The firewall flowtable should allow ethX only interfaces.
It does not need to be set to PPP/BOND/VLAN/WG/etc, as it will work anyway if this interface is part of the forwarding of eth.
set firewall flowtable OFFLOAD interface ethX
Needs to consider/recheck about VLANs as at least it mentioned in the code https://elixir.bootlin.com/linux/v6.6.28/source/include/net/netfilter/nf_flow_table.h#L26