Firewall dropping incoming packets for srcnat by the input chain.

Found this:
http://forum.mikrotik.com/t/connection-tracking-timeout-values/77167/1
and this:
http://forum.mikrotik.com/t/lot-of-packets-being-dropped-due-to-invalid-connection/17948/1

I increased the timeouts, but still get the some amount of invalid packets.
Most of the invalid packets are RST, or ACK/FYN for an already discarded nat connection.
Maybe this is normal, but I’m not sure.