also... I am using NAT port-forward/DNAT rules to redirect client UDP/53 traffic to the local OPNsense DNS resolver. Could this contribute to the reported Eastpect state collisions by causing DNS queries originally destined for different resolvers to collapse onto the same translated 5-tuple when a client reuses a UDP source port? Is there a way to reduce the volume of the collisions?
"