Summary: problem solved
allthough it was excepted (as some contributors wrote here, thanks for the replies) that an automatic reply-to setting should make the
response packets leave the firewall towards the proper gateway I could not see this happen. Always the default route was choosen.
So
1) I do not (as I did in the beginning) choose some kind of automatic firewall generation in the DNAT rules, but choose "manual" rule creation
2) these manual rules can be set with the "Rules [new]" dialogue, but need "Advanced mode".
there I had to configure under "Source Routing" the "Reply-to" to point to the correct uplink gateway.
This means that I have one such rule per target host, target port and incoming interface.
Technically one could combine multiple target hosts and ports into one rule but that would be less specific then and allow additional traffic possibly.
special thanks to @viragomann
allthough it was excepted (as some contributors wrote here, thanks for the replies) that an automatic reply-to setting should make the
response packets leave the firewall towards the proper gateway I could not see this happen. Always the default route was choosen.
So
1) I do not (as I did in the beginning) choose some kind of automatic firewall generation in the DNAT rules, but choose "manual" rule creation
2) these manual rules can be set with the "Rules [new]" dialogue, but need "Advanced mode".
there I had to configure under "Source Routing" the "Reply-to" to point to the correct uplink gateway.
This means that I have one such rule per target host, target port and incoming interface.
Technically one could combine multiple target hosts and ports into one rule but that would be less specific then and allow additional traffic possibly.
special thanks to @viragomann
"