Stack Exchange network consists of 183 Q&A communities including Stack Overflow, the largest, most trusted online community for developers to learn, share their knowledge, and build their careers.
@TerryBurton That's a very valid point (hence you got my upvote), but another way is to implement the SYN proxy in the stateful firewall itself. Then you need no separate SYN proxy middlebox, as the firewall itself has the SYN proxy.
No, I haven't tried it yet. Not sure if production network is the proper location for such a trial... On a trial network, such as Linux containers / network namespaces, it could be tried with little difficulty. Perhaps I'll do that.