In particular: Reject a config with a user ACL with scope: flow if there is any combination of expose blocks from the two ends of the peering that does not have masquerade or port forwarding (because we don't support scope: flow without flow tracking, currently only provided by masquerade or port forwarding).
In particular: Reject a config with a user ACL with
scope: flowif there is any combination of expose blocks from the two ends of the peering that does not have masquerade or port forwarding (because we don't supportscope: flowwithout flow tracking, currently only provided by masquerade or port forwarding).