Firewall behind comcast cable modem doesn't forward

We have installed a new ipfire firewall (2.23 core update 137). I have followed the instructions here: https://wiki.ipfire.org/configuration/firewall/rules/port-forwarding/red_to_server_on_green (with the exception of putting in my green side web server ip 172.16.0.10. I am getting a drop_input on traffic from the outside world to the ipfire. I have ports 80 and 443 forwarding from our external IP (no URL associated, just the ip) from our cable modem which is on 10.1.10.1.

I am getting drop_input in the logs showing the source as my external IP address and the destination as the firewall red IP

image

my iptables entry shows
Chain FORWARDFW (1 references)
target prot opt source destination
ACCEPT tcp – anywhere 172.16.0.10

Any guidance is appreciated

I didn’t have NAT firewall set to auto.

resolved.