(In reply to Valentin Rothberg from comment #1) > Do you know if there's an open issue or PR for upstream? I checked quickly, > but couldn't find something that matches. The reporter mentioned this bug on IRC, and I identified it as an upstream regression (we don't have any iptables patches, and the bug occurs due to iptables rules AFAICS). I didn't submit an issue upstream yet, but I should do that soon. The main thing stopping me from doing so is that I cannot reproduce the issue locally at the moment -- meaning that bisecting is going to be a nightmare.