IP RAW - feature that allows traffic to skip Connection tracking
fasttrack-connection - feature that allows traffic to skip everything else except Connection tracking.
No - you can't have both at the same time
Biggest minus of connection tracking is that if it captures packet fragments in NEEDS to de-fragment them - very time and resource consuming process, to account that packet properly
There are 2 ways to use it:
1) connection-tracking enabled=yes and use action="no-track" for some specific traffic to SKIP connection tracking for some traffic.
2) connection-tracking enabled=no and use action="accept" for some specific traffic to SEND it to connection tracking (yes, even if conntrack is off)
So fasttrack and raw is 2 excluding features really
My mind is busy with other question - what firewall filter chain=input/forward rules should i move to ip raw chain=prerouting??