Philip Schaten <philip@xxxxxxxxxxxxxx> wrote: > > The normal way to accept packets from a nat'ed connection is something > > like 'ct status dnat accept' > "ct state dnat accept" leads me to this bug. > http://lists.netfilter.org/pipermail/netfilter-buglog/2016-March/003393.html What nft version are you using? That bug should have been fixed 3 years ago.