When k8s cluster use ipvlan L3/L2, macvlan or other underlay network plugin. The traffic come back from pod to host maybe not go through conntrack in host, and can not un-snat to hostip which client requested.

Masquerad all traffic can make sure the pod reply come back to host and go through conntrack in host.

When k8s cluster use
ipvlanL3/L2,macvlanor otherunderlaynetwork plugin. The traffic come back from pod to host maybe not go throughconntrackin host, and can not un-snat tohostipwhich client requested.Masquerad all traffic can make sure the pod reply come back to host and go through
conntrackin host.