Dear Spirit, in case of SNAT/DNAT, do we really need add POSTROUTING rule? In my case PVE firewall works for outgoing rules without POSTROUTING rule (PVE 5.2).
Also I wonder, how pve-firewall works on outgoing traffic rules. For example, if I define blocking outgoing rule on cluster/node...