Incoming ICMP errors are not properly rewritten when the ICMP error is for a tracked TCP/UDP connection. This will result in TCP/UDP connections that are NAT-ed to never receive ICMP errors.