does not appear so, such rule remains apparently undisturbed there. Thence (again being simple minded) would assume that either the on/off switch is set somehere else - but where?

And where are the syn flood protection settings located, aside from option syn_flood '1' in /etc/config/firewall? :confused:

Also the following rules are injected into the firewall

Set tcp_ecn to off
Set tcp_syncookies to on
Set tcp_window_scaling to on

The first two are stated in the sysctl.conf but removing them from there has no impact, still showing up and thus there must be another source, notwithstanding the last rule.

Where is all of this coming from?

Set tcp_ecn to off
Set tcp_syncookies to on
Set tcp_window_scaling to on

Seem to be bootloader environment variables