Hi, I wouldn't think that is the problem...as far as I know conntrack sets specific timeouts on the connections to match with the actual conntrack state. You can see these via sysctl -a | grep net.netfilter.nf_conntrack_ Best, Jesus -----Original Message----- From: Dennis Jacobfeuerborn [mailto:dennisml@xxxxxxxxxxxx] Sent: 20 January 2017 12:37 To: Mark Coetser <mark@xxxxxxxxxxxx>; Llorente Santos Jesus <jesus.llorente.santos@xxxxxxxx>; netfilter@xxxxxxxxxxxxxxx Subject: Re: intermittent nat issue On 20.01.2017 10:47, Mark Coetser wrote: > Hi Llorente > > I did run conntrack -F to check that but still had the unnatted > packets traversing the interface. > Hi, I'm seeing this as well on our systems. One thing I notice is that all packets either the RST of FIN flag set. Could this be some sort of race condition where Conntrack removes the connection from the table because of the flags and as a result the final packet will not get masqueraded/nat'ed? Regards, Dennis ��.n��������+%������w��{.n����z���)��jg��������ݢj����G�������j:+v���w�m������w�������h�����٥