RESOLUTION
Starting from HSPc 3.2.2 HSPc firewall could be enabled using the following command inside HSPc VE:
# /usr/sbin/hspc-config --firewall ipt_state and iptable_filter modules should be loaded on hardware node and enabled for HSPc VE to load all required rules. Please read this article to know how to allow usage of iptables modules.
Firewall is configured in ipt_enable() function from /usr/share/hspc-config/hspc-config-functions.