From my understanding, when setup kubernetes service with session affinity equal to "clientIP", the internal iptables writes rule to nat traffic by endpoint(service ip