This has been discussed before. I believe Checkpoint has a capability to list rules according to iptables output, so the more realistic question is whether Astaro will have a capability to take iptables rules and create PF rules. Presently not, but that would be a very strategic piece of software for them, indeed...