Description of problem:
xtables-nft-multi maybe not check rule as strict as old iptables.
Version-Release number of selected component (if applicable):
iptables v1.8.1 (nf_tables)
Steps to Reproduce:
iptables -t mangle -A OUTPUT -p tcp -j TCPMSS --set-mss 135
RHEL7 will give a promptin dmesg: xt_TCPMSS: Only works on TCP SYN packets
but RHEL8 accept this rule without --syn.
accept is rule.
reject this rule and give out prompt.
*** This bug has been marked as a duplicate of bug 1659307 ***