The first SYN packet never arrives the server. If I do not make a logical mistake, there is no RDR entry for source=VPN dest=1.2.3.4, but there are entries from internal clients.
Is the RDR rule not bound to VPN interfaces? Where is it defined?
Is the RDR rule not bound to VPN interfaces? Where is it defined?