Am 01.12.22 um 12:32 schrieb Amish:
But conntrack table itself can have 5000-10000 entries at its peak. (assumption)
irrelevant because ctstate rules don't iterate the conntrack tables on their own - ctstate is known implicit because conntrack runs anyways unless you mark packets in the RAW table