Just been looking at an issue where I had lost NFS access across a site-to-site Wireguard VPN.
I found that a permit rule that was using an alias that contained aliases ( Alias_NW1, Alias_NW2 ) was not allowing traffic to pass.
While a separate rules for Alias_NW1 and Alias_NW2 worked as they should.
This looks to be a change of behavior from prior to 26-7