Is it the first rule?
Also I think you need to do something with firewall Zones.
I Found this somewhat useful and it explains the problem. Basically its not a clear communication of iptables to nftables from FW3 to FW4. I have avoided this because I installed SQM
For the Backend “I will do it myself” people: