Next hop traffic getting blocked by invalid state rule

It looks like there’s been some changes to how the firewall works very recently. I’m certainly used to attaching rulesets to interfaces, not what appears to be global rules in the rolling version. I took a look at this post and a few other example configs and looking at the cli tree in the latest rolling, it looks like you can still configure the invalid state rule under forward filter instead of in global option. Would that make a difference? Clearly, I’m really struggling to understand how the invalid state rule gets applied.