On Mon, Nov 07, 2022 at 09:00:11AM -0500, John Lauro wrote: > The SYN-ACK tracking works in transparert mode with haproxy. I have setup > haproxy to rebind all connections before and basically proxy the internet > (and use NAT for udp). That said, I assume the point of DSR is that it's > not always going to take the same path and that is where the real issue > is. Haproxy can handle an initial SYN-ACK man in the middle, but moving > the end point would be the problem.
Transparent mode is different from DSR, you *really* have two connections. In DSR haproxy would never see the return traffic. Willy

