Does netfilter/iptables support failover/HA?
The answer is a clear ‘yes’ and ‘no’. If you are thinking about a full failover, while all the state information is preserved: Not really. Doing state synchronization between multiple nodes is a difficult process. Harald (of the netfilter core team) has published a paper about this, but not yet found any sponsor to fund the development. Meanwhile, you can try to use our ‘connection pickup’ feature, which [after a failover] tries to pick up already established connections: Might be sufficient depending on the requirements. If you do NAT and want to preserve your NAT mappings: No.