I'm marking this as Fix Released as the Focal FFe (v4.5.0) will likely
be accepted and there is a reference there for this bug. There is also
the fact that there is no *fix* properly saying: its just a reference
saying upstream knows about this issue and ignores it on purpose for
now. If ffe is
commit 92c49b6f2847546f3f938b10a2a97021774f0be3
Author: Jan Pokorný
Date: Wed Dec 4 14:36:59 2019 +0100
IPaddr2: ipt_CLUSTERIP "iptables" extension not "nft" backend
compatible
Reference:
https://lists.clusterlabs.org/pipermail/users/2019-December/026674.html
(thread also
For strongswan, I found a reference in a 2018 workshop to work on
xt_cluster support:
https://wiki.strongswan.org/projects/strongswan/wiki/Linux_IPsec_Workshop_2018
No open bug reports about moving from ipt_CLUSTERIP to xt_cluster, just
references in old bugs about how that was wanted, but just