I also have this issue, I tried to modify router_patconfig with the suggestion above, but it still doesn’t work.

I think it would be just AWESOME if next to each virtual server you have a checkbox that says “Reflection” (or hairpin) and if you check it ZS will create the 2? extra iptables commands to allow access to the WAN ip port forwards from the internal range.