The VRF-Lite configuration uses mangle to handle incoming packets. This works for connections established from the internal side.
UPnP will dynamically create NAT rules when used from with a VRF, but a matching mangle rule is also required. Is there a way to automatically create/update/remove these rules to match the NAT rules?