Thanks Ales,
This looks good to me.
Acked-by: Mark Michelson
On 3/28/24 03:54, Ales Musil wrote:
The current packet injection loses ct_state in the process. When
the ct_state is lost we might commit to DNAT zone and perform
zero SNAT after the packet injection. This causes the first session
The current packet injection loses ct_state in the process. When
the ct_state is lost we might commit to DNAT zone and perform
zero SNAT after the packet injection. This causes the first session
to be wrong as the reply packets are not unDNATted.
Instead of re-injecting the packet back into the