What you need to do is add the script startup.sh to your firewall applications. I think it's quite strange that it works this way, but it seems to do the trick.