Confirmed fixed on my end - thanks @elek. I re-ran the exact same measurement after your k8s/firewall fix: one hour of continuous SYN/SYN-ACK capture at my WAN interface, same vantage and same analysis as before. The in-range failures are gone.
| Source | Source port | Flows | Failed | Rate |
|---|---|---|---|---|
| Storj sat (79.127.163.0/24 + 79.127.205.0/24) | 30000–32767 | 62 | 0 | 0.00% (was 60/60 = 100%) |
| Storj sat (79.127.163.0/24 + 79.127.205.0/24) | anything else | 2,934 | 0 | 0.00% |
| every other network | 30000–32767 | 140 | 0 | 0.00% |
| every other network | anything else | 14,926 | 0 | 0.00% |
Zero blackholed handshakes in the whole 18,062-flow capture. This is a real fix!: the hosts that used to fail 100% of their in-range dials still use the same source ports, but this time and every one completed - 79.127.205.251 drew 12, .250 drew 11, .249 drew 10, 79.127.163.228/.229/.230 drew 8/9/8, all clean. Previously every one of those would have hung.
Really appreciate you chasing it down - glad the capture was useful.