Same problem here! Hours lost, but I'm lucky enough to have found this post. Thank you very much! For those asking which rule/how to move, go to menu IP->Firewall. In Filter tab look for the rule in chain forward, action accept, comment = defconf: accept established, related, untracked and move it (...