Yes, it’s the same. If association did not work with block private removed the issue was auto-reply-to to your upstream gateway and your upstream router does not send your reply back internally. For some this works normally even so, for some it doesn’t. Disable reply-to from advanced section of manual firewall rule or from the advanced firewall settings altogether.
PS: A Port forward by definition is a tolerated security issue. The default is to go through the additional filter to associated rule, but if you don’t want that or something is wrong with this a simple pass is ok too. Not passing the traffic is a POLA violation. We do all we can in the defaults, but it is an uphill battle in terms of security and no easy answer as you can see.