Hello everyone! I'm trying to create HA firewall, which will dst-nat traffic from outside to local network, but I can't understand how to do this. If i enable sync-connection-track=yes all dnat'ed connections are synced to backup router, but without dstnat flag and them are not src-natted(and dst-natted) by backup router [they are routed as-is from LAN to WAN without any address translation], but SRC-NAT works fine, if I trying to connect from LAN to WAN and shutting down master router connection does not dropping. Can anyone help with that?
(
https://imgur.com/a/O3EiSn4)