Thanks - my “solution” (a separate rule for 443) works well enough as is.
What I’d like to understand is what is actually happening “behind the scene” so to speak. What I do differently in setting up a single port vs multi-port NAT rule ?
It doesn’t make any sense. One port or multiple ports, it works the same. Check also your other rules, there must be something else influencing this.
And no, ports in IP->Services have nothing to with this, dstnat happens first, so even if some of router’s services listens on same ports, dstnat wins over that.