Hello, please tell me, did you manage to resolve everything?The fix for the issue with packets sometimes passing has been merged into upstream [1] and we are working on backporting it [2]. I will also look into the nomatch-logic issue this week.
[1] https://lore.kernel.org/netfilter-d.../T/#m3abf2ea4b93935387a14f61dce430a17acec6446
[2] https://lore.proxmox.com/pve-devel/20250911100555.63174-1-g.goller@proxmox.com/