DROP IPv6 forward: in:<wan-interface> out:<guest-interface>, connection-state:invalid src-mac <fritz-box-ip-address>, proto TCP (RST), [2a004005:800::200a]:443->[<lan-ip-address>]:36772, len 20
...but I have the following rules defined and enabled:
chain=forward action=drop connection-state=invalid connection-type="" log=no log-prefix=""
chain=forward action=drop log=yes log-prefix="DROP IPv6"
Why isn't the packet dropped by the first rule but by the second?