Using 'any' led to specifying '0.0.0.0' or '::', respectively, as destination in the corresponding firewall INPUT rule. That is wrong however. What is wanted here is a match-all destination, so use '0.0.0.0/0' or '::/0', respectively.
(detail)
by kristov