I ended up with the solution posted here: changing the firewall rule source from network tag to subnet apparently solved, 24h now without an error!