SuSEfirewall2_init doesn't need any networking. It only installs basic rules to disallow incoming traffic. So it can run as early as possible. During boot no iptables rules are installed then until SuSEfirewall2_setup. After that one has run udev events trigger SuSEfirewall2 on iface add/rm.