On Fri, Sep 11, 2026 at 04:09:51PM +0200, Pablo Neira Ayuso wrote:
Hi Julius,
On Fri, Sep 11, 2026 at 12:10:04PM +0000, Julius Bairaktaris wrote:
quoted
Hi Pablo,
thanks for taking your time to review.
quoted
conntrack needs to see packets in both directions, are you assuming a
packet-based load balancer in front of it?
No, an asymmetric route is in front of it, with two subnets sharing one
L2 segment and the server answering over that link, so the router only
ever sees one direction.
I see this requirement to support asymmetric path keeps coming, but
how hard is really to maintain this TCP state machine to deal with all
possible scenarios? ie. invalid transitions, retransmissions, etc.
this all without having access to full TCP connection. Is it that you
need NAT and the stateless NAT in nftables does not fulfill your
requirements?
I can reply myself, you're targetting at offloading this flow via the
flowtable.
Let me take a look what can be done here for this assymetric case.