Connection Tracking (conntrack): Design and Implementation Inside Linux Kernel Published at 2020-08-09 | Last Update 2021-04-26 Note: this post also provides a Chinese version. Abstract 1 Introduction 1.1 Concepts 1.2 Thoery 1.3 Design: Netfilter 1.4 Design: further considerations 1.5 Use cases 1.5.1 Network address translation (NAT) Layer 4 load balancing (L4LB) 1.5.2 Stateful firewall OpenStack