If you ask if it could be a bug then the answer is “Yes, it could be” but ..
A. Are you sure that you have no NAT rule which redirects packets to 10.251.0.20 or 10.251.0.142 or 10.251.0.174?
B. As it is forward chain then I suspect that that is “returning” stream of data to PC or other devices which have started communication sending data via VRRP interface which have had been masquaraded. Just quessing as we have no configuration of your device … even simple drawing what, where and how is configured.
A. Yes, I’m sure, there are no NAT rule which other IPs. Only the /24 ( current /32 ).
Additional Information. The Subnet 10.251.0.0/24 is for some L2TP Connetion. At the Moment only for 10.251.0.10 ( only on L2TP )
B. Only one L2TP Tunnel has the IP 10.251.0.10, so no other Device can started communication sendig data via VRRP.
After I change from /24 to /32 I see in the logfile that the output Interface change to the correct Interface ( out:l2tp )
Before I change the subnet, the output Interface was the parent Interface for the VRRP Interface.
I change the subnet in NAT. No IP from the subnet is configure in the MT. The IP is only available after connect via L2TP.