In my setup, which admittedly is a Lithium preview, I needed another two entries in the vyatta-postconfig-bootup.script:

ip6tables -t mangle -I POSTROUTING -j VYOS_SNPT_HOOK

ip6tables -t mangle -I PREROUTING -j VYOS_DNPT_HOOK

I don't know if this is a known issue or a deliberate omission from the template, but I thought I'd mention it. These rules should be there already.

-- kouak

Should we also mention that NPTv6 isn't compatible with stateful firewall rules such as 'related' or 'established'?