Yes, I assume you did update from Gingerbread to ICS via official OTA update - in this case I have to sadly inform you, that T-mobile really patched the kernel and there is no more support for firewall. Actually infra kernels are very good, but this is the classic case of pawned kernel by vendor. You can find some ways how to fix it - just look for kernel with iptables support.