Is it the first rule?

Also I think you need to do something with firewall Zones.
I Found this somewhat useful and it explains the problem. Basically its not a clear communication of iptables to nftables from FW3 to FW4. I have avoided this because I installed SQM

For the Backend “I will do it myself” people: