In 17.1.8, creating a NAT rule with a destination of "WAN address" causes forwarding for the entire WAN net instead. We had to create a rule to the specific WAN address IP instead to avoid this issue. I don't know on which version this issue started.