If existing modules are compiled without an option, can't replacement modules be created, with (and I know this is ugly) ... so adding nf_conntrack in a fresh module might be possible.
If I'm limited to ad-hoc I'd put up with sshing in and onwards, and/or using an http proxy, job done, let's move on.
I want to keep investigating getting infrastructure working. I read up about this and found our wifi driver supports all the right things, we're just a couple of kernel revisions behind the support which adds this. We're in the new world of standardised wifi drivers.