06:58
Tamino
i wonder if that was sort of the root of it. because that would mean that if the internal IP tries to make more than one outbound connection to the same external (IP, port) pair, then that would count as a reuse of the 4-tuple and be disallowed, just, in general. even without challenge-ack.
because in order for you to have gotten hurt by PAN's behavior, you would have to have been reusing 4-tuples a lot, which normally doesn't happen unless machines are being rebooted a lot.