If you have an asymetric traffic pattern, like the OpenVPN setup mentioned by metamul in post #12, I would suggest to leave the existing rule intact, and instead add an exception for the vpn traffic back to the peer network (10.8.0.0/24):
iptables -I FORWARD -m state --state INVALID...