Although it is based on iptables, it does not standard configuration files (for example /etc/sysconfig/iptables).
So the best way is always use the esxcfg-firewall command.
Andre
Andrew | http://about.me/amauro | http://vinfrastructure.it/ | @Andrea_Mauro