Filter reload error with NAT reflection enabled
Plus Target Version:
Recent 2.5.0 snap, hit this on reboot:
/tmp/rules.debug:112: rule expands to no valid combination
112:no nat on vmx1 proto tcp from vmx1 to 10.6.0.10 port 22
And several more like it.
Looks like the interface name as a source needs parens, so