To check behaviour I disabled shared forwarding. Nothing changed - same behaviour like described above. Same after reboot.
There is an other buggy(?) behaviour in both cases traffic shaping on or off. We have only one interface for our specific net an a single firewall rule, which routes to the specific gateway. But traffic shaper shows some few connections from that specific interface on default-wan/gateway-pipes (upload and download also).
Here our rule (GW3 is our specific gateway):
Seems like traffic shaper detectes packages wrong or firewall-gateway-setting does not match all packages but passes packages to default gateway...
Tell me, which information do you need or how I can help you.