I literally cannot compare one snippet of a config that "is working" to another that "is not" when they don't show anything that can actually be compared.
Yes, the two rules are the same on the surface, however due to implementation differences, the behaviour may be entirely different. For example, the USG using explicit DNAT and Firewall rules (which are able to be logged), rather than the "port forward wizard" entries with "auto firewall" enabled you have on the ER (which are not logged).