Hello.
I believe it would be useful if routed packets go through connection-tracking (and therefore consume more processing power) only if we want them to and that it would be useful if we could control this. Possibly by destination subnet - for example all our clients with Public IPs.
This way we would offload conntrack and save CPU and have more confidence that IP packets are not "touched" in any way while passing through the Linux-kernel based MikroTik RouterOS
What do you think?
Thanks.