nf_conntrack has several timeout setting, each for entries of different TCP states [...] default timeout for established state conntrack entries is 423000 s (5 days!). Possible reason for so large a value may be: TCP/IP specification allows established connection stays idle for infinite long time (but still alive)TIL :woozy_baa: