Solved. http://marc.info/?l=netfilter-devel&m=150027256708621&w=2
You are probably lacking the reply NAT chain, which needs to be
registered.
https://wiki.nftables.org/wiki-nftables/index.php/Performing_Network_Address_Translation_(NAT)
I'm updating right now the wiki to put this in bold.
On 2017-07-15 22:47, sorcus@xxxxxxxxxxx wrote:
Output for command nft --debug all -f ruleset
https://gist.github.com/MrSorcus/2c8c65461e3c65fb70364f3a70d95439
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html